3 ms·
Since everyone is venturing a guess, here's mine: They used XSS (cross site scripting) to send a mail to the target. When the email is viewed a CSRF (cross sit
by rdj 17y ago
Since everyone is venturing a guess, here's mine:
They used XSS (cross site scripting) to send a mail to the target. When the email is viewed a CSRF (cross site request forgery) is executed to add a new device (phone) to the authenticated devices list. Next they log in, receive the SMS on their phone that is now in the list...bam!
[Edit: I didn't mean XSS to send the email, I meant inject an XSS attack into the email and send it. I'm thinking something like psuedo: location.replace(/link/to/add/device/?phone=555-1212 ]
- Xichekolas 17y agoAs jgrahamc pointed out: http://news.ycombinator.com/item?id=642280 http://news.ycombinator.com/item?id=642280 They probably sent the mail like you said, only used the CSRF to jack the cookie, which would be easier than adding a phone to the list.
- tptacek 17y agoCan you explain what the CSRF attack you're thinking of is? Maybe I'm not reading you carefully enough (long day), but that doesn't sound like a CSRF to me.
- Xichekolas 17y agoWell my thoughts were something like: Victim logs in using two-factor auth, gets a cookie which lets them back in without phone in future. Attacker sends email to victim with some kind of script embedded. Victim views email, javascript runs and sends cookie info to attacker. Attacker uses cookie to impersonate victim. Of course, it's been a long day here too, and I'm so far from an expert on this stuff it's entirely probable that what I just described doesn't make sense/isn't possible. Edit: Yeah, guess what I described is more XSS than CSRF
- ErrantX 17y agoI suspect your on the right lines: but from the XSSExploits tweets I imagine that what they might well have done is ecxecute some JS to add a new authorised phone number to the list (i.e. by just posting the new details). That said they say they also needed a strongwebmail account for it to work so I could be wrong - perhaps they just hijacked their authed session ID into the ceo's (possibly??)
- rdj 17y agoI hope the rules of the contest allow disclosure. Until then, I only have this tweet to reference from June 3rd: http://twitter.com/XSSExploits/status/2019746890 http://twitter.com/XSSExploits/status/2019746890 "alternatively- add a device to the auth list and wala ;)" [edit: I should note that XSSExploits seems to be the twitter account for the company that won the contest)
- rdj 17y agoLooks like we may never know. Disclosure is not permitted per the official rules http://www.strongwebmail.com/secure/email/contests/hack/tc http://www.strongwebmail.com/secure/email/contests/hack/tc