Classic Cross Site Scripting: Gibson Research Corporation

From: http-equiv@excite.com
Date: 05/01/02

  • Next message: Russ: "2 mistaken approvals to the list"
    Date:         Wed, 1 May 2002 16:34:47 -0000
    From: "http-equiv@excite.com" <http-equiv@MALWARE.COM>
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    

    Wednesday, May 01, 2002

    The following represents a classic [fitting] working example of the
    dangers of Cross Site Scripting.

    [see: http://www.cert.org/advisories/CA-2000-02.html
    http://www.cert.org/archive/pdf/cross_site_scripting.pdf]

    Gibson Research Corporation http://www.grc.com is an interesting site
    covering a wide variety of security topics for newcomers. Cursory
    research suggests that it enjoys a substantial loyal following who
    trust it implicitly.

    The problem is two-fold:

    1. The site has a web based discussion forum
    2. The site has a custom 'filter', the so-called: "Gibson Research
    Corporation's IIS Advanced Prophylactic Filter"

    This custom 'filter' is supposed to protect the server
    from 'malicious abuse' and both 'detect and block' invalid requests
    submitted to the server:

    http://www.grc.com/apf/

    [screen shot: http://www.malware.com/flitty.png 25KB]

    Unfortunately, what it actually does is allow us to inject our own
    html code through grc.com's secured server. This is particularly
    ticklish as it does not take much to conjure up a scenario where we
    construct a 'fake' e-commerce page, say peddling a book or 'gadget'
    download and simply invite the loyal following to go and submit their
    credit card details to our custom form.

    The site grc.com well known and trusted. The page is on a secured
    server with valid certificates.

    Ripe For Picking™

    Crude Working example:

    note: custom crafted for Internet Explorer 5.5 and 6

    http://www.malware.com/grc.html

    [screen shot: http://www.malware.com/lucre.png 11KB]

    Notes:

    1. Watch where you "point and click". It's all smoke and mirrors out
    there.
    2. 3 mail messages within 72 hours to support @ grc.com remain
    unanswered to date.

    End Call

    --
    http://www.malware.com
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Delivery co-sponsored by TruSecure Corporation
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Demonstrate your knowledge and understanding of core IT Security, become
    TICSA certified.
    Are you responsible for IT security in job function, but not necessarily
    in title? Do you want to prove your IT security knowledge and increase
    opportunities? Interested? Visit;
    http://www.trusecure.com/solutions/certifications/ticsa/
    for more information.
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    


    Relevant Pages

    • Re: Force user to use outlook and custom organizational form
      ... > You can get the server name of the Exchange server, ... > you have for avoiding the security prompts and administering the ... > If you don't use custom forms any custom properties won't stay intact ...
      (microsoft.public.exchange.development)
    • Classic Cross Site Scripting: Gibson Research Corporation
      ... Gibson Research Corporation http://www.grc.com is an interesting site ... The site has a custom 'filter', ... Corporation's IIS Advanced Prophylactic Filter" ... This custom 'filter' is supposed to protect the server ...
      (NT-Bugtraq)
    • Classic Cross Site Scripting: Gibson Research Corporation
      ... Gibson Research Corporation http://www.grc.com is an interesting site ... The site has a custom 'filter', ... Corporation's IIS Advanced Prophylactic Filter" ... This custom 'filter' is supposed to protect the server ...
      (Vuln-Dev)
    • Classic Cross Site Scripting: Gibson Research Corporation
      ... Gibson Research Corporation http://www.grc.com is an interesting site ... The site has a custom 'filter', ... Corporation's IIS Advanced Prophylactic Filter" ... This custom 'filter' is supposed to protect the server ...
      (Bugtraq)
    • Re: Runtime Error when going to Hotmail
      ... This may be a symptom of too strict security on the client side. ... BTW what zone is this URL coming up in? ... An application error occurred on the server. ... The current custom ...
      (microsoft.public.windows.inetexplorer.ie6.browser)