Submissions Requiring Manual Approval

Questions or requests about submissions
Post Reply
Spam404Online
Posts:296
Joined:Mon Nov 23, 2015 6:43 pm
Contact:
Submissions Requiring Manual Approval

Post by Spam404Online » Thu Jan 07, 2016 8:55 am

Hey,

I just submitted XSS vulnerabilities for the following domains, it seems they need manual approval so it would be great if you could -
bit.do
acer.su
toptenreviews.com
siemens.sk
blackanddecker.com
epson-europe.com
lexmark.com (x2)
adobe.com
wmo.int

Thanks in advance! :)

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Submissions Requiring Manual Approval

Post by x1admin » Thu Jan 07, 2016 12:58 pm

only js redirects to data can be approved as xss

Spam404Online
Posts:296
Joined:Mon Nov 23, 2015 6:43 pm
Contact:

Re: Submissions Requiring Manual Approval

Post by Spam404Online » Thu Jan 07, 2016 1:38 pm

x1admin wrote:only js redirects to data can be approved as xss
Oh I see, I don't think I get the concept about them yet, sorry :D

How do you verify if it's a js one? Would appreciate any guidance here so I can only submit the correct ones in the future :)

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Submissions Requiring Manual Approval

Post by x1admin » Sat Jan 09, 2016 5:36 am

now we dont accept redirect to data as xss because this xss dont work in all browsers

ret2libc
Posts:62
Joined:Tue Nov 24, 2015 11:52 am

Re: Submissions Requiring Manual Approval

Post by ret2libc » Sat Jan 09, 2016 5:13 pm

x1admin wrote:now we dont accept redirect to data as xss because this xss dont work in all browsers
This logic is ridiculous. 90% of xss aren't working in chrome.

Lewis
Posts:20
Joined:Tue Nov 24, 2015 2:13 pm

Re: Submissions Requiring Manual Approval

Post by Lewis » Sat Jan 09, 2016 8:52 pm

ret2libc wrote:
x1admin wrote:now we dont accept redirect to data as xss because this xss dont work in all browsers
This logic is ridiculous. 90% of xss aren't working in chrome.
Agreed, I think the logic to disallow redirects to base64 encoded payloads is purely the wrong choice; you dont see bug bounty programs counting it out of scope?

If it can be used maliciously it should be classed as a vulnerability; surely?

Firefox is still one of the top 3 browsers worldwide so why disallow a vuln that utilizes its features?
:ugeek:

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Submissions Requiring Manual Approval

Post by x1admin » Sat Jan 09, 2016 9:28 pm

we accept this vulnerabilities as open redirect

ret2libc
Posts:62
Joined:Tue Nov 24, 2015 11:52 am

Re: Submissions Requiring Manual Approval

Post by ret2libc » Sat Jan 09, 2016 10:01 pm

x1admin wrote:we accept this vulnerabilities as open redirect
well this makes some more sense since the javascript isnt executing in the context of the vuln domain... but still, owasp.org would disagree with you on this :)

ret2libc
Posts:62
Joined:Tue Nov 24, 2015 11:52 am

Re: Submissions Requiring Manual Approval

Post by ret2libc » Sat Jan 09, 2016 11:33 pm

you can still have something being vuln to open redirect while disallowing redirection to a data: uri with inputs

Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests