4 ms·
So uh. This works on a few websites. A couple I've found http://dig.whois.com.au/dig.php?dom=jamiehankins.co.uk&type=ALL&submit=Dig+Lookup http://dig.whois.com
by JamieH 12y ago
So uh. This works on a few websites. A couple I've found
http://dig.whois.com.au/dig.php?dom=jamiehankins.co.uk&type=ALL&submit=Dig+Lookup http://dig.whois.com.au/dig.php?dom=jamiehankins.co.uk&type=...
http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins.co.uk&run=toolpage http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins....
- jpinkerton88 12y agoBeautifully done.
- mc_hammer 12y ago^^ hilarious :)
- nitinag 12y agoOur dns lookup tool is safe from this: https://www.misk.com/tools/#dns/jamiehankins.co.uk https://www.misk.com/tools/#dns/jamiehankins.co.uk
- arenaninja 12y agoOH! Now I get it. Honestly, this is hilarious
- swartkrans 12y agoSo like, what template library are these sites using that doesn't have basic XSS protection. :|
- Havvy 12y agoProbably basic PHP?
- serveradminblog 12y agoMXToolbox is a windows based app
- jsmthrowaway 12y agoPut your e-mail on your profile. The smart appsec groups, like Google's, would look at your hack as a resume. Seriously, who would have ever thought of XSS via DNS? You could have just alert'd, too, but no. Harlem Shake. Bravo.
- giancarlostoro 12y agoI'm guessing nobody else noticed the Rick Roll in there too?
- astrodust 12y agoI appreciated the "allowfullscreen" option being thoughtfully included.
- BuildTheRobots 12y agoAs the script was just bouncing the search box at the start I a) assumed it was deliberate and b) expected them to start trying to sell me domains. The rickroll was the first bit I noticed o_0
- spb 12y agohttp://dig.whois.com.au/dig.php?dom=jamiehankins.co.uk&type=ALL&submit=Dig+Lookup http://dig.whois.com.au/dig.php?dom=jamiehankins.co.uk&type=... appears to have fixed it.
- josephjrobison 12y agoAm I the only one here that doesn't get what I should be looking for? I see the txt fields have google-site-verification and peniscorp but what is that doing?
- Sanddancer 12y agoThey finally fixed it, but when this was first posted, the whois sites didn't do any sanitization of the TXT records, which meant that they'd just slap the record into the page. As the record included html saying, "hey, load this script from peniscorp", loading the page would let the script loaded there do various manipulations.
- duncans 12y agoNitpick: they should have been encoding the output not sanitising.
- btown 12y agoTo those at work: exploited sites will autoplay music. Make sure your sound is muted or your headphones are in.