Flash_xss mining tips

Source: Internet
Author: User

Malicious swf can obtain cookies in the swf domain under iframe. The more users, the more dangerous the website is, because the attacks are hidden in China, especially QQ and BAIDU, in foreign countries, gg, fb, etc ----------------------------------------------Using tx as an Example1. Upload a swf file to the qq domain. it is difficult, but now act3.qq.com has completely paused FLASH upload 2. Looking for the existing swf xss vulnerability, the difficulty is much lower than above, but one by one go swf for analysis, what we can't do is to quickly analyze the possible xss location and ask gainover for A. Search for site: qq.com filetype: swf. Of course, you can also enable swf to capture and access qq's website B, go down to C, and use the shuosi flashing genie to open the selected swf material one by one --- action. Open any action and search for navigateToURL ExternalInterface on it. call, text (note that there are spaces after the comma) Search for all AS files and analyze them again. Can we control the variables? An actual example:JWPlayer Xss 0day [Flash programming security issues] 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.