Stored XSS in an iPhone (the database address and other information have been returned)

Source: Internet
Author: User

Stored XSS in an iPhone (the database address and other information have been returned)

0x01
Someone recommended me a software called one password that day:


 


 
This can be synchronized to the cloud, and password transmission can be performed on different terminals.
But what does it have to do with today's vulnerabilities?
The cloud used by this software is different from others' cloud. It uses iCloud:


 
Start test:
It has remarks and login information that can be saved or synchronized to the cloud:


 
We insert code in the remarks and login information locations (other locations are also required:



 


 
Then synchronize to iCloud:


 
Then return the cookie:


 
The two locations are different, indicating that the two locations are inserted at different locations.
0x02
(1) first, why is the iPhone xss, not ios, because it uses third-party software rather than the system itself.
(2) Is this stored xss or self xss? What the team thinks is self-plug... You know ..
 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.