Aerosol Posted December 30, 2014 Report Posted December 30, 2014 *CNN Travel.cnn.com <http://Travel.cnn.com> XSS and Ads.cnn.com<http://Ads.cnn.com> Open Redirect Security Vulnerability**Domain:*http://cnn.com"CNN is sometimes referred to as CNN/U.S. to distinguish the Americanchannel from its international sister network, CNN International. As ofAugust 2010, CNN is available in over 100 million U.S. households.Broadcast coverage of the U.S. channel extends to over 890,000 Americanhotel rooms, as well as carriage on cable and satellite providersthroughout Canada. Globally, CNN programming airs through CNNInternational, which can be seen by viewers in over 212 countries andterritories." (Wikipedia)"As of August 2013, CNN is available to approximately 98,496,000 cable,satellite and telco television households (86% of households with at leastone television set) in the United States." (Wikipedia)*Vulnerability Description:*CNN has a security problem. It cab be exploited by XSS (Cross SiteScripting) and Open Redirect attacks.Based on news published, CNN users were hacked based on both Open Redirectand XSS vulnerabilities.According to E Hacker News on June 06, 2013, "(@BreakTheSec) came across adiet spam campaign that leverages the open redirect vulnerability in one ofthe top News organization CNN."After the attack, CNN takes measures to detect Open Redirectvulnerabilities. The measure is quite good. Almost no links are vulnerableto Open Redirect attack on CNN's website, now. It takes long time to find anew Open Redirect vulnerability that is un-patched on its website.CNN.com was hacked by Open Redirect in 2013. While the XSS attacks happenedin 2007.*<1>* "The tweet apparently shows cyber criminals managed to leverage theopen redirect security flaw in the CNN to redirect twitter users to theDiet spam websites." (E Hacker News)At the same time, the cybercriminals have also leveraged a similarvulnerability in a Yahoo domain to trick users into thinking that the linkspoint to a trusted website.Yahoo Open Redirect Vulnerabilities:http://securityrelated.blogspot.sg/2014/12/yahoo-yahoocom-yahoocojp-open-redirect.html*<2>* CNN.com XSS hackedhttp://seclists.org/fulldisclosure/2007/Aug/216*(1) CNN (cnn.com <http://cnn.com>) Travel-City Related Links XSS (crosssite scripting) Security Vulnerabilities**Domain:*http://travel.cnn.com/*Vulnerability Description:*The vulnerabilities occur at "http://travel.cnn.com/city/all" pages. Alllinks under this URL are vulnerable to XSS attacks, e.ghttp://travel.cnn.com/city/all/all/washington?page=0%2C1http://travel.cnn.com/city/all/all/tokyo/all?page=0%2C1The vulnerability can be exploited without user login. Tests were performedon Firefox (34.0) in Ubuntu (14.04) and IE (9.0.15) in Windows 7.*Poc Code:*http://travel.cnn.com/city/all/all/tokyo/all' /"><img src=xonerror=prompt(/justqdjing/)>http://travel.cnn.com/city/all/all/bangkok/all' /"><img src=xonerror=prompt(/justqdjing/)>*(1.1) Poc Video:*https://www.youtube.com/watch?v=Cu47XiDV38M&feature=youtu.be*Blog Details:*http://securityrelated.blogspot.sg/2014/12/cnn-cnncom-travel-city-related-links.html*(2) CNN cnn.com <http://cnn.com> ADS Open Redirect Security Vulnerability **Domain:*http://ads.cnn.com*Vulnerability Description:*The vulnerability occurs at "http://ads.cnn.com/event.ng" page with"&Redirect" parameter, i.e.http://ads.cnn.com/event.ng/Type=click&FlightID=92160&AdID=125504&TargetID=1346&RawValues=&Redirect=http:%2f%2fgoogle.comThe vulnerability can be attacked without user login. Tests were performedon Chrome 32 in Windows 8 and Safari 6.16 in Mac OS X v10.7.*(2.1)* Use the following tests to illustrate the scenario painted above.The redirected webpage address is "http://www.tetraph.com/blog". Supposethat this webpage is malicious.*Vulnerable URL:*http://ads.cnn.com/event.ng/Type=click&FlightID=92160&AdID=125504&TargetID=1346&RawValues=&Redirect=http:%2f%2fcnn.com*Poc Code:*http://ads.cnn.com/event.ng/Type=click&FlightID=92160&AdID=125504&TargetID=1346&RawValues=&Redirect=http:%2f%2ftetraph.com%2Fblog*(2.1) Poc Video:*https://www.youtube.com/watch?v=FE8lhDvKGN0&feature=youtu.be*Blog Detail:*http://securityrelated.blogspot.sg/2014/12/cnn-cnncom-ads-open-redirect-security.htmlThose vulnerabilities were reported to CNN in early July by Contactinformation from Here.http://edition.cnn.com/feedback/#cnn_FBKCNN_comReported by:Wang Jing, School of Physical and Mathematical Sciences, NanyangTechnological University, Singapore.http://www.tetraph.com/wangjing/*Blog Details:*http://securityrelated.blogspot.sg/2014/12/cnn-cnncom-travel-xss-and-ads-open.html--Wang JingSchool of Physical and Mathematical Sciences (SPMS)Nanyang Technological University (NTU), SingaporeSource Quote