咬定青山不放松,立根原在破岩中。千磨万击还坚劲,任尔东西南北风

© 竹意 | Powered by LOFTER

【转载】The Weather Channel weather.com Almost All Lin

来自:greenlife

The Weather Channel weather.com Almost All Links Vulnerable to XSS Attacks







Domain Description:

http://www.weather.com/


"The Weather Channel is an American basic cable and satellite television channel which broadcasts weather forecasts and weather-related news and analyses, along with documentaries and entertainment programming related to weather."


"As of August 2013, The Weather Channel was received by approximately 99,926,000 American households that subscribe to a pay television service (87.50% of U.S. households with television), making it the most common cable channel in the country." (Wikipedia)







Vulnerability description:



The Weather Channel has a security problem. It is vulnerable to XSS attacks.


Almost all links under the domain weather.com are vulnerable to XSS attacks. Attackers just need to add script at the end of The Weather Channel's URLs. Then the scripts will be executed.


10 thousands of Links were tested based a self-written tool. During the tests, 76.3% of links belong to weather.com were vulnerable to XSS attacks.


The reason of this vulnerability is that Weather Channel uses URLs to construct its HTML tags without filtering malicious script codes. 








The vulnerability can be attacked without user login. Tests were performed on Firefox (33.0) in Ubuntu (14.04) and IE (8.0. 7601) in Windows 7.








The Weather Channel weather.com Almost All Links Vulnerable to XSS Attacks - whitehat - 白帽子安全漏洞






The Weather Channel weather.com Almost All Links Vulnerable to XSS Attacks - whitehat - 白帽子安全漏洞









POC Codes, e.g.

http://www.weather.com/slideshows/main/"--/>"><img src=x onerror=prompt('justqdjing')>

http://www.weather.com/home-garden/home/white-house-lawns-20140316%22--/"--/>"><img src=x onerror=prompt('justqdjing')>t%28%27justqdjing%27%29%3E

http://www.weather.com/news/main/"><img src=x onerror=prompt('justqdjing')>








POC Video:

https://www.youtube.com/watch?v=Ij78WnzKB4M&feature=youtu.be


Blog Details:

http://securityrelated.blogspot.sg/2014/11/the-weather-channel-weather.html





The Weather Channel has patched this Vulnerability in late November, 2014 (last Week).









Reported by:

Wang Jing, School of Physical and Mathematical Sciences, Nanyang Technological University, Singapore.

http://www.tetraph.com/wangjing/










Related Articles:

http://www.scmagazine.com/the-weather-channels-website-found-vulnerable-to-xss-attacks/article/386010/

http://www.hotforsecurity.com/blog/weather-channel-web-site-vulnerable-to-reflected-cross-site-scripting-xss-10906.html

http://www.computerworld.com/article/2852502/weathercom-fixes-web-app-flaws.html

http://www.pcworld.com/article/2853292/weathercom-fixes-web-application-vulnerabilities.html

http://www.theregister.co.uk/2014/12/01/weather_channel_forecast_bleak_with_a_chance_of_xss/

https://cxsecurity.com/issue/WLB-2014120001

http://seclists.org/fulldisclosure/2014/Nov/89

http://whitehatview.tumblr.com/post/104313615841/the-weather-channel-fixes-web-app-flaws-the

http://diebiyi.com/articles/%E5%AE%89%E5%85%A8/the-weather-channel-weather-com-almost-all-links-vulnerable-to-xss-attacks/

http://tetraph.wordpress.com/2014/12/04/httpdiebiyi-comarticles%E5%AE%89%E5%85%A8the-weather-channel-weather-com-almost-all-links-vulnerable-to-xss-attacks/

http://whitehatpost.lofter.com/post/1cc773c8_4183cc5





 
评论
 
回到顶部