WebApp Sec mailing list archives

Re: Recent App Test


From: Blake Schneider <blake.schneider () gmail com>
Date: Fri, 20 Aug 2004 03:22:08 -0600

On 18 Aug 2004 08:04:44 -0000, ramatkal () hotmail com
<ramatkal () hotmail com> wrote:


During a recent Application pen test I came across a url of the form:

http://www.vulnsite.com/cgi-bin/vulnscript.jsp?url=www.website.com&id=12345

I changed the url parameter to something like url=www.google.com and google appeared in my browser. Next, i changed 
the url to url=www.whatismyip.com, hoping that the ip address of the webserver would be displayed, however, only my 
ip address was displayed.

Were frames involved? It looks like it could be loading the passed URL
in one frame, and perhaps showing some other data in another.

1) Can use vulnsite as a proxy (& hack other sites)

Doubtful, if it is just loading the URL into a seperate frame.

2) Can port scan using the vuln site by changing url=www.website.com to url=www.sitetoscan.com:port

3) Can connect to & port scan machines behind the firewall.

Later,

Blake


Current thread: