{"id":66,"date":"2005-10-27T07:40:52","date_gmt":"2005-10-27T14:40:52","guid":{"rendered":"http:\/\/outflux.net\/blog\/archives\/2005\/10\/27\/pastebin-rulez\/"},"modified":"2005-10-27T07:40:52","modified_gmt":"2005-10-27T14:40:52","slug":"pastebin-rulez","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2005\/10\/27\/pastebin-rulez\/","title":{"rendered":"pastebin rulez"},"content":{"rendered":"<p>When discussing code on IRC, I&#8217;ve found <a href=\"http:\/\/pastebin.com\/\">http:\/\/pastebin.com\/<\/a> to be a valuable resource for sharing code snippets.  It has a really simple interface, and can give you a semi-private area just by specifying a subdomain (e.g. <a href=\"http:\/\/yayoutflux.pastebin.com\/\">http:\/\/<strong>yayoutflux<\/strong>.pastebin.com\/<\/a>).<\/p>\n<p>I had spent some time yesterday doing some other security audits, and figured I&#8217;d poke around at pastebin.  Overall, the system was fine (only two inputs: text and name &#8212; both were strongly filtered).  I did discover a redirect bug, though, which would let me use the site to redirect to somewhere else.  While there isn&#8217;t anything to &#8220;steal&#8221; on pastebin, a bad guy could still trick their unsuspecting friends into visiting other (maybe more dangerous?) websites.<\/p>\n<p>I reported the problem to pastebin&#8217;s author (Paul Dixon), and he had it fixed before I woke up.  <em>That&#8217;s<\/em> how vulnerability reporting is supposed to work!  Thanks Paul!<\/p>\n<p>Here&#8217;s how it used to work.  From the <a href=\"http:\/\/pastebin.com\/?help=1\">pastebin help<\/a>, you can type in a subdomain to use for your pastebin.  (Like &#8220;yayoutflux&#8221; above.)  The form did some checking (no \/&#8217;s allowed), but would accidentally let you send whitespace, including a linefeed.<\/p>\n<p>Normally, a web redirect from that form would look something like this, where the user input is shown in bold:<\/p>\n<blockquote><p>\nHTTP\/1.1 302 Found<br \/>\nLocation: http:\/\/<strong>yayoutflux<\/strong>.pastebin.com\n<\/p><\/blockquote>\n<p>However, if I add a linefeed (URL encoded as %0A: <a href=\"http:\/\/pastebin.com\/pastebin.php?goprivate=cnn.com%0A\">http:\/\/pastebin.com\/pastebin.php?goprivate=cnn.com<strong>%0A<\/strong><\/a>), I could break the &#8220;Location&#8221; tag, and trick the browser into going somewhere else:<\/p>\n<blockquote><p>\nHTTP\/1.1 302 Found<br \/>\nLocation: http:\/\/<strong>cnn.com<\/strong><br \/>\n.pastebin.com\n<\/p><\/blockquote>\n<p>Great illustration of redirection XSS.<\/p>\n<p style='text-align:left'>&copy; 2005, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>When discussing code on IRC, I&#8217;ve found http:\/\/pastebin.com\/ to be a valuable resource for sharing code snippets. It has a really simple interface, and can give you a semi-private area just by specifying a subdomain (e.g. http:\/\/yayoutflux.pastebin.com\/). I had spent some time yesterday doing some other security audits, and figured I&#8217;d poke around at pastebin. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,12],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/66"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=66"}],"version-history":[{"count":0,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/66\/revisions"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=66"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=66"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=66"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}