kempactick Posted August 26, 2013 Report Share Posted August 26, 2013 (edited) Salut! am gasit azi 12 xss intr-un subdomeniu din google si cateva persistente...#Exploit: *.google.com - Cross-Site-Scripting#Author: kempactick#Target: Google#Status: Waiting for an response#PoC: http://s16.postimg.org/awgzdt2ad/Untitled.jpghttp://s2.postimg.org/5m7tyu855/test.jpgVoi face in curand un V.P.o.C cu toate xss-urile. Edited August 27, 2013 by kempactick Link to comment Share on other sites More sharing options...
BLODAS666 Posted August 26, 2013 Report Share Posted August 26, 2013 Hall of fame is yours... Link to comment Share on other sites More sharing options...
Silviu Posted August 26, 2013 Report Share Posted August 26, 2013 E bine mosule, o sa devii milionar Link to comment Share on other sites More sharing options...
SilenTx0 Posted August 26, 2013 Report Share Posted August 26, 2013 12 xss-uri intr-o zi?Altii nu gaasesc atat in toata viata.Greu de crezut, asteptam V.P.o.C-ul Link to comment Share on other sites More sharing options...
dekeeu Posted August 26, 2013 Report Share Posted August 26, 2013 Fa-mi te rog o favoare si dai un alert(document.domain) .Mersi. Link to comment Share on other sites More sharing options...
Active Members akkiliON Posted August 26, 2013 Active Members Report Share Posted August 26, 2013 (edited) OFF: Ce bine dorm cu ochii deschi?i !Copy/Paste ! Thank you ( ?tii la ce m? refer )ON: Nu cred a?a ceva. Sorry. Daca tot zici c? o s? faci un V.P.o.C, a?tept?m ! Edited August 26, 2013 by akkiliON Link to comment Share on other sites More sharing options...
SilenTx0 Posted August 26, 2013 Report Share Posted August 26, 2013 (edited) Fa-mi te rog o favoare si dai un alert(document.domain) .Mersi.Asta as fi vrut si eu pentru ca nu prea cred.Mi-a spus florin ca l-a intrebat pe el daca este xss ala si cum sa il raporteze ceea ce ma face sa cred ca nu a gasit 12 xss-uri ci un xss si a folosit 12 vectori. Pare incepator Le: Din cate vad eu, google e scris cu gri.In general subdomeniile sunt scrise cu gri.Cred ca ce ai gasit tu e xss intr-un site cu subdomeniu google.blablabla sau ceva de genu (daca exista asa ceva). Trebuia sa nu cenzurezi partea de dupa google. Edited August 26, 2013 by SilenTx0 Link to comment Share on other sites More sharing options...
Active Members dancezar Posted August 26, 2013 Active Members Report Share Posted August 26, 2013 Fa-mi te rog o favoare si dai un alert(document.domain) .Mersi.Dap da print la document.domain asa stim sigur daca este google si nu google.ceva.com Link to comment Share on other sites More sharing options...
Renegade Posted August 26, 2013 Report Share Posted August 26, 2013 si nici in stanga jos nu apare acel "Transfering data from.."daca gresesc corectati-ma Link to comment Share on other sites More sharing options...
puscarie Posted August 26, 2013 Report Share Posted August 26, 2013 mare fake. Link to comment Share on other sites More sharing options...
florin_darck Posted August 26, 2013 Report Share Posted August 26, 2013 Waiting for VPOC. 12 xss-uri in google .. nu stiu cata lume mai reuseste asta Link to comment Share on other sites More sharing options...
Active Members akkiliON Posted August 26, 2013 Active Members Report Share Posted August 26, 2013 Waiting for VPOC. 12 xss-uri in google .. nu stiu cata lume mai reuseste astaE fake. Daca privesti mai atent google e subdomeniu ( are culoarea gri ) ! De obicei subdomeniul apare cu gri. Parerea mea este ca e fake acest xss. Link to comment Share on other sites More sharing options...
a1234 Posted August 26, 2013 Report Share Posted August 26, 2013 Yes this is fake. You can tell the https: and google are the same colors.With actual https it's lighter gray. Link to comment Share on other sites More sharing options...
Darkb0t Posted August 27, 2013 Report Share Posted August 27, 2013 play.google.com, and this is the page that contains xsscongrats, great find, hall of fame + money in the bank account XD Link to comment Share on other sites More sharing options...
FarSe Posted August 27, 2013 Report Share Posted August 27, 2013 12 xssuri in google? ce dracu ma, au facut romanii acel subdomain? vezi ca e si sqli! Link to comment Share on other sites More sharing options...
H3xoR Posted August 27, 2013 Report Share Posted August 27, 2013 (edited) De la 3 la 12? Bravo! Edited August 27, 2013 by H3xoR Link to comment Share on other sites More sharing options...
kempactick Posted August 27, 2013 Author Report Share Posted August 27, 2013 http://s2.postimg.org/5m7tyu855/test.jpg , unul persistentis not fake.V.P.o.C(s): Soon! thanks h3x Link to comment Share on other sites More sharing options...
poq Posted August 27, 2013 Report Share Posted August 27, 2013 Dar ce e dupa google? Link to comment Share on other sites More sharing options...
Gotyc Posted August 27, 2013 Report Share Posted August 27, 2013 de ce ai dat cautare pe rst?) Link to comment Share on other sites More sharing options...
kempactick Posted August 27, 2013 Author Report Share Posted August 27, 2013 @ poqu , pai ce sa fie ? @gotyc, sa vad posturile de securitate. Link to comment Share on other sites More sharing options...
malsploit Posted August 27, 2013 Report Share Posted August 27, 2013 @kempactick daca or sa mai zica multi ca e fake, o sa fiu nevoit sa iti cer o dovada sau sa o prezinti tu unui administrator. Link to comment Share on other sites More sharing options...
SilenTx0 Posted August 27, 2013 Report Share Posted August 27, 2013 Mda, nu sunt fake.Mi-a dat 2-3 xss-uri.Sunt in niste subdomenii pe care va lua (daca va lua) 100$.Si ca sa clarificam, google era scris cu gri pentru ca a cenzurat ce nu trebuie Link to comment Share on other sites More sharing options...
d33nis Posted August 27, 2013 Report Share Posted August 27, 2013 OFF: @kempactick,Be the best, fuck the restBe the one, not anyone. ON: Foarte frumos, asteptam V.P.o.C Link to comment Share on other sites More sharing options...
TheTime Posted August 27, 2013 Report Share Posted August 27, 2013 Hai sa ne intelegem, googleceva.com nu este subdomeniu al google.com, nu este acelasi lucru cu ceva.google.com.Poate este vreun alt site ce apartine companiei Google unde nu poti face mai nimic cu un xss.Diferente intre cele 2 cazuri sunt multe. Preferata mea, cu un xss intr-un subdomeniu inutil precum code.google.com poti face bypass la same origin policy pentru google.com sau alte subdomenii sensibile (doar in anumite cazuri, descoperiti voi care). Deci, pana la urma, ce sa fie? Subdomeniu google.com sau un alt domeniu ce apartine companiei Google? Link to comment Share on other sites More sharing options...
SilenTx0 Posted August 27, 2013 Report Share Posted August 27, 2013 Erau niste subdomenii ale unor site-uri ce apartin de google foarte vechi, i-au spus ca sunt izolate si ca blablabla si nu ia nimic pe ele:) Link to comment Share on other sites More sharing options...