3 ms·
Pardon my ignorance, but how are the passwords actually stolen? If I understand correctly, this exploit lets you execute arbitrary code on the search results p
by ipince 10y ago
Pardon my ignorance, but how are the passwords actually stolen?
If I understand correctly, this exploit lets you execute arbitrary code on the search results page. And in this case, the code will load up an iframe from a separate place in McD's domain, get the 'penc' cookie and decrypt your own password.
So you would still need to send a link to a McD registered user, who clicked in Remember Password, and then presumably send his/her decrypted password to your own servers (how?). And also somehow steal their username/email.
Is that correct?
- dogshoes 10y agoIt's pretty simple to exfiltrate data from the JavaScript sandbox once it has been compromised via XSS. The simplest way is probably appending an img tag to the page's DOM, with a src pointing to a server you control and send the user's password as the image name.
- Orangeair 10y ago> Is that correct? Yes, that's the classic XSS attack pattern. It's like phishing, but better since you're sending the person a link to the actual website. And once they've clicked on it, they're already screwed; they don't even need to manually enter any information. > how? Once you have the cookie, its as simple as something like making an XMLHttpRequest to your own server that includes the decrypted email and password from the cookies.
- chadscira 10y agoIf they don't have X-Frame-Options the attacker can also just use a 1x1 iframe on a popular website or shitty ad network to trigger that page to load