Wc3edit.net steals swat cookies now - tryout a XSS attack

Talk about anything you want, but keep it within the rules, please.
User avatar
Dekar
Forum Drunk
Posts: 2898
Joined: January 17th, 2007, 4:22 pm
Has thanked: 1 time
Been thanked: 1 time

Wc3edit.net steals swat cookies now - tryout a XSS attack

Post by Dekar »

Since redscull took some time to understand how XSS works (no offence, it just isn't that easy!) I made a proof of concept.
Wc3edit.net now steals the swat account cookie for every user who visits this forum and is logged in his swat account.
This data _doesn't_ allow anyone to access your account (I didn't plan to abuse it) but simply shows the vulnerability.

Here you can see the cookies it logged so far:
http://dekar.wc3edit.net/logger.php

To try it out just make an account at http://night.org/swat2/playerdb/index.php?p=new and visit wc3edit.net after logging in there.
Don't pm me with Warcraft questions, this is a forum so just make a post!
In the world of thinking we are all immigrants. -Robert Nozick
User avatar
Hmmz0r
Junior Member
Posts: 33
Joined: April 16th, 2009, 9:17 pm
Title: Peon
Location: Sweden

Re: Wc3edit.net steals swat cookies now - tryout a XSS attack

Post by Hmmz0r »

I have no idea what this does, but it sounds Dangerous o.O
Spoiler for Truth:
Image
Bart is awesome :-)
User avatar
Dekar
Forum Drunk
Posts: 2898
Joined: January 17th, 2007, 4:22 pm
Has thanked: 1 time
Been thanked: 1 time

Re: Wc3edit.net steals swat cookies now - tryout a XSS attack

Post by Dekar »

http://en.wikipedia.org/wiki/Cross-site_scripting
Yeah kinda... could delete/steal data... But I'm not evil ;)
Don't pm me with Warcraft questions, this is a forum so just make a post!
In the world of thinking we are all immigrants. -Robert Nozick
User avatar
Hmmz0r
Junior Member
Posts: 33
Joined: April 16th, 2009, 9:17 pm
Title: Peon
Location: Sweden

Re: Wc3edit.net steals swat cookies now - tryout a XSS attack

Post by Hmmz0r »

That truly is evil :shock:
Spoiler for Truth:
Image
Bart is awesome :-)
User avatar
Dekar
Forum Drunk
Posts: 2898
Joined: January 17th, 2007, 4:22 pm
Has thanked: 1 time
Been thanked: 1 time

Re: Wc3edit.net steals swat cookies now - tryout a XSS attack

Post by Dekar »

Okay the party is over, he finally fixed it ;)
Don't pm me with Warcraft questions, this is a forum so just make a post!
In the world of thinking we are all immigrants. -Robert Nozick