![]() |
|
CyberGhost XSS - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Design (https://sinister.li/Forum-Design) +--- Forum: Web Design (https://sinister.li/Forum-Web-Design) +--- Thread: CyberGhost XSS (/Thread-CyberGhost-XSS) |
CyberGhost XSS - ɘxɘ - 02-13-2016 Pulses.xyz Security Report 0x03 support.cyberghost.com (XSS) 1/31/2016 Yet again, it really hurts me when I see something like this. A privacyoriented site that has these types of vulnerabilities. It’s not really their fault, it’s the software’s fault. They use a softare called “Kayako” which is a paid helpdesk script. More info is located at http://www.kayako.com/ I don’t know if it’s just that CyberGhost hasn’t updated their software for a while, or Kayako hasn’t updated theirs. I had some problems with testing this vulnerability through my browser as it blocked it, even after disabling XSS protection. So I will tell you how to do it even with it enabled. [hide]So the vulnerability is located here: https://support.cyberghostvpn.com///"onmouseover='prompt(1337)'bad="> So now if you basically move your mouse to the image that didn’t load then you’ll see a prompt popup that says "1337" and ask for your input. Also, if this didn’t work then you have the same problem I did. Your browser is blocking it. To fix this, right click on the page and click "Inspect Element" and then go find "%22" in the image URL, replace it with a " [/hide] Also, I know this seems like it's just using Inspect Element to change some variables and that the servers really blocking the XSS, well it's not. I have used this with some other browsers that don't have this protection and it has worked. RE: CyberGhost XSS - Zenta - 02-13-2016 Great share. Please add hide tags. Regards, @2 RE: CyberGhost XSS - Jasper - 02-13-2016 Nice found. Need more credits though. RE: CyberGhost XSS - Geek - 02-13-2016 Many big companies use Kayako so if they are using the latest version, then it's on a lot of sites then. Good find. RE: CyberGhost XSS - Krados - 02-17-2016 (02-13-2016, 03:00 PM)Zenta Wrote: Great share. Please add hide tags. "pls add hide tags" (This post was last modified: 02-13-2016, 02:02 PM by Zenta.) silly zenta :noh: OT: Thanks for the share! RE: CyberGhost XSS - Esoterith - 04-02-2016 Amazing Share. Thanks for this! |