PlayNC XSS proof of concept

2 pages Page 1
p
pablo24
Frost Gate Guardian
#1
https://secure.plaync.com/cgi-bin/plaync_login.pl

That's kinda stupid the only serious XSS flaw I found on their site was right on the login page.
Gogo fix it!

Knew this for a while but I figured I'd post because I saw this thread http://www.guildwarsguru.com/forum/s...php?t=10047808.

Btw don't be ashamed plaync... blizzard got the same problem on their e-card site and it still hasn't been fixed even though I reported it like a year ago. =)

Edit: Fixed first link to work for most browsers.

Edit2: Yay it's fixed!
Kashrlyyk
Kashrlyyk
Jungle Guide
#2
What? What? What?
p
pablo24
Frost Gate Guardian
#3
Quote:
Originally Posted by Kashrlyyk
What? What? What?
Click the linky
Kashrlyyk
Kashrlyyk
Jungle Guide
#4
Quote:
Originally Posted by pablo24
Click the linky
Did that, one leads me to this thread and the other to the PlayNC login. So what should I see there?
Aba
Aba
Wilds Pathfinder
#5
point??? dont know whats goin on.....
p
pablo24
Frost Gate Guardian
#6
Quote:
Originally Posted by Kashrlyyk
Did that, one leads me to this thread and the other to the PlayNC login. So what should I see there?
I only tested it on firefox, you are probably using IE? Sec lemme fix the link to work for IE too.
Kashrlyyk
Kashrlyyk
Jungle Guide
#7
Quote:
Originally Posted by pablo24
I only tested it on firefox, you are probably using IE? Sec lemme fix the link to work for IE too.
Opera 9.26

Probably using IE? Should I feel insulted?
12 chars
p
pablo24
Frost Gate Guardian
#8
Ok, edited the first link to work for most browsers.
Kusandaa
Kusandaa
Forge Runner
#9
The only thing I see that's weird on the first is the series is %20 (spaces) and some other %## I don't remember ATM...

The other link goes right back at this thread.

Can you explain the whole problem though? Is it a security flaw or something?

EDIT: clicked on the link above... wtf... O_o;;...

EDIT2: Using FireFox ATM.
Witchblade
Witchblade
Polar Bear Attendant
#10
<-- Noob,
What's going on ? ^^
Aba
Aba
Wilds Pathfinder
#11
Im still wondering myself.
used firefox,still clueless.....



Is this what your pointing too????


Quote:
Existing Customer
WHY?! Why does PlayNC have an XSS flaw right on their login page?
Alexandra-Sweet
Alexandra-Sweet
Wilds Pathfinder
#12
In short, pablo24 found yet another exploit in PlayNC/Guild Wars that PlayNC/Arena Net can't be arsed to fix.
Rift
Rift
Frost Gate Guardian
#13
The security flaw is that their script will echo the html/javascript directly into your browser.

With this, a malicious user could steal a session from a user, or, as in the first example, redirect the unsuspecting user to another webpage in the context of the plaync website (phishing)

Why? Because sadly even web developers these days fail to understand the severity of such an attack.
Kusandaa
Kusandaa
Forge Runner
#14
Quote:
Originally Posted by Rift
The security flaw is that their script will echo the html/javascript directly into your browser.

With this, a malicious user could steal a session from a user, or, as in the first example, redirect the unsuspecting user to another webpage in the context of the plaync website (phishing)

Why? Because sadly even web developers these days fail to understand the severity of such an attack.
Thanks for giving me an explanation I can actually understand

Could that be where the possible hacker got his info from? Regarding the hacked accounts thread thingy... I say it's possible >_>.
Sleeper Service
Sleeper Service
Jungle Guide
#16
the normal site is secured and the fake not.
but yeah someone could use that to steal login and pass....ironic no?
M
Malice Black
Site Legend
#17
Less geek, more street?
p
pablo24
Frost Gate Guardian
#18
Quote:
Originally Posted by Sleeper Service
the normal site is secured and the fake not.
but yeah someone could use that to steal login and pass....ironic no?
With some tweaking the modified site would be secure too.
Kusandaa
Kusandaa
Forge Runner
#19
Quote:
Originally Posted by Sleeper Service
the normal site is secured and the fake not.
but yeah someone could use that to steal login and pass....ironic no?
Actually if I understood correctly, the REAL site (the https: / / ) one IS flawed... flawed so much someone can redirect to that object that totally creeped me out (wasn't expecting it at all and my speakers were loud x];;; )

But I could be wrong. I'm no expert.
slowerpoke
slowerpoke
Desert Nomad
#20
if this is an expolit you should prolly report it to them and not advertise it here