| InterN0T - Advisories Advisories that are found by members of InterN0T. |
#1
| ||||
| ||||
| AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities AdPeeps Ad Rotator - XSS and HTML Injection Vulnerabilities Version Affected: 8.5d1 (3-18-09) (newest) Info: Ad Peeps is a banner rotator and text ad rotator - all in one that allows you to track, sell and manage banner ads, rich-media/flash ads and text ads on your website. Built using PHP/MYSQL, Ad Peeps provides you and your advertisers with highly detailed real-time statistics and is capable of delivering millions of impressions per day on a typical shared web server. - Plus, you can try it right now on your website with our 7 day trial. Ad Peeps is so versatile that it can even show your text ads Yahoo! Style or Google AdWords Style. Unlike many other banner ad rotator programs, Ad Peeps was skillfully designed to use minimal server resources while maintaining speed and unparalleled performance. Built on a highly scalable and versatile database architecture, Ad Peeps works without fuss even on high traffic web sites and won't crash your high powered website.. Opinion: AdPeeps, along with many others should really hire people to audit their code. Credits: Matt and all of InterN0T :-) Googled0rk: (there might be more accurate d0rks) intitle:"Advertisement Management Control Panel" External Links: http://www.adpeeps.com/ http://www.adpeeps.com/signup.html http://demo.adpeeps.com/index.php?lo...gin&uid=100000 Default Login: admin / admin -:: The Advisory ::- Quote:
The most easy solution is to validate user input and strip or convert bad / html characters. Conclusion: Even if One decides to (ab)use the Advertiser Name, First- and Last-name's as injection points and the administrator sees this (in an e-mail), then he will still be affected by the injection and possibly have a hard time deleting those malicious users safely except if he might have NoScript turned on for his own website. (the injection points might render the desired pages useless) Disclosure Information: - Vulnerabilities found 26th May 2009. - Advisory finished and published on InterN0T the 27th May. - Bugtraq (SecurityFocus) and Milw0rm contacted the 27th May. *AdPeeps will be contacted soon. (full disclosure rocks!) - Milw0rm: http://milw0rm.com/exploits/8818 - Secunia: http://secunia.com/advisories/35262/ All of the best, MaXe
__________________ ![]() Quote:
|
|
#2
| |||
| |||
| Re: [InterN0T] AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities
To MAXE: (sorry to talk about something not releated to this topic at all, hope you see my point when you read it) In my honest opinion I am very much agains public disclosure, or even disclosure while at that point. I don't know what benifit do you get from releasing exploits and just giving the script kiddies more tools in their already enormous arsenal. Not to mention teaching the whitehat industry of possible new types of coding mistakes and extreminating some exploit methods, just like what happened to BoFs in closed source applications and services. Even if that doesn't touch you, why give the exploits to vendors when they already have an IT sec team working round the clock to find new holes. If you outsmarted them, use that, don't just help them get better security with out the sweat of finding them for theirself. As I can not understand your motives i just want you to tell me your honest oppinion about this, PM it if you want to. I know that my other point of view might get me a BAN here, but I am a blackhat, i hate disclosure of vulns PoCs etc. and trying to reason everybody that's agains my opinion. accelerator_dd |
|
#3
| ||||
| ||||
| Re: [InterN0T] AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities
Nice find. IMO I do think full discloses is good because its valuable for multiple people/
__________________ "Intern0t, fight crime with crime, preventing internet security risks since 2009!" |
|
#4
| ||||
| ||||
| Re: [InterN0T] AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities
i believe the only way a script kiddie can fully learn is through this kind of teaching for example, maxe explains everything about how and why it works which is very anti selfish of himself and accelerator you probably learned from masters yourself nice one maxe xD
__________________ OSWP Certified |
|
#5
| ||||
| ||||
| Re: [InterN0T] AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities
@accelerator2610 => Don't worry you wont get banned for saying your opinion, it's only flaming that might get you a warning, but not a ban :-) (only if it's really bad which this is not nearly anywhere near of). Anyways i see your concern, i could hide the exploits for higher ranked members and in some cases i have done it while working on it. Or keep it all to myself, but since i'm not going to abuse it except if i had a target (which i don't), then i don't see a purpose in not sharing it to the community. The reason why i begin to make advisories and share them is simply because it might inspire other members to do the same! It also helps us increase in popularity or in other words how known we might be on the internet. On numerous places i've heard people saying there's nothing interesting on InterN0T, but there is now! And whenever i find vulnerabilities, i'll most likely post them. They might be in non-public sections for a few days but not more than a few weeks. I think that's the essence of being grayhat, sometimes i might have intentions of hack- ing a particular target, but mostly i just like finding holes in web application systems and websites which are poorly coded. It's all for the fun, no profit at all. No malicious intentions :) @hestas and TheXero => Yes it's also about teaching people, especially in the other advisory where i explained how to abuse the issue and where it might fail, where it might work etc. The only thing i'm not going to explain is where all the flaws are in the code, because I myself is not really the best coder and programmer. But in future advisories i might just write an article as i might begin to look through the codes instead of getting a copy to install on my own webserver ;-) And when i finally begin programming for real, i might look into software vulnerabilities instead! I actually think those are even better, especially if it's software that is widely used and which can give a root/meterpreter shell. I wish i was better at that kind of stuff ;D However i still need to improve my (+Blind) SQL injection (which really sucks) and more! Thanks for the feedback :)
__________________ ![]() Quote:
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
| |
LinkBacks (?)
LinkBack to this Thread: http://forum.intern0t.net/intern0t-advisories/1049-adpeeps-8-5d1-cross-site-scripting-html-injection-vulnerabilities.html | ||||
| Posted By | For | Type | Date | |
| 54790: AdPeeps index.php Multiple Parameter XSS | This thread | Refback | 17th August 2010 20:13 | |
| US-CERT Cyber Security Bulletin SB10-207 -- Vulnerability Summary for the Week of July 19, 2010 | This thread | Refback | 2nd August 2010 19:56 | |
| CVE - CVE-2009-4939 (under review) | This thread | Refback | 29th July 2010 18:04 | |
| 54790: AdPeeps index.php Multiple Parameter XSS | This thread | Refback | 27th July 2010 07:34 | |
| Öйú¹ú¼ÒÐÅÏ¢°²È«Â©¶´¿â | This thread | Refback | 26th July 2010 02:55 | |
| 66479: AdPeeps Admin Account Default Password | This thread | Refback | 22nd July 2010 15:57 | |
| [InterN0T] AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities | This thread | Refback | 8th July 2009 06:18 | |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| ShareTronix 1.0.4 - HTML Injection Vulnerability | MaXe | InterN0T - Advisories | 0 | 29th January 2010 15:30 |
| Simple Machines Forum '[url]' Tag HTML Injection Vulnerability | MaXe | Exploits, Vulnerabilities & PoCs | 3 | 17th December 2009 01:00 |
| LightNEasy 2.2.2 - HTML Injection Vulnerability | MaXe | InterN0T - Advisories | 0 | 3rd June 2009 23:32 |