4 ms·
I don't understand why he didn't make an alert(document.domain), the universal "this is legit" bat signal. Instead, creating some weird form phishing demo? I t
by fredericoqq 9y ago
I don't understand why he didn't make an alert(document.domain), the universal "this is legit" bat signal. Instead, creating some weird form phishing demo?
I think there is more to this story, it sounds like this wasn't a "Cross Site Scripting", but "Content Injection" or "Content Spoofing", a far less serious bug.
You're gonna hate me, but I would award $0 for Content Injection, it's just not a big deal ¯\_(ツ)_/¯
- GregoryVPerry 9y agoInitially JavaScript was being escaped with their WAF. The second POC demonstrated the ability to evade both their WAF and XSS_Auditor. Their development team then verified the ability to execute arbitrary JavaScript from any *.cloudfront.net host. That's pretty much the whole story.
- fredericoqq 9y agoCould you make an alert(1) or not? If you couldn't, it's plausible the non-security developers incorrectly speculated it was possible?
- netsec_burn 9y agoNow I'm starting to wonder the same thing, *.cloudfront.net is not Uber.