5 ms·
While we are at it.. XSS search: https://github.com/search?q=extension%3Aphp+%3C%3F%3D%24_GET&type=Code&ref=searchresults https://github.com/search?q=extension%
by a1a 13y ago
While we are at it.. XSS search:
https://github.com/search?q=extension%3Aphp+%3C%3F%3D%24_GET&type=Code&ref=searchresults https://github.com/search?q=extension%3Aphp+%3C%3F%3D%24_GET...
- btipling 13y agoJavaScript version: https://github.com/search?q=extension%3Ajs+html+%2B&type=Code&ref=searchresults https://github.com/search?q=extension%3Ajs+html+%2B&type...
- gingerlime 13y agothis one seems to produce quite a lot of false-positives though, doesn't it?
- btipling 13y agoThose all look like XSS vulnerabilities to me.
- gingerlime 13y agoOf course this is a pretty good starting point to find XSS, but I still see quite a few false positives: the first result I see currently: https://github.com/matsprehn/122B/blob/1d54d2a72f25a23d63ff77edaac65b814043c7c7/js/footer.js https://github.com/matsprehn/122B/blob/1d54d2a72f25a23d63ff7... also spotted this, which looks pretty harmless: https://github.com/cameroni2003/picgrid/blob/0b3becda1f250ef598a0fd72ac101dd08f0892a2/js/globals.js https://github.com/cameroni2003/picgrid/blob/0b3becda1f250ef... a lot others look similar, plus it depends on context...
- btipling 13y agoYes, sure. Those two do not reveal vulnerabilities just from the results, but I have to wonder at not using templates on the first.
- timothya 13y agoIs it an XSS if you can only make it output code to your own browser? I can already execute whatever JavaScript I want in the console, so what's the advantage of having the server deliver that code to (only) me? I can definitely see the issue if the server saves the unfiltered input and tries to print that out for other uses, but it seems to me that outputting a raw $_GET variable will only go to the requester and therefore could only run unfiltered code on that requesters machine. EDIT: Answering my own question: This is a security hole because the unsafe JavaScript is stored in the URL for the page (it is a GET parameter). This bad URL could then be sent as a link in a spam email or similar. Victims clicking on the link would then see a page that comes from the legitimate source, but is running unsafe code compromising that user's session. This sort of attack relies on the attacker distributing the link with the bad code as a URL parameter, and is not a vulnerability that a user could encounter when just visiting that site as I had first assumed.
- arthurschreiber 13y agoThat's _exactly_ what XSS is about. One possible way to exploit things like this is if I send you a link to a website, that embeds the target page through an iframe with javascript output injected. I could then have the JS steal your cookies/session or worse.
- deleted 13y ago[deleted]
- a1a 13y agoYes. They are referred to as "reflective" or "non-persistent" XSS vulnerabilities. The attacker might exploit these using for example an "invisible" iframe on a different website, and thus loading the vulnerable website, in the background, with the desired parameters. This will result in the malicious javascript being executed "on the vuln. website", in the victims browser. This (http://web.math.jjay.cuny.edu/fcm791/web2.0_Vulnerabilities.pdf http://web.math.jjay.cuny.edu/fcm791/web2.0_Vulnerabilities....) is a pretty good paper (jump to page 7) if you are interested.
- mgkimsal 13y agoOr bit.ly/shortener links - you got it. I used to think like you did - what harm is there in 'exploiting' my own browser? Took a while for the penny to drop in my case.
- krapp 13y agoalso $_POST https://github.com/search?p=4&q=extension%3Aphp+%3C%3F%3D%24_POST&ref=searchresults&type=Code https://github.com/search?p=4&q=extension%3Aphp+%3C%3F%3...