Jump to content
b3hr0uz

Yahoo Authentication Bypass + Add/Edit/Upload privileges with SCD/FPD

Recommended Posts

Posted

Hello,

This write-up will cover how I bypassed one of Yahoo’s log-in pages with a sample trick. Even though I had decided to not write anything about this report (since it was out of scope), but a few people wanted to see the trick and I thought It would be a great thing to share with everyone else. (So please don’t bother to mention it’s out of scope and carry on with the post)

Let’s have a look at what caught my attention in the first place that led on to the attack:

SuNJ4P2.png

Which took me to the following URL:

a>

However, by clicking on any of the following links I would be redirected to a login page that kind of looks like this:

3kOMV0b.png

First step I took was to run curl and see if I am able to see the content of the files on my own server so:

curl http://tw.urcosme.fashion.yahoo.net/justbeauty/Vol/22/edit > u2.html

sto3fhn.png

Now that I know I am able to see the content I decided to switch to firefox and fire-up the good ol’ NoRedirect:

4DGwkGH.png

WE ARE IN. Here are a couple things I was able to do:

Add new content:

40KJaHd.png

Edit:

4PBp1dR.png

and I was also able to upload a file which you will be able to see here:

I was able to get the full path and MySQL credentials by messing around with POST. There was also a possible SQLi via POST in the following admin panel which I wasn’t able to exploit due to the fact that I found the bug after the initial report.

Timeline:

2014/04/18 – Reported

2014/04/18 – Triaged

2014/04/18 – Requested more information

2014/04/21 – Closed

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...