+ Reply to Thread
Results 1 to 8 of 8
Like Tree1Likes
  • 1 Post By 41.w4r10r

Thread: Gmail XSS vulnerability through Content Sniffing Share/Save - My123World.Com!

  1. #1
    InfoSec Consultant 41.w4r10r has a spectacular aura about41.w4r10r has a spectacular aura about41.w4r10r has a spectacular aura about 41.w4r10r's Avatar
    Join Date
    Jul 2010
    Location
    Pune
    Posts
    301
    Thanks
    31
    Thanked 82 Times in 37 Posts

    Gmail XSS vulnerability through Content Sniffing



    Hi all,

    a few months before i found this vulnerability which was reported to google and patched (Basically my way to google hall of fame).


    Product: Gmail.com
    Setup: Windows XP SP3 with IE 7.0 (Google Chrome frame installed)
    Vulnerability: XSS possible using malicious Image as attachment(works for IE6/7)

    Introduction:
    The vulnerability was in www.gmail.com which can be used to send Emails. We can send images as attachments to any user. By creating malicious image file and attaching it to mail attacker can exploit this vulnerability which can lead to complete compromise of account by stealing mail receiver cookies.
    Gmail was not validating contents of uploaded image files which can lead to XSS by including java scripts in image files. Following are screen shots which demonstrates complete attack vector.


    Name:  1.jpg
Views: 2778
Size:  49.0 KB

    Name:  2.jpg
Views: 2374
Size:  76.0 KB

    Name:  3.jpg
Views: 2795
Size:  94.4 KB

    Name:  4.jpg
Views: 2374
Size:  56.4 KB

    basically firstly this attack was limited for IE 6/7 but after some research i was able to bypass the IE8/9/10 protection which we presented in NullCon 2012. detail paper for same will be published soon here on g4h.
    Attached Images Attached Images    
    amolnaik4 likes this.

  2. The Following 8 Users Say Thank You to 41.w4r10r For This Useful Post:

    "vinnu" (03-14-2012), abhaythehero (03-13-2012), amolnaik4 (03-09-2012), b0nd (03-09-2012), fb1h2s (03-09-2012), neo (03-12-2012), prashant_uniyal (03-09-2012), [s] (03-13-2012)

  3. #2
    Security Researcher fb1h2s has a spectacular aura aboutfb1h2s has a spectacular aura aboutfb1h2s has a spectacular aura about fb1h2s's Avatar
    Join Date
    Jul 2010
    Location
    India
    Posts
    595
    Blog Entries
    23
    Thanks
    279
    Thanked 150 Times in 76 Posts
    On of the very critical Vulnerabilities since it was affecting Webmails, and a cool discovery .
    Hacking Is a Matter of Time Knowledge and Patience

  4. #3
    Security Analyst prashant_uniyal has a spectacular aura aboutprashant_uniyal has a spectacular aura about prashant_uniyal's Avatar
    Join Date
    Jul 2010
    Location
    localhost
    Posts
    498
    Blog Entries
    8
    Thanks
    248
    Thanked 104 Times in 55 Posts
    Simply awesome !! And a critical one. Great work by 4N1L bro
    The three great essentials to achieve anything worth while are: Hard work, Stick-to-itiveness, and Common sense. - Thomas A. Edison
    __________________________________________________ _____________________

    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  5. #4
    Garage Newcomer r007k17-w is on a distinguished road
    Join Date
    Feb 2012
    Posts
    2
    Thanks
    1
    Thanked 0 Times in 0 Posts
    great..................!! Gud1

  6. #5
    [s]
    [s] is offline
    Security Researcher [s] will become famous soon enough [s]'s Avatar
    Join Date
    Nov 2010
    Posts
    187
    Blog Entries
    2
    Thanks
    62
    Thanked 53 Times in 30 Posts
    I am seriously asking to admin when we are making Section called as Google Advisories :P ...

    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  7. #6
    Web Security Consultant amolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really nice amolnaik4's Avatar
    Join Date
    Jul 2011
    Location
    webr00t
    Posts
    269
    Blog Entries
    3
    Thanks
    24
    Thanked 178 Times in 100 Posts
    And here comes the most awaited PoC ...Gmail Content Sniffing ByPass.

    Nice work, Anil.

    Cheers,
    AMol NAik

  8. #7
    Security Researcher fb1h2s has a spectacular aura aboutfb1h2s has a spectacular aura aboutfb1h2s has a spectacular aura about fb1h2s's Avatar
    Join Date
    Jul 2010
    Location
    India
    Posts
    595
    Blog Entries
    23
    Thanks
    279
    Thanked 150 Times in 76 Posts
    [S] yea man we should seriously have that, will set it up by tonight .
    Hacking Is a Matter of Time Knowledge and Patience

  9. #8
    Network Security Administrator Hackuin will become famous soon enough Hackuin's Avatar
    Join Date
    Apr 2011
    Location
    /india/ap/hyd
    Posts
    97
    Thanks
    1
    Thanked 84 Times in 37 Posts
    Good one Anil.
    Microsoft should have learned about file processing with IE7 itself, which they failed to, but managed to process appropreatly type of file the browser encounters with IE9.

    check --> Text File Redirection [All versions below IE9] doesn't process type of file correctly.
    "Free software" is a matter of liberty, not price. To understand the concept, you should think of "free" as in "free speech," not as in "free beer."
    "Microsoft is not the answer. Microsoft is the question. NO (or Linux) is the answer."
    "Ubuntu - Linux For Human Beings."

    Currently reading books:
    CCIE Security v3.0, Configuration Practice Labs -- by Yusuf Bhaiji
    Network Flow Analysis -- by Michael W. Lucas

LinkBacks (?)

  1. 02-25-2013, 06:46 PM
  2. 11-28-2012, 11:03 PM
  3. 09-05-2012, 11:52 PM
  4. 05-15-2012, 04:52 AM
  5. 04-07-2012, 08:04 PM
  6. 04-03-2012, 04:29 PM
  7. 03-15-2012, 08:25 AM
  8. 03-13-2012, 02:46 PM
  9. 03-13-2012, 09:01 AM
  10. 03-13-2012, 05:32 AM
  11. 03-13-2012, 04:48 AM
  12. 03-12-2012, 11:37 PM
  13. 03-12-2012, 07:45 PM
  14. 03-10-2012, 03:26 AM
  15. 03-09-2012, 06:01 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts