House of Hackers

Persistent XSS
In Blogtags (reported, but not fixed)
In Grouplocation Tag and Group Website field (reported, but not fixed)

Reflective XSS
On Profile not found page (already fixed)
Edit:
Workarround not acceptable works with other attack vector.
Same on Group not found page and so on.
Opera
Firefox
On Profilecontroller (unknown action issue) (reported, but not fixed)
http://houseofhackers.ning.com/profiles/profile/<here>
PoC Firefox
PoC Opera

Edit: Same on eventcontroller, ... and so on. Workarround not acceptable.

Next one I found:
PoC

PoC Opera
PoC Firefox
PoC Firefox
.....

Tags: exploit, ning, poc, vulnerabilities, web, xss

Share 

Add a Comment

You need to be a member of House of Hackers to add comments!

Join this Ning Network

fragge Comment by fragge on May 8, 2008 at 5:45am
ugh and yeah there is no way to edit, amongst other missing functions in this app (like custom group page, inviting members to group, searching members by country, searching members by age, searching members by group, more customization to main page, topics in forums rather than just random ordering.. god ning has nothing!). GRR! :@
fragge Comment by fragge on May 8, 2008 at 5:43am
i'll do a proper run through of URL and form injection later tomorrow or on the weekend. been tied up with work all day, and will most likely be swamped tomorrow. god adobe takes forever to install shit, had to reinstall acrobat -_-
Wildcat Comment by Wildcat on May 8, 2008 at 2:14am
Yep, the "Event not found", "Group not found" "Member not Found", ....... pages have a lot of XSS vulns ...
I am searching for SQLI vulns, but nothing found yet

lol @ fragge ^^
friends are overrated xD
Hm no edit function for blog comments yet, ..... that sux!
fragge Comment by fragge on May 8, 2008 at 2:06am
i have no friends :(
Sam Aldis Comment by Sam Aldis on May 8, 2008 at 2:00am
Another XSS:
PoC
Sam Aldis Comment by Sam Aldis on May 8, 2008 at 1:52am
its a shame I'm your only friend i wanted that to go out
to everyone. ;)
fragge Comment by fragge on May 8, 2008 at 1:50am
:P
Sam Aldis Comment by Sam Aldis on May 8, 2008 at 1:44am
wow thanks for the message fragge..
you could have put something other than
This is a PoC in it though ;)
Wildcat Comment by Wildcat on May 8, 2008 at 1:42am
Better I turn noscript on, for a while ... ;D
Sam Aldis Comment by Sam Aldis on May 8, 2008 at 1:40am
was going to wait untill pdp looked at the darkstar group
and change the front page because i created an auto submit form
that uses CSRF but thats probably a bit harsh :/
anyways you can see the XSS in action here:
http://houseofhackers.ning.com/group/darkstar

About

pdp pdp created this Ning Network.

© 2009   Created by pdp on Ning.   Create a Ning Network!

Badges  |  Report an Issue  |  Privacy  |  Terms of Service

Sign in to chat!