Saturday, 7 November 2015

Daily Mail Online Website XSS Cyber Security Zero-Day Vulnerability

Daily Mail Online Website XSS Cyber Security Zero-Day Vulnerability


Website Description:

"The Daily Mail is a British daily middle-market tabloid newspaper owned by the Daily Mail and General Trust. First published in 1896 by Lord Northcliffe, it is the United Kingdom's second biggest-selling daily newspaper after The Sun. Its sister paper The Mail on Sunday was launched in 1982. Scottish and Irish editions of the daily paper were launched in 1947 and 2006 respectively. The Daily Mail was Britain's first daily newspaper aimed at the newly-literate "lower-middle class market resulting from mass education, combining a low retail price with plenty of competitions, prizes and promotional gimmicks", and was the first British paper to sell a million copies a day. It was at the outset a newspaper for women, the first to provide features especially for them, and as of the second-half of 2013 had a 54.77% female readership, the only British newspaper whose female readers constitute more than 50% of its demographic. It had an average daily circulation of 1,708,006 copies in March 2014. Between July and December 2013 it had an average daily readership of approximately 3.951 million, of whom approximately 2.503 million were in the ABC1 demographic and 1.448 million in the C2DE demographic. Its website has more than 100 million unique visitors per month." (Wikipedia)


Domain Name:

http://www.dailymail.co.uk/


The Alexa rank of it is 93 on January 01 2015. It is one of the most popular websites in the United Kingdom.







(1) Vulnerability description:

Daily Mail has a security problem. Criminals can exploit it by XSS attacks.

The vulnerability occurs at "reportAbuseInComment.html?" page with "&commentId" parameter, i.e.

http://www.dailymail.co.uk/home/reportAbuseInComment.html?articleId=346288&commentId=877038


POC Code:

http://www.dailymail.co.uk/home/reportAbuseInComment.html?articleId=346288&commentId="><img src=x onerror=prompt('justqdjing')>























The vulnerability can be attacked without user log in. Tests were performed on Mozilla Firefox (34.0) in Ubuntu (14.04) and Microsoft IE (9.0.15) in Windows 7.




Poc Video:

https://www.youtube.com/watch?v=Oig-ZrlJDf8&feature=youtu.be



Blog Detail:

http://tetraph.com/security/web-security/daily-mail-xss-bug/
http://securityrelated.blogspot.com/2015/10/daily-mail-online-website-xss-cyber.html
https://vulnerabilitypost.wordpress.com/2015/10/30/daily-mail-xss/





(2) What is XSS?

"Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side script into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy. Cross-site scripting carried out on websites accounted for roughly 84% of all security vulnerabilities documented by Symantec as of 2007. Their effect may range from a petty nuisance to a significant security risk, depending on the sensitivity of the data handled by the vulnerable site and the nature of any security mitigation implemented by the site's owner." (Wikipedia)






(3) Vulnerability Disclosure:

This vulnerability has been patched.






Discoved and Disclosured By:

Wang Jing, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. (@justqdjing)
http://www.tetraph.com/wangjing







Reference:

https://packetstormsecurity.com/files/134189/Daily-Mail-Unvalidated-Redirect
http://news.softpedia.com/news/the-telegraph-and-daily-mail-fix-xss
https://www.secnews.gr/dailymail_open_redirect_bug
http://whitehatview.tumblr.com/post/132726489926/daily-mail-xss
http://sys-secure.es/daily-mail-registration-page-unvalidated
http://itsecuritynews.info/tag/jing-wang/
http://itsecurity.lofter.com/post/1cfbf9e7_8d45d6b
http://computerobsess.blogspot.com/2015/11/daily-mail-xss.html
https://computertechhut.wordpress.com/2015/11/04/daily-mail-xss/
http://marc.info/?l=full-disclosure&m=144651836427184&w=4


Daily Mail Registration Page Unvalidated Redirects and Forwards & XSS Web Security Problem

Daily Mail Registration Page Unvalidated Redirects and Forwards & XSS Web Security Problem


Website Description:
"The Daily Mail is a British daily middle-market tabloid newspaper owned by the Daily Mail and General Trust. First published in 1896 by Lord Northcliffe, it is the United Kingdom's second biggest-selling daily newspaper after The Sun. Its sister paper The Mail on Sunday was launched in 1982. Scottish and Irish editions of the daily paper were launched in 1947 and 2006 respectively. The Daily Mail was Britain's first daily newspaper aimed at the newly-literate "lower-middle class market resulting from mass education, combining a low retail price with plenty of competitions, prizes and promotional gimmicks", and was the first British paper to sell a million copies a day. It was at the outset a newspaper for women, the first to provide features especially for them, and as of the second-half of 2013 had a 54.77% female readership, the only British newspaper whose female readers constitute more than 50% of its demographic. It had an average daily circulation of 1,708,006 copies in March 2014. Between July and December 2013 it had an average daily readership of approximately 3.951 million, of whom approximately 2.503 million were in the ABC1 demographic and 1.448 million in the C2DE demographic. Its website has more than 100 million unique visitors per month." (Wikipedia)


One of its website's Alexa rank is 93 on January 01 2015. The website is one of the most popular websites in the United Kingdom.


The Unvalidated Redirects and Forwards problem has not been patched, while the XSS problem has been patched.






(1) Daily mail Registration Page Unvalidated Redirects and Forwards Web Security Problem


(1.1) Vulnerability Description:
Daily online websites have a cyber security problem. Hacker can exploit it by Open Redirect (Unvalidated Redirects and Forwards) attacks. During the tests, all Daily mail websites (Daily Mail, Mail on Sunday & Metro media group) use the same mechanism. These websites include dailymail.co.uk, thisismoney.co.uk, and mailonsunday.co.uk.















































Google Dork:
"Part of the Daily Mail, The Mail on Sunday & Metro Media Group"


The vulnerability occurs at "&targetUrl" parameter in "logout.html?" page, i.e.
http://www.dailymail.co.uk/registration/logout.html?targetUrl=http%3A%2F%2Fgoogle.com






(1.2.1) Use the following tests to illustrate the scenario painted above.

The redirected webpage address is "http://diebiyi.com/articles". Can suppose that this webpage is malicious.

Vulnerable URLs:


POC Code:




POC Video:



Blog Details:



(1.2.2) The program code flaw can be attacked without user login. Tests were performed on Microsoft IE (9 9.0.8112.16421) of Windows 8, Mozilla Firefox (37.0.2) & Google Chromium 42.0.2311 (64-bit) of Ubuntu (14.04.2),and Apple Safari 6.1.6 of Mac OS X v10.9 Mavericks.

These bugs were found by using URFDS (Unvalidated Redirects and Forwards Detection System).





(1.2) Description of Open Redirect:
Here is the description of Open Redirect: "A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks. An http parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. Because the server name in the modified link is identical to the original site, phishing attempts have a more trustworthy appearance." (From CWE)




(1.3) Vulnerability Disclosure:
These vulnerabilities have not been patched.






(2) Daily Mail Website XSS Cyber Security Zero-Day Vulnerability


(2.1) Vulnerability description:
DailyMail has a security problem. Criminals can exploit it by XSS attacks.

The vulnerability occurs at "reportAbuseInComment.html?" page with "&commentId" parameter, i.e.
http://www.dailymail.co.uk/home/reportAbuseInComment.html?articleId=346288&commentId=877038



POC Code:
http://www.dailymail.co.uk/home/reportAbuseInComment.html?articleId=346288&commentId="><img src=x onerror=prompt('justqdjing')>




The vulnerability can be attacked without user login. Tests were performed on Mozilla Firefox (34.0) in Ubuntu (14.04) and Microsoft IE (9.0.15) in Windows 7.
























(2.2) What is XSS?
"Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side script into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy. Cross-site scripting carried out on websites accounted for roughly 84% of all security vulnerabilities documented by Symantec as of 2007. Their effect may range from a petty nuisance to a significant security risk, depending on the sensitivity of the data handled by the vulnerable site and the nature of any security mitigation implemented by the site's owner." (Wikipedia)




(2.3) Vulnerability Disclosure:
This vulnerability has been patched.




Discover and Reporter:
Wang Jing, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. (@justqdjing)







TeleGraph All Photo (Picture) Pages Have Been Vulnerable to XSS Cyber Attacks

TeleGraph All Photo (Picture) Pages Have Been Vulnerable to XSS Cyber Attacks


Website Description:

http://www.telegraph.co.uk


"The Daily Telegraph is a British daily morning English-language broadsheet newspaper, published in London by Telegraph Media Group and distributed throughout the United Kingdom and internationally. The newspaper was founded by Arthur B. Sleigh in June 1855 as The Daily Telegraph and Courier, and since 2004 has been owned by David and Frederick Barclay. It had a daily circulation of 523,048 in March 2014, down from 552,065 in early 2013. In comparison, The Times had an average daily circulation of 400,060, down to 394,448. The Daily Telegraph has a sister paper, The Sunday Telegraph, that was started in 1961, which had circulation of 418,670 as of March 2014. The two printed papers currently are run separately with different editorial staff, but there is cross-usage of stories. News articles published in either, plus online Telegraph articles, may also be published on the Telegraph Media Group's www.telegraph.co.uk website, all under The Telegraph title." (From Wikipedia)





(1) Vulnerability Description:

Telegraph has a Web security bug problem. It is vulnerable to XSS attacks. In fact, all its photo pages are vulnerable to XSS (Cross-Site Scripting) vulnerabilities. Telegraph's picture pages use "&frame" as its parameter. All its web pages use "&frame" are vulnerable to the bugs. Those vulnerabilities have been patched now.


Examples of Vulnerable Links:

http://www.telegraph.co.uk/culture/culturepicturegalleries/10663967/The-worlds-most-spectacular-theatres.html?frame=2836095
http://www.telegraph.co.uk/property/investmentinproperty/10609314/For-sale-top-20-properties-ripe-for-investment.html?frame=2808162
http://www.telegraph.co.uk/foodanddrink/foodanddrinkpicturegalleries/9737226/Elephant-dung-coffee-Black-Ivory-beans-passed-through-the-animals-guts.html?frame=2424280
http://www.telegraph.co.uk/education/9487434/Graduate-jobs-Best-languages-to-study.html?frame=2314790
http://www.telegraph.co.uk/motoring/picturegalleries/10782171/The-20-best-cars-to-own-in-2014.html?frame=2890278



POC Code:

http://www.telegraph.co.uk/culture/culturepicturegalleries/10663967/The-worlds-most-spectacular-theatres.html?frame=2836095"><img src=x onerror=prompt('justqdjing')>
http://www.telegraph.co.uk/property/investmentinproperty/10609314/For-sale-top-20-properties-ripe-for-investment.html?frame=2808162"><img src=x onerror=prompt('justqdjing')>
http://www.telegraph.co.uk/foodanddrink/foodanddrinkpicturegalleries/9737226/Elephant-dung-coffee-Black-Ivory-beans-passed-through-the-animals-guts.html?frame=2424280"><img src=x onerror=prompt('justqdjing')>
http://www.telegraph.co.uk/education/9487434/Graduate-jobs-Best-languages-to-study.html?frame=2314790"><img src=x onerror=prompt('justqdjing')>
http://www.telegraph.co.uk/motoring/picturegalleries/10782171/The-20-best-cars-to-own-in-2014.html?frame=2890278"><img src=x onerror=prompt('justqdjing')>


The vulnerability can be attacked without user login. Tests were performed on Firefox (37.02) in Ubuntu (14.04) and IE (8.0. 7601) in Windows 7. The bugs found by using CSXDS.






































































(2) XSS Description:

The description of XSS is: "Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted web sites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user within the output it generates without validating or encoding it." (OWSAP)




Poc Video:

https://www.youtube.com/watch?v=SqjlabJ1OzA&feature=youtu.be





Blog Details:

http://www.tetraph.com/security/website-test/telegraph-xss/
http://securityrelated.blogspot.com/2015/10/telegraph-xss-0day.html
https://vulnerabilitypost.wordpress.com/2015/10/30/telegraph-bug/





(3) Vulnerability Disclosure:

Those vulnerabilities are patched now.





Discoved and Disclosured By:

Wang Jing, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. (@justqdjing)
http://www.tetraph.com/wangjing








References:
http://lists.openwall.net/full-disclosure/2015/11/03/7
http://permalink.gmane.org/gmane.comp.security.fulldisclosure/2642
https://www.mail-archive.com/fulldisclosure%40seclists.org/msg02682.html
https://cxsecurity.com/issue/WLB-2015110023
http://marc.info/?l=full-disclosure&m=144651821527165&w=4
http://germancast.blogspot.com/2015/11/telegraph-xss.html
http://itsecurity.lofter.com/post/1cfbf9e7_8d3ea9e








Wednesday, 14 October 2015

心的回归 - 这一生,我们都走在回家的路上
















这一生,我们都走在回家的路上。


回家,永远是我心中无法解开的情节。无论身在何处,我的心永远是朝着家的方向,它在一角默默的绽开,灯火阑珊处映射着家的绚丽。


家,也将是一个多么令人心痛的字眼。离家之后才明白对家是多么的不舍,张开的翅膀听到它也会微微一颤,纵然身躯多么矫健,臂膀多么宽厚,在家的面前也将是脆弱无力。


夜 深,烟花升,灯火明。多少人已经离开了家,多少人将要离开家,又有多少人想要回家。多少人在异地不经意的抬头,看见烟火绚烂的绽放,失落感油然而生,可 为了所谓的梦想,多少人无可奈何,百感交集。家里的灯火或许没那么美丽,烟花或许没那么灿烂,但是自己的内心仍能感受到家的体温,它像母亲的双手般温暖, 父亲的教导般纯朴,亲人的劝告般温馨。它流在你的血液里,扎根在你的骨髓中。它无时不刻不在提醒你,让心回家。


公益回家的广告,煽动了我 们多少泪点,也唤醒了我久已沉睡的心。父母在,不远行。直到今天我才大彻大悟,这句话说了两千年,可有多少人才能明白它的真谛? 有多少人能按照它的旨意前行?起码我不是,以前不是。我不得不悔恨自己,悔恨当初。曾经一心想飞,想离家远远的,越远越好。抛开一切,逃避束缚,为了所谓 的梦想,可怜的父母,在所谓面前低人一等,而他们没有半句怨言,依然在静静的支持你,鼓励你。背后的辛酸与泪水你看不到,你看到的只是灯红酒绿,你看到的 只是金钱与权力,你看到的只是名声与羡慕!你眼里只有你所谓的成功,只有你的片刻的掌声与欢笑。你没有看到,父母的孤独与寂寞,他们什么都不需要,只要你 的陪伴与电话!他们只想要一个完整的你,一个健康快乐的你。有时候他们只是想见你一面,想听听你的声音,这你都不能满足,又怎能谈成功?


我 欠他们的太多了,多的一辈子都无法弥补,这是一种罪,天大的罪,罄竹难书。我们太吝啬了,小气到在家就不曾说句感激的话,不曾多一些时间多陪一陪他们。 而我们呢,很忙,真的很忙。我们忙什么了?睡觉?玩电脑?玩手机?聚会?是啊,是挺忙的。我们给了他们多少时间?一日两餐吗?


内疚是失败 者 的独白,但却是良心的谴责。当车票买到手的那刻,我知道我对父母的歉疚只能加深而不能弥补了。远行,我甚至有些反感了,多少次我扪心自问,按 照这样的走法,与父母的相处机会可是真的屈指可数了。相信很多远行者都是一年回家两次,按照这个算法,我们回家的次数还能过百吗?


永远不会 忘记,我们是中国人,百善孝为先。如果我连最基本的都做不到,我就是一个一事无成的人,一个不完整的人。每次离家我都会躲避母亲的眼神,那是失 望,期望,坚定的汇总。仔细想想,我最基本的责任都没尽到,其他还有什么可谈。家,永远是我们梦境也是我们自己创造的,是我们大脑存在的凌乱的记忆碎片在 梦中被一种无形的力量加以整合与编造,使之存在短暂的真实感,并伴随着醒来渐渐消退。的港湾,心中没有家的人永远是一个失败者。


无论多久,它总会在梦中出现,不论多远,我们不会停止奔跑的脚步,朝着家的方向。将来的将来,我不再迷茫,不再没有目的的追求,不走没有结果的旅程。家,永远是我的落脚点,让心回家,回到父母身边,弥补欠下的债。



这一生,我们都走在回家的路上。






转载自蝶比翼美文:
http://diebiyi.com/articles/essay/home-back/

Thursday, 1 October 2015

Five Important Work Suggestion - Very Useful for Success
















This post is in partnership with Time. The article below was originally published at Time.com

With so much career advice floating around the interwebs, some of it is bound to be poor. Luckily we here at Levo don’t just trust the haphazardly doled-out opinions of self-appointed “leadership experts” and other dubious characters. We go straight to the top—men and women who have worked their way to massive career success — and ask them. What strategies actually worked for them? Which career buzz phrases should be ignored completely? Here are a few pieces of career advice that you should never follow.

1. “Always have a five-year plan.”
Haven’t you heard? Five-year plans are out, pivoting is in. Having tangible goals is awesome and necessary, but trying to plan out the next five years of your life is neither. The best opportunities are often those that you don’t see coming. Being too stuck to your “five-year plan” inhibits you from taking opportunities as they arise, and pivoting in new directions.

2. “Don’t be a job hopper.”
There are worse things to be. Namely, the quiet loyal workhorse who never leaves or makes the money she deserves. It’s a new economy people, job hopping is becoming the norm. These days, employees who stay in companies for longer than two years earn 50% less over their lifetimes. So yes, be gracious and respectful to each and every one of your employers, but certainly don’t stay in a position for fear of being labeled “a job hopper.”

3. “Follow the money.” / “Just do what you love and the money will follow.”
Equally bad advice, from opposite ends of the spectrum. Following the money with complete disregard for your interests is a surefire path toward a soul-sucking career doing something you hate. It may not even be the best financial move in the long term. On the other side of that coin, doing what you love with the expectation that financial success will miraculously follow is naive and ridiculous. As Kate White always says, think about where your interests and talents intersect with the greatest potential for financial success, and head toward those points of intersection.

4. “Don’t be too grabby. Let your work speak for itself.”
This is the kind of advice your Middle Eastern grandfather who owned a small business 40 years ago might give you (not from personal experience or anything). Even if it means well, it is just not true. Remember that episode of New Girl? Jess wants to be vice principal of her school: “I’m just hoping, you know in a few years, I’ll have enough experience that Dr. Foster will consider me for Vice Principal.” Coach asks, “Why don’t you just ask for it?” Jess says, “You can’t just ask for a promotion, you know, you have to earn the promotion with years of hard work.” Coach laughs. Please, don’t be Jess.

5. “Don’t waste time applying to jobs you know you won’t get.”
We just published a great piece from the Personal Branding Blog that addresses this very topic. Just because you think a particular job is a reach or you’re not the ideal fit, that doesn’t mean you shouldn’t apply. Within limits of course—don’t start applying for wedding photographer assistant positions if you want to be a pharmacist (unless you’ve always cultivated a secret passion for photography of course). Every job you apply to is an opportunity to tighten up your resume, hone your interview skills, and build confidence, which is never a waste of time.


Article From InZeed:
http://www.inzeed.com/kaleidoscope/life/work-useful-suggestion/

Sunday, 27 September 2015

VuFind 1.0 Reflected XSS (Cross-site Scripting) Application 0-Day Web Security Bug

VuFind 1.0 Reflected XSS (Cross-site Scripting) Application 0-Day Web Security Bug



Exploit Title: VuFind Results? &lookfor parameter Reflected XSS Web Security Vulnerability

Product: VuFind
Vendor: VuFind
Vulnerable Versions: 1.0
Tested Version: 1.0
Advisory Publication: September 20, 2015
Latest Update: September 25, 2015
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference:
Impact CVSS Severity (version 2.0):
CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6
CVSS Version 2 Metrics:
Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism
Access Complexity: Medium
Authentication: Not required to exploit
Impact Type: Allows unauthorized modification
Discover and Reporter: Wang Jing [School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore] (@justqdjing)








































Caution Details:



(1) Vendor & Product Description:



Vendor:

VuFind



Product & Vulnerable Versions:

VuFind
1.0



Vendor URL & Download:

Product can be obtained from here,
http://sourceforge.net/p/vufind/news/




Product Introduction Overview:

"VuFind is a library resource portal designed and developed for libraries by libraries. The goal of VuFind is to enable your users to search and browse through all of your library's resources by replacing the traditional OPAC to include: Catalog Records, Locally Cached Journals, Digital Library Items, Institutional Repository, Institutional Bibliography, Other Library Collections and Resources. VuFind is completely modular so you can implement just the basic system, or all of the components. And since it's open source, you can modify the modules to best fit your need or you can add new modules to extend your resource offerings. VuFind runs on Solr Energy. Apache Solr, an open source search engine, offers amazing performance and scalability to allow for VuFind to respond to search queries in milliseconds time. It has the ability to be distributed if you need to spread the load of the catalog over many servers or in a server farm environment. VuFind is offered for free through the GPL open source license. This means that you can use the software for free. You can modify the software and share your successes with the community! Take a look at our VuFind Installations Wiki page to see how a variety of organizations have taken advantage of VuFind's flexibility. If you are already using VuFind, feel free to edit the page and share your accomplishments. "






(2) Vulnerability Details:

VuFind web application has a computer security problem. Hackers can exploit it by reflected XSS cyber attacks. This may allow a remote attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server.

Several other similar products 0-day vulnerabilities have been found by some other bug researchers before. VuFind has patched some of them. "scip AG was founded in 2002. We are driven by innovation, sustainability, transparency, and enjoyment of our work. We are completely self-funded and are thus in the comfortable position to provide completely independent and neutral services. Our staff consists of highly specialized experts who focus on the topic information security and continuously further their expertise through advanced training".



(2.1) The code flaw occurs at "lookfor?" parameter in "/vufind/Resource/Results?" page.


Some other researcher has reported a similar vulnerability here and VuFind has patched it.

https://vufind.org/jira/si/jira.issueviews:issue-html/VUFIND-54/VUFIND-54.html







(3) Solution:

Update to new version.









References:

http://tetraph.com/security/xss-vulnerability/vufind-xss/
http://russiapost.blogspot.ru/2015/09/vufind-xss-issue.html
https://infoswift.wordpress.com/2015/09/25/vufind-issue/
http://www.openwall.com/lists/oss-security/2015/09/25/2
http://whitehatview.tumblr.com/post/129834589981/vufind-xss-bugs 
http://itsecurity.lofter.com/post/1cfbf9e7_854cb25
https://progressive-comp.com/?l=oss-security&m=144316469829656&w=1
http://essayjeans.blog.163.com/blog/static/23717307420158253407863/
http://seclists.org/oss-sec/2015/q3/639
http://frenchairing.blogspot.fr/2015/09/vufind-bug.html
https://itswift.wordpress.com/2015/09/22/vufind-0day/
http://permalink.gmane.org/gmane.comp.security.oss.general/17836