Just to clarify: did you just demonstrate a XSS vulnerability in @tmobileat‘s website? #amaziglygoodsecurity
-
-
-
Yes, Daniel.
-
Lol. What is there left to say...
- 1 more reply
New conversation -
-
-
Did we find the same on that page or is it yet another XSS? Mine has to do with referrals, roughly said.pic.twitter.com/uyYrdzcyuU
-
Mine uses Javascript code with injected strings from HTTP parameters.pic.twitter.com/nitCZ2kyYN
-
Same here, but the parameter has to do with referrals in my case. What's your parameter about?
-
The text of an error message.
-
Great, so there are a whole load of XSS vulnerabilites on their site. Interesting thing is, that the Telekom in Germany did exclude XSS vulnerabilites from their bug bounty program scope in 2013. Guess it were too much to pay.
-
That's a smoking gun if I've ever seen one. "Can't have XSS if we refuse to recognise it"
-
I guess they fix it nontheless, because they still provide hall of fame entries for findings they removed from their scope in 2013. But I'd like to hear a single reason for removing LFI, RFI, XSS and CSRF vulnerabilites from scope.
End of conversation
New conversation -
-
-
Hahaha that's what you call amazingly good security!
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
At this point, it would be better if they just 'sudo rm -rf /*'d everything...
-
Or maybe a nice little 'sudo dd if=/dev/urandom of=/dev/sda'
End of conversation
New conversation -
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Lol what am I watching?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Reflective or stored xss?
-
The pictures make me think all examples are reflective.
-
One tweet mentioned an error page that seemed to parrot query params. So for at least one of the cases, you’re correct
-
Indeed. There was a couple of pics on Twitter that had a reflective look about them. Just observations mind you. I'm leaving the checking to the security tester buccaneers. ^_^
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
