5 ms·
Wait a second, could you not read my google login session cookie from this page with a seamless iframe to a google domain? Again, like the person above, I didn'
by ororlrlrlylyly 13y ago
Wait a second, could you not read my google login session cookie from this page with a seamless iframe to a google domain? Again, like the person above, I didn't really understand what's going on here.
- sluukkonen 13y agoGoogle uses a different domain for user content, namely googleusercontent.com.
- ororlrlrlylyly 13y agoWhat's the definition of "user content"?
- homakov 13y agoUntrustworthy scripts, HTML, images, email attachments.
- ororlrlrlylyly 13y agoBut I'm logged in! It shows myname in the corner. So obviously you could get that cookie, right?
- homakov 13y agoPart with yourname is other_origin. I change content of GUC Page 2 using GUC Page 1 through other_origin (translate.google.com). No XSS or cookies. Just standards :D
- mh- 13y agoI seriously admire your patience in replying to comments.
- homakov 13y agoI have no life.
- mh- 13y agoI was only referring to your continuing lengthy, polite comments when replying to commenters' questions. :)
- homakov 13y ago:) it's pleasant to explain hacks you discover. actually PoC is fixed - http://homakov.blogspot.com.es/2013/07/googleusercontentcom-fun-or-snowden-is.html http://homakov.blogspot.com.es/2013/07/googleusercontentcom-...
- homakov 13y agono cookie/XSS or any real vuln here involved. This is completely standard design problem of sandbox domain. Check out http://homakov.github.io/guc.html http://homakov.github.io/guc.html
- ororlrlrlylyly 13y agoOh, btw, also, you may be interested in window.setTimeout.
- homakov 13y agoi am js jedi, but don't spend much time on PoCs.