Jump to content
b3hr0uz

Yahoo Authentication Bypass + Add/Edit/Upload privileges with SCD/FPD

Recommended Posts

Hello,

This write-up will cover how I bypassed one of Yahoo’s log-in pages with a sample trick. Even though I had decided to not write anything about this report (since it was out of scope), but a few people wanted to see the trick and I thought It would be a great thing to share with everyone else. (So please don’t bother to mention it’s out of scope and carry on with the post)

Let’s have a look at what caught my attention in the first place that led on to the attack:

SuNJ4P2.png

Which took me to the following URL:

a>

However, by clicking on any of the following links I would be redirected to a login page that kind of looks like this:

3kOMV0b.png

First step I took was to run curl and see if I am able to see the content of the files on my own server so:

curl http://tw.urcosme.fashion.yahoo.net/justbeauty/Vol/22/edit > u2.html

sto3fhn.png

Now that I know I am able to see the content I decided to switch to firefox and fire-up the good ol’ NoRedirect:

4DGwkGH.png

WE ARE IN. Here are a couple things I was able to do:

Add new content:

40KJaHd.png

Edit:

4PBp1dR.png

and I was also able to upload a file which you will be able to see here:

I was able to get the full path and MySQL credentials by messing around with POST. There was also a possible SQLi via POST in the following admin panel which I wasn’t able to exploit due to the fact that I found the bug after the initial report.

Timeline:

2014/04/18 – Reported

2014/04/18 – Triaged

2014/04/18 – Requested more information

2014/04/21 – Closed

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...