Kiwibonga Advance Message Boards
Register | Member List | Site main | Board main
Login
Login:
Password:
2 user(s) online: 2 guests - 267 visitors in the last 24 hours.

Pages: 1
Post Reply
   Kiwibonga Advance > Kiwibonga Advance Boards > Bug Reports > Bugtraq, Part 2!
 
M_DCad
Posts: 3/17

Bugernaut baby



Location: Calgary
[E-mail]
[AIM]
Last Activity: 8294 day(s) and 21 hour(s) ago
Registered: Jan 9 2003
Posted on 01/09/2003 at 06:52:32AM Quote

Bug 3: Cross-site Scripting Vulnurability
------------------------------------------

Problem: Although anything between <script> HTML tags is deleted by the forum software, it is still possible to inject potentially malicious javascript by using (for example) the following piece of code, which would execute in Internet Explorer. (Although Mozilla is unaffected by this code, it is possible to modify it in order to make it work on it and other browsers):

<img src="javascript:alert(document.cookie)">

By creating a simple emailer CGI script on another server (such as on a free webspace provider like Tripod or Lycos) it is possible to silently steal users' MD5 password hashes which are stored in a cookie. MD5 is extremely weak as a form of encryption, and these hashes could then be cracked with ease. Or, because of the way this forum software requires no account authentication other than the stored cookie itself when changing one's account settings, it would be possible to take over another person's account.

Solution: Have the forum change instances of the string "javascript:" to something else such as "xjavascript:".



Bug 4: Weak User Authentication for Account Updating
----------------------------------------------------

Problem: This ties in directly with the last bug. The only form of authentication required to change an account's settings is a cookie with the member's username and MD5 password hash.

Solution: When a user tries to update his account, require his password to be re-entered.
-----------
-M_DCAD
@kiwibonga
I own two websites now. It sucks. :P
Posts: 221/717

The President of Spainmark



Location: Montreal, Quebec, Canada
[E-mail]
[AIM]
Last Activity: 3059 day(s) and 7 hour(s) ago
Registered: Sep 16 2002
Posted on 01/10/2003 at 01:50:13AM Quote

Kiwibonga
Thanks for those, and I'd also like to ask you for more examples of javascript or scripting I could filter if you know more, since I have very limited JavaScript knowledge, I can understand it since it has quite basic syntax, but I really can't code any...

*adds some stuff to the stripjavascript() function*
-----------
Happiness.
M_DCad
Posts: 6/17

Bugernaut baby



Location: Calgary
[E-mail]
[AIM]
Last Activity: 8294 day(s) and 21 hour(s) ago
Registered: Jan 9 2003
Posted on 01/10/2003 at 02:08:33AM Quote

You still need to filter out things like "onerror=", "onload=", etc., since they automatically execute as javascript without the "javascript:" prefix required for img src's and etc. Sorry, my knowledge of Javascript isn't very extensive.

Of course, the best way would be to filter out HTML altogether (change < and > to &lt; and &gt;), and later change back only certain tags (like b, i, img, etc.) to their actual HTML versions.
-----------
-M_DCAD

Edited by M_DCad on 01/09/2003 at 09:09:00PM
Edited by M_DCad on 01/09/2003 at 09:09:46PM
@kiwibonga
I own two websites now. It sucks. :P
Posts: 222/717

The President of Spainmark



Location: Montreal, Quebec, Canada
[E-mail]
[AIM]
Last Activity: 3059 day(s) and 7 hour(s) ago
Registered: Sep 16 2002
Posted on 01/10/2003 at 02:20:02AM Quote

Kiwibonga
Well, I really like to let people use HTML, so I only want to filter "harmful" stuff...

Thanks for that, I'll look up some more stuff on MSDN...
-----------
Happiness.
M_DCad
Posts: 9/17

Bugernaut baby



Location: Calgary
[E-mail]
[AIM]
Last Activity: 8294 day(s) and 21 hour(s) ago
Registered: Jan 9 2003
Posted on 01/10/2003 at 02:56:19AM Quote

Weird, I can't seem to post a new topic in the Bugs forum.

Another XSS hole:
http://www.kiwibonga.com/gba/forum.php?id=%3E%3Cscript%3Ealert(document.cookie);%3C/script

Although both single and double quotes are escaped by the php script, it should still be possible to define a URL to send document.cookie to by using String.fromCharCode(...)
-----------
-M_DCAD


Edited by M_DCad on 01/09/2003 at 09:56:27PM
Edited by M_DCad on 01/09/2003 at 09:56:35PM
Edited by M_DCad on 01/09/2003 at 09:56:51PM
Edited by M_DCad on 01/09/2003 at 09:58:08PM
Edited by M_DCad on 01/09/2003 at 09:58:21PM
Edited by M_DCad on 01/09/2003 at 09:58:21PM
@kiwibonga
I own two websites now. It sucks. :P
Posts: 228/717

The President of Spainmark



Location: Montreal, Quebec, Canada
[E-mail]
[AIM]
Last Activity: 3059 day(s) and 7 hour(s) ago
Registered: Sep 16 2002
Posted on 01/10/2003 at 03:21:56AM Quote

Please explain
-----------

Edited by kiwibonga on 01/09/2003 at 10:22:22PM
M_DCad
Posts: 10/17

Bugernaut baby



Location: Calgary
[E-mail]
[AIM]
Last Activity: 8294 day(s) and 21 hour(s) ago
Registered: Jan 9 2003
Posted on 01/10/2003 at 03:36:37AM Quote

Well, go to that URL, and you'll see the vulnurability.

However, try putting cookie.document in quotes, and you'll see that you can't use quotes in the javascript since they're escaped with backslahes when you try.

But it's still possible to abuse this XSS problem by using String.fromCharCode:

http://www.kiwibonga.com/gba/forum.php?id=%3E%3Cscript%3Ealert(String.fromCharCode(104,116,116,112,58,47,47,115,111,97,110,100,115,111,46,99,111,109,47,101,118,105,108,115,99,114,105,112,116,46,99,103,105,63)+%2B+document.cookie);%3C/script
-----------
@kiwibonga
I own two websites now. It sucks. :P
Posts: 230/717

The President of Spainmark



Location: Montreal, Quebec, Canada
[E-mail]
[AIM]
Last Activity: 3059 day(s) and 7 hour(s) ago
Registered: Sep 16 2002
Posted on 01/10/2003 at 04:14:20AM Quote

I just made sure it would remove disabled3E, but that's about all I could find...
-----------
M_DCad
Posts: 11/17

Bugernaut baby



Location: Calgary
[E-mail]
[AIM]
Last Activity: 8294 day(s) and 21 hour(s) ago
Registered: Jan 9 2003
Posted on 01/10/2003 at 04:24:20AM Quote

The problem's with the way the "Mark this forum read" link blindly writes $id in the a href tag. The best solution's probably to make sure $id is a number before doing anything on forum.php, and remove any non-numeric characters from it before continuing.
-----------

Edited by M_DCad on 01/09/2003 at 11:25:34PM
Edited by M_DCad on 01/09/2003 at 11:26:36PM
@kiwibonga
I own two websites now. It sucks. :P
Posts: 231/717

The President of Spainmark



Location: Montreal, Quebec, Canada
[E-mail]
[AIM]
Last Activity: 3059 day(s) and 7 hour(s) ago
Registered: Sep 16 2002
Posted on 01/10/2003 at 04:38:16AM Quote

Oh I see now!

EDIT: That's fixed now.
-----------

Edited by kiwibonga on 01/09/2003 at 11:42:46PM
 
   Kiwibonga Advance > Kiwibonga Advance Boards > Bug Reports > Bugtraq, Part 2!
Post Reply
Pages: 1

© 2002 Kiwibonga.com - 156.6589 visitors per day - rendered in 0.033 seconds.