Netease series mailbox versions with long-lasting mail titles xss
Netease 126 yeah 163 5.0 users can receive all emails from each other when they open their inbox. Netease mailbox 5.0 still has a large number of users, because 5.0 is relatively simple and fast to load, so my mailbox has not been set to a new version since registration, 5.0 of users may be set to 6.0 at the beginning of this year, but vice versa.
If a single sign-on mailbox has a cookie, all emails can be received through webmail. Here we only look at xss
The cause is that 163 of wap mailboxes do not strictly filter attachment names. Through wap, attackers can send attack emails to other Netease mailbox users, which are triggered when the email recipient opens the inbox.
This is because the process is cumbersome and is not suitable for the burp demonstration.
Network Disk sharing poc C # program and source code
Link: http://pan.baidu.com/s/1sjSuQwl password: 5vrw
The Email recipients and senders in the poc are fixed.
3Bconsole. log % 281% 29% 3B % 2F % 2F'
Add console. log to prove xss
Log On with the 126 email address in the poc source code, click the inbox, and check that the console outputs a lot.
Netease has the same effect on other types of mailboxes as 5.0.