3 ms·
Initially JavaScript was being escaped with their WAF. The second POC demonstrated the ability to evade both their WAF and XSS_Auditor. Their development team
by GregoryVPerry 9y ago
Initially JavaScript was being escaped with their WAF.
The second POC demonstrated the ability to evade both their WAF and XSS_Auditor.
Their development team then verified the ability to execute arbitrary JavaScript from any *.cloudfront.net host.
That's pretty much the whole story.
- fredericoqq 9y agoCould you make an alert(1) or not? If you couldn't, it's plausible the non-security developers incorrectly speculated it was possible?
- netsec_burn 9y agoNow I'm starting to wonder the same thing, *.cloudfront.net is not Uber.