Rev Potential exploit.

Status
Not open for further replies.

Dan Smith

Member
Sep 10, 2011
64
3
Basicly. i belive that rev is xxs cross scriptable.

All thats needed is to set your motto to <script>alert('XXS')</script> and on online, it sends an alert.


Does anybody have a fix for this?

The fix will be largely appreciated!

Also, you may want to know:
Whats is XXS?




-Dan :D
 

Dan Smith

Member
Sep 10, 2011
64
3
a0e04925ab6921fc0ac2713edae04da0.png
 

Find

Posting Freak
Jun 21, 2012
597
189
Basically it means if they put that code in their motto, anywhere on the site that it shows their motto a script will pop up :)
 

Clit

Posting Freak
Feb 25, 2012
1,065
103
Basically it means if they put that code in their motto, anywhere on the site that it shows their motto a script will pop up :)
Its for staff use only then pretty much, don't see how it is an exploit. It's basically putting %username% in your motto.
 

Find

Posting Freak
Jun 21, 2012
597
189
Well the user could use it on the me page, and we have an online users page as you just saw so it would not only work for staff :)
 

Clit

Posting Freak
Feb 25, 2012
1,065
103
Well the user could use it on the me page, and we have an online users page as you just saw so it would not only work for staff :)
Me page, only the user can see.
Online users is like a graph thing, and have to hover, doubt that enables/works like that. (idfk wot i seD)
and its a staff ability, and for vip's its a special feature, and if they are one of the lucky randoms. 
it shows up on online users page. its XXs cross scripting, that's an exploit
dont even have mottos enabled on online users page -.-
tbh, even if its a popup, who cares, ITS A POPUP, no harm facepalm.jpg
 

Tomm

The Legend
Aug 19, 2012
191
92
it works on the /online page for all users, as every online user is displayed here. I think Mr Find fixed the issue by disabling mottos on the /online page.
 

Find

Posting Freak
Jun 21, 2012
597
189
As you quite clearly did not read the link posted on the original post,

"Cross-site scripting (XSS) is a type of typically found in , such as through breaches of , that enables attackers to into viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass such as the . Cross-site scripting carried out on websites accounted for roughly 84% of all security vulnerabilities documented by Symantec as of 2007. Their effect may range from a petty nuisance to a significant security risk, depending on the sensitivity of the data handled by the vulnerable site and the nature of any security mitigation implemented by the site's owner."

So as you can see it is more of a risk than "just a popup"
 

Clit

Posting Freak
Feb 25, 2012
1,065
103
it works on the /online page for all users, as every online user is displayed here. I think Mr Find fixed the issue by disabling mottos on the /online page.
regardless, no reason to remove the code, its a fucking popup, also nobody knew of this, lol, never been used anywhere. blame op for releasing ;p, REGARDLESS, ITS A FUCKING POPUP LOL
 

Clit

Posting Freak
Feb 25, 2012
1,065
103
This pop up could ALSO be abused, showing advertisements or inappropriate messages. This is un-professional.
yeah deffiantly with limited motto characters. 
I think what he's trying to say is if that alert script can be used, then they could manipulate the XSS code and end up putting shells into the server.
tell me how you're gonna do that in 12 fucking characters..facepalm.jpg
 
Status
Not open for further replies.

Users who are viewing this thread

Top