Netease mailbox + album four XSS

Source: Internet
Author: User

I have seen some XSS in NetEase mail, which are quite rare, but I think some methods can also be used, therefore, the mailbox is packaged together with a storage type of Netease album.

1. the name of the business card is not filtered out.
First:

 

XSS cause: No output filter for "name"
Usage:
1) Upload a. vcf business card with the name "/> <IFRAME onload = alert (1898)> </IFRAME>

 

Export data on your computer or webpage and use the export function of your mailbox to import data.

2) directly modify the form through POST

 


2. Resume Center
When editing, many parts are not filtered and will play in many places.
The professional name is not filtered during preview.

 


GET form GET http://resume.mail.126.com/huntjob/nresume/create.do? Type = 1 & language = 1: A New RESUME will be created continuously, and the RESUME value of the RESUME will be returned.
Then the POST form

 

Modified. This should allow you to add and modify others' resumes so that others can edit or preview their resumes and execute malicious code.

3. Album
1) preview a photo in your mailbox

 

Preview the photo album XSS in the mailbox because the photo description is not filtered

4. view the stored XSS www.2cto.com of photos in NetEase album
The brand and model in EXIF are not filtered.
You can modify the image attributes.

 
 

PS because the image description in the album is submitted to a DWR. I am not very familiar with this aspect, so I have not conducted further tests. If this can also be used for CSRF, I can use this to modify the image description of others' photos, cause XSS to be previewed in the mailbox.

Summary:
Although these XSS seem to be very weak, they can also be used in some ways. For example, like the one I posted earlier, using CSRF to modify others' image information and add others' business cards, you can also use it as a backdoor to increase others' resumes.

PS: It's not long before you get in touch with security. If you have any mistakes, please point out and learn from each other. Thank you!


Self-testing of mailbox is very convenient .. The business card name can be changed only when the entered length is detected on the page.

Internet: http://photo.163.com/pinqy520/#m=2&aid=242173714&pid=7783267192

Point EXIF


Solution:

Amount...
 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.