I have seen some XSS in NetEase mail, which are quite rare, but I think some methods can also be used, therefore, the mailbox is packaged together with a storage type of Netease album.
1. the name of the business card is not filtered out.
First:
XSS cause: No output filter for "name"
Usage:
1) Upload a. vcf business card with the name "/> <IFRAME onload = alert (1898)> </IFRAME>
Export data on your computer or webpage and use the export function of your mailbox to import data.
2) directly modify the form through POST
2. Resume Center
When editing, many parts are not filtered and will play in many places.
The professional name is not filtered during preview.
GET form GET http://resume.mail.126.com/huntjob/nresume/create.do? Type = 1 & language = 1: A New RESUME will be created continuously, and the RESUME value of the RESUME will be returned.
Then the POST form
Modified. This should allow you to add and modify others' resumes so that others can edit or preview their resumes and execute malicious code.
3. Album
1) preview a photo in your mailbox
Preview the photo album XSS in the mailbox because the photo description is not filtered
4. view the stored XSS www.2cto.com of photos in NetEase album
The brand and model in EXIF are not filtered.
You can modify the image attributes.
PS because the image description in the album is submitted to a DWR. I am not very familiar with this aspect, so I have not conducted further tests. If this can also be used for CSRF, I can use this to modify the image description of others' photos, cause XSS to be previewed in the mailbox.
Summary:
Although these XSS seem to be very weak, they can also be used in some ways. For example, like the one I posted earlier, using CSRF to modify others' image information and add others' business cards, you can also use it as a backdoor to increase others' resumes.
PS: It's not long before you get in touch with security. If you have any mistakes, please point out and learn from each other. Thank you!
Self-testing of mailbox is very convenient .. The business card name can be changed only when the entered length is detected on the page.
Internet: http://photo.163.com/pinqy520/#m=2&aid=242173714&pid=7783267192
Point EXIF
Solution:
Amount...