Sinisterly
CyberGhost XSS - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Design (https://sinister.li/Forum-Design)
+--- Forum: Web Design (https://sinister.li/Forum-Web-Design)
+--- Thread: CyberGhost XSS (/Thread-CyberGhost-XSS)



CyberGhost XSS - ɘxɘ - 02-13-2016

Pulses.xyz Security Report 0x03 ­ support.cyberghost.com (XSS) ­ 1/31/2016

Yet again, it really hurts me when I see something like this. A privacy­oriented site that has these types of vulnerabilities. It’s not really their fault, it’s the software’s fault. They use a softare called “Kayako” which is a paid helpdesk script. More info is located at http://www.kayako.com/ I don’t know if it’s just that CyberGhost hasn’t updated their software for a while, or Kayako hasn’t updated theirs.

I had some problems with testing this vulnerability through my browser as it blocked it, even after disabling XSS protection. So I will tell you how to do it even with it enabled. 

[hide]So the vulnerability is located here: https://support.cyberghostvpn.com///"onmouseover='prompt(1337)'bad="> So now if you basically move your mouse to the image that didn’t load then you’ll see a prompt popup that says "1337" and ask for your input. Also, if this didn’t work then you have the same problem I did. Your browser is blocking it. To fix this, right click on the page and click "Inspect Element" and then go find "%22" in the image URL, replace it with a " [/hide]

Also, I know this seems like it's just using Inspect Element to change some variables and that the servers really blocking the XSS, well it's not. I have used this with some other browsers that don't have this protection and it has worked.


RE: CyberGhost XSS - Zenta - 02-13-2016

Great share. Please add hide tags.

Regards,
@2


RE: CyberGhost XSS - Jasper - 02-13-2016

Nice found. Need more credits though.


RE: CyberGhost XSS - Geek - 02-13-2016

Many big companies use Kayako so if they are using the latest version, then it's on a lot of sites then. Good find.


RE: CyberGhost XSS - Krados - 02-17-2016

(02-13-2016, 03:00 PM)Zenta Wrote: Great share. Please add hide tags.

Regards,
@2

"pls add hide tags"
(This post was last modified: 02-13-2016, 02:02 PM by Zenta.)


silly zenta  :noh:

OT: Thanks for the share!


RE: CyberGhost XSS - Esoterith - 04-02-2016

Amazing Share. Thanks for this!