Giffgaff.com reflective XSS (Unreportable) -_-

Questions or requests about submissions
Post Reply
Lewis
Posts:20
Joined:Tue Nov 24, 2015 2:13 pm
Giffgaff.com reflective XSS (Unreportable) -_-

Post by Lewis » Sat Dec 12, 2015 10:37 am

https://www.giffgaff.com/auth/signup

manually type "><svg/onload=prompt(document.domain)> into the email field and you'll get a popup; couldnt find a relevant header to report after some time searching; could you pls try manually approve it or? ;/


:|
:ugeek:

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Giffgaff.com reflective XSS (Unreportable) -_-

Post by x1admin » Sat Dec 12, 2015 3:42 pm

please use https://www.xssposed.org/report/ for report

Lewis
Posts:20
Joined:Tue Nov 24, 2015 2:13 pm

Re: Giffgaff.com reflective XSS (Unreportable) -_-

Post by Lewis » Sat Dec 12, 2015 5:56 pm

reported it; please could ya manually submit as it didnt work last time; thanks.
:ugeek:

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Giffgaff.com reflective XSS (Unreportable) -_-

Post by x1admin » Sun Dec 13, 2015 3:42 am

provide us any solution how this xss can be exploited against other users

Lewis
Posts:20
Joined:Tue Nov 24, 2015 2:13 pm

Re: Giffgaff.com reflective XSS (Unreportable) -_-

Post by Lewis » Sun Dec 13, 2015 2:15 pm

half the post based reflective xss reports on search functions are useless on this forum; this one equally as useless and just requires the same principles but without actually hitting enter on your keyboard and sending the request; whether or not it can be used against others isnt relevant if you're accepting post based reflective xss's which are also useless ._.
:ugeek:

Spam404Online
Posts:296
Joined:Mon Nov 23, 2015 6:43 pm
Contact:

Re: Giffgaff.com reflective XSS (Unreportable) -_-

Post by Spam404Online » Sun Dec 13, 2015 3:55 pm

Lewis wrote:half the post based reflective xss reports on search functions are useless on this forum; this one equally as useless and just requires the same principles but without actually hitting enter on your keyboard and sending the request; whether or not it can be used against others isnt relevant if you're accepting post based reflective xss's which are also useless ._.
I wouldn't call POST method XSS useless. It can be achieved without user interaction. See - http://hackers2devnull.blogspot.co.uk/2 ... ently.html

If the vulnerability you've found here can be achieved in a similar fashion I do believe it should be accepted though and more importantly, fixed by giffgaff.

Lewis
Posts:20
Joined:Tue Nov 24, 2015 2:13 pm

Re: Giffgaff.com reflective XSS (Unreportable) -_-

Post by Lewis » Wed Dec 16, 2015 7:22 pm

I agree, however even if it cant be achieved in the same manner it should at least be accepted; its basically just utilizing ajax instead of a user actually hitting enter and submitting a post request; no reason why this should be treated to any others imo :)

Please submit mr admino
:ugeek:

User avatar
mradamdavies
Posts:29
Joined:Wed Nov 25, 2015 3:00 pm
Contact:

Re: Giffgaff.com reflective XSS (Unreportable) -_-

Post by mradamdavies » Wed Dec 16, 2015 10:03 pm

x1admin wrote:provide us any solution how this xss can be exploited against other users
^Agreed.


Same example, different domain: http://uktvplay.uktv.co.uk
Copy/Pasta works, but end point is blocked so exploitation isn't possible.

You can't say a site is exploitable if you have to manually enter the PoC from the target's computer. If a _GET or _POST doesn't work, it's not vuln. Unless you get a virus on the "victim" and force them to manually type the PoC with malware, it's not an exploit. Nice reflective, but no dice.

vdvcoder
Posts:16
Joined:Mon Nov 23, 2015 5:29 pm
Contact:

Re: Giffgaff.com reflective XSS (Unreportable) -_-

Post by vdvcoder » Thu Dec 17, 2015 10:41 pm

mradamdavies wrote:
x1admin wrote:provide us any solution how this xss can be exploited against other users
^Agreed.


Same example, different domain: http://uktvplay.uktv.co.uk
Copy/Pasta works, but end point is blocked so exploitation isn't possible.

You can't say a site is exploitable if you have to manually enter the PoC from the target's computer. If a _GET or _POST doesn't work, it's not vuln. Unless you get a virus on the "victim" and force them to manually type the PoC with malware, it's not an exploit. Nice reflective, but no dice.
Good to know! Thank u!

Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests