BugTraq
google xss Apr 04 2006 09:34PM
almfnod gawab com (1 replies)
RE: google xss Apr 09 2006 11:50PM
Andy Meyers (andy meyers hushmail com) (2 replies)
Re: google xss Apr 10 2006 07:40PM
pagvac (unknown pentester gmail com) (1 replies)
Re: google xss Apr 12 2006 12:34PM
Vladimir Levijev (vladimir levijev gmail com)
Re: google xss Apr 10 2006 07:11PM
Jim Ley (jim jibbering com)

"Andy Meyers" <andy.meyers (at) hushmail (dot) com [email concealed]> wrote in message
news:20060409235034.1AAAC17042 (at) smtp2.hushmail.com. (dot) . [email concealed]
> My BlackICE stops this from XSS from happening, however changing the URL
> from a .ae domain to a .com and leaving the rest in tact, I am then
> prompted.
>
> http://www.google.com/search?hl=ar&q=<script>alert("1")</script>&meta=

The flaw is very exploitable, basically any search that includes a books
result and contains script will trigger the flaw, the .com seems to only
include the flaw in arabic, and sometime depending on the users location or
some other thing (I can't identify).

Using a different search to trigger more book results allows you to much
more easily exploit it.

http://jibbering.com/blog/?id=506 and http://jibbering.com/blog/?id=507
show a phishing exploit and a gmail contacts stealing method using the above
attack.

Google still appear to be unable to do the simple programming matter of
encoding of user input before writing it back out.

Cheers,

Jim.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus