Author Topic: XSS in Evilzone  (Read 1193 times)

0 Members and 1 Guest are viewing this topic.

Offline ShadowCloud

  • Serf
  • *
  • Posts: 33
  • Cookies: 31
  • -My word is my bond
    • View Profile
XSS in Evilzone
« on: November 25, 2015, 09:13:50 pm »
So with the blessing from iTpHo3NiX I present to you a fun little story of finding a XSS vulnerability on the site.

We were messing around on IRC and someone jokingly told a new member the challenge was to find XSS in evilzone :

Quote
<AndroUser> 12 tasks ?
<blacknieve> Oh if only it were that easy.
<davinci> you must deface a website in the name of puddi
<AndroUser> will try
<blacknieve> And impress dr. m0rph.
<parad0x> AndroUser, find Xss in EZ
<parad0x> don't kill me for this :p
<AndroUser> ill pass on that para
<parad0x> show on IRC a proof of your Xss finding in the forums
<blindfuzzy> lol
<parad0x> we'll make you admin
<parad0x> the moment you do that

I figured, heck why not give it a shot?

I messed around with the main forum for a while and found some interesting things on the forum settings with regards to the time format (You can really confuse yourself by putting some garbage values in there) but it seemed to sanitize the input properly.  Then I remember the IRC stats page seems to be a little non standard and could be vulnerable.  After messing around I realized this really only shows values and I can't find a parameter to inject.

Then I figured, hey, there's still the wiki...

I was checking the pages on the wiki and the associated parameters with these requests, I was watching the requests in the developer toolbar and noted an error being returned :

Quote
The XSS Auditor refused to execute a script in  [url] because its source code was found within the request. The auditor was enabled as the server sent neither an 'X-XSS-Protection' nor 'Content-Security-Policy' header.

Bingo, fired up Firefox and resent the request and bam.  XSS vulnerability discovered.

Luckily iTpHo3NiX was online (being the only admin I'd really been in contact with) so I disclosed the vulnerability and within minutes (Like not even 5) Ande had stepped in and patched it.
QA Engineer walks into a bar. Orders a beer. Orders 0 beers. Orders 999999999 beers. Orders a lizard. Orders -1 beers. Orders a sfdeljknesv.

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: XSS in Evilzone
« Reply #1 on: November 25, 2015, 09:15:53 pm »
This is a true story and goes to show that Shadow is awesome :-P
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline blindfuzzy

  • VIP
  • Peasant
  • *
  • Posts: 86
  • Cookies: 34
    • View Profile
Re: XSS in Evilzone
« Reply #2 on: November 25, 2015, 09:23:07 pm »
Nice find!

Offline 0E 800

  • Not a VIP
  • VIP
  • Baron
  • *
  • Posts: 895
  • Cookies: 131
  • • тнε ιηтεяηεт ιs мү яεcүcℓε-вιη •
    • View Profile
Re: XSS in Evilzone
« Reply #3 on: November 25, 2015, 09:36:33 pm »
Fuck yeah broski. Don't spoil your dinner but have a cookie.
The invariable mark of wisdom is to see the miraculous in the common.

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Re: XSS in Evilzone
« Reply #4 on: November 26, 2015, 02:39:23 am »
Dude, how will he rank up now? it was his task... btw that somebody is me, if you didn't forget. Nice work though.

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: XSS in Evilzone
« Reply #5 on: November 26, 2015, 03:45:30 am »
Well, they lied about the admin part but meh. You deserve to rank up as you go.
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]

Offline chris

  • EZ's GOD
  • VIP
  • Knight
  • *
  • Posts: 197
  • Cookies: 37
  • What should I put here :(
    • View Profile
Re: XSS in Evilzone
« Reply #6 on: November 26, 2015, 03:51:12 am »
GJ man... I like you... Have a cookie...
<chris1> give me a idea of a img to use for a avatar
<HTH> A cock

Offline ShadowCloud

  • Serf
  • *
  • Posts: 33
  • Cookies: 31
  • -My word is my bond
    • View Profile
Re: XSS in Evilzone
« Reply #7 on: November 26, 2015, 04:48:48 am »
Dude, how will he rank up now? it was his task... btw that somebody is me, if you didn't forget. Nice work though.

Hahaha he is more than welcome to look for a different place that has a different XSS vulnerability.
And nope, I definitely didn't forget :)
QA Engineer walks into a bar. Orders a beer. Orders 0 beers. Orders 999999999 beers. Orders a lizard. Orders -1 beers. Orders a sfdeljknesv.

Offline Darkvision

  • EZ's Fluffer
  • VIP
  • Royal Highness
  • *
  • Posts: 755
  • Cookies: 149
  • Its not a bug, It's a Chilopodas.
    • View Profile
Re: XSS in Evilzone
« Reply #8 on: November 26, 2015, 03:37:43 pm »
@parad0x, it is well known that in order to get admin one must hack the internet with a dragon dildo.

@shadowcloud, nice find man. Here more cookie for you.
The internet: where men are men, women are men, and children are FBI agents.

Ahh, EvilZone.  Where networking certification meets avian fecal matter & all is explained, for better or worse.

<Phage> I used an entrence I never use

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Re: XSS in Evilzone
« Reply #9 on: November 26, 2015, 06:03:13 pm »
@parad0x, it is well known that in order to get admin one must hack the internet with a dragon dildo.
I don't think he knows it yet :P

Offline Matriplex

  • Knight
  • **
  • Posts: 323
  • Cookies: 66
  • Java
    • View Profile
Re: XSS in Evilzone
« Reply #10 on: November 26, 2015, 06:19:50 pm »
Impressive
\x64\x6F\x75\x65\x76\x65\x6E\x00