Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > The Inner Circle > The Riverside Inn

Notices

Reply
 
Thread Tools Display Modes
Old May 05, 2008, 05:16 PM // 17:16   #1
Frost Gate Guardian
 
Join Date: Aug 2007
Advertisement

Disable Ads
Default PlayNC XSS proof of concept

https://secure.plaync.com/cgi-bin/plaync_login.pl

That's kinda stupid the only serious XSS flaw I found on their site was right on the login page.
Gogo fix it!

Knew this for a while but I figured I'd post because I saw this thread http://www.guildwarsguru.com/forum/s...php?t=10047808.

Btw don't be ashamed plaync... blizzard got the same problem on their e-card site and it still hasn't been fixed even though I reported it like a year ago. =)

Edit: Fixed first link to work for most browsers.

Edit2: Yay it's fixed!

Last edited by pablo24; May 05, 2008 at 09:52 PM // 21:52..
pablo24 is offline   Reply With Quote
Old May 05, 2008, 05:38 PM // 17:38   #2
Jungle Guide
 
Kashrlyyk's Avatar
 
Join Date: May 2005
Default

What? What? What?
Kashrlyyk is offline   Reply With Quote
Old May 05, 2008, 05:39 PM // 17:39   #3
Frost Gate Guardian
 
Join Date: Aug 2007
Default

Quote:
Originally Posted by Kashrlyyk
What? What? What?
Click the linky
pablo24 is offline   Reply With Quote
Old May 05, 2008, 05:42 PM // 17:42   #4
Jungle Guide
 
Kashrlyyk's Avatar
 
Join Date: May 2005
Default

Quote:
Originally Posted by pablo24
Click the linky
Did that, one leads me to this thread and the other to the PlayNC login. So what should I see there?
Kashrlyyk is offline   Reply With Quote
Old May 05, 2008, 05:45 PM // 17:45   #5
Aba
Wilds Pathfinder
 
Aba's Avatar
 
Join Date: Dec 2006
Location: Vancouver,Canada
Default

point??? dont know whats goin on.....
Aba is offline   Reply With Quote
Old May 05, 2008, 05:46 PM // 17:46   #6
Frost Gate Guardian
 
Join Date: Aug 2007
Default

Quote:
Originally Posted by Kashrlyyk
Did that, one leads me to this thread and the other to the PlayNC login. So what should I see there?
I only tested it on firefox, you are probably using IE? Sec lemme fix the link to work for IE too.
pablo24 is offline   Reply With Quote
Old May 05, 2008, 05:48 PM // 17:48   #7
Jungle Guide
 
Kashrlyyk's Avatar
 
Join Date: May 2005
Default

Quote:
Originally Posted by pablo24
I only tested it on firefox, you are probably using IE? Sec lemme fix the link to work for IE too.
Opera 9.26

Probably using IE? Should I feel insulted?
12 chars

Last edited by Kashrlyyk; May 05, 2008 at 05:51 PM // 17:51..
Kashrlyyk is offline   Reply With Quote
Old May 05, 2008, 05:49 PM // 17:49   #8
Frost Gate Guardian
 
Join Date: Aug 2007
Default

Ok, edited the first link to work for most browsers.

Last edited by pablo24; May 05, 2008 at 05:59 PM // 17:59..
pablo24 is offline   Reply With Quote
Old May 05, 2008, 05:49 PM // 17:49   #9
Forge Runner
 
Kusandaa's Avatar
 
Join Date: Jul 2006
Profession: N/Mo
Default

The only thing I see that's weird on the first is the series is %20 (spaces) and some other %## I don't remember ATM...

The other link goes right back at this thread.

Can you explain the whole problem though? Is it a security flaw or something?

EDIT: clicked on the link above... wtf... O_o;;...

EDIT2: Using FireFox ATM.

Last edited by Kusandaa; May 05, 2008 at 05:52 PM // 17:52..
Kusandaa is offline   Reply With Quote
Old May 05, 2008, 05:50 PM // 17:50   #10
Polar Bear Attendant
 
Witchblade's Avatar
 
Join Date: May 2005
Default

<-- Noob,
What's going on ? ^^
Witchblade is offline   Reply With Quote
Old May 05, 2008, 05:52 PM // 17:52   #11
Aba
Wilds Pathfinder
 
Aba's Avatar
 
Join Date: Dec 2006
Location: Vancouver,Canada
Default

Im still wondering myself.
used firefox,still clueless.....



Is this what your pointing too????


Quote:
Existing Customer
WHY?! Why does PlayNC have an XSS flaw right on their login page?
Aba is offline   Reply With Quote
Old May 05, 2008, 05:52 PM // 17:52   #12
Wilds Pathfinder
 
Alexandra-Sweet's Avatar
 
Join Date: Dec 2006
Location: That one place with the trees, mountains and snow
Guild: Ember Power Mercenaries [EMP]
Profession: Me/
Default

In short, pablo24 found yet another exploit in PlayNC/Guild Wars that PlayNC/Arena Net can't be arsed to fix.
Alexandra-Sweet is offline   Reply With Quote
Old May 05, 2008, 05:54 PM // 17:54   #13
Frost Gate Guardian
 
Rift's Avatar
 
Join Date: Jul 2007
Location: Canada
Guild: Virtual Love [kiSu]
Default

The security flaw is that their script will echo the html/javascript directly into your browser.

With this, a malicious user could steal a session from a user, or, as in the first example, redirect the unsuspecting user to another webpage in the context of the plaync website (phishing)

Why? Because sadly even web developers these days fail to understand the severity of such an attack.
Rift is offline   Reply With Quote
Old May 05, 2008, 05:57 PM // 17:57   #14
Forge Runner
 
Kusandaa's Avatar
 
Join Date: Jul 2006
Profession: N/Mo
Default

Quote:
Originally Posted by Rift
The security flaw is that their script will echo the html/javascript directly into your browser.

With this, a malicious user could steal a session from a user, or, as in the first example, redirect the unsuspecting user to another webpage in the context of the plaync website (phishing)

Why? Because sadly even web developers these days fail to understand the severity of such an attack.
Thanks for giving me an explanation I can actually understand

Could that be where the possible hacker got his info from? Regarding the hacked accounts thread thingy... I say it's possible >_>.
Kusandaa is offline   Reply With Quote
Old May 05, 2008, 05:57 PM // 17:57   #15
Jungle Guide
 
Kashrlyyk's Avatar
 
Join Date: May 2005
Default

Quote:
Originally Posted by pablo24
Way less obfuscated, but this should work for most browsers:
https://secure.plaync.com/cgi-bin/plaync_login.pl
Thanks that worked!
Kashrlyyk is offline   Reply With Quote
Old May 05, 2008, 05:59 PM // 17:59   #16
Jungle Guide
 
Sleeper Service's Avatar
 
Join Date: Dec 2005
Guild: CULT
Default

the normal site is secured and the fake not.
but yeah someone could use that to steal login and pass....ironic no?
Sleeper Service is offline   Reply With Quote
Old May 05, 2008, 06:00 PM // 18:00   #17
Site Legend
 
Join Date: Oct 2005
Default

Less geek, more street?
__________________
Old Skool '05
Malice Black is offline   Reply With Quote
Old May 05, 2008, 06:01 PM // 18:01   #18
Frost Gate Guardian
 
Join Date: Aug 2007
Default

Quote:
Originally Posted by Sleeper Service
the normal site is secured and the fake not.
but yeah someone could use that to steal login and pass....ironic no?
With some tweaking the modified site would be secure too.
pablo24 is offline   Reply With Quote
Old May 05, 2008, 06:01 PM // 18:01   #19
Forge Runner
 
Kusandaa's Avatar
 
Join Date: Jul 2006
Profession: N/Mo
Default

Quote:
Originally Posted by Sleeper Service
the normal site is secured and the fake not.
but yeah someone could use that to steal login and pass....ironic no?
Actually if I understood correctly, the REAL site (the https: / / ) one IS flawed... flawed so much someone can redirect to that object that totally creeped me out (wasn't expecting it at all and my speakers were loud x];;; )

But I could be wrong. I'm no expert.
Kusandaa is offline   Reply With Quote
Old May 05, 2008, 06:03 PM // 18:03   #20
Desert Nomad
 
slowerpoke's Avatar
 
Join Date: Jul 2007
Location: Cuba
Default

if this is an expolit you should prolly report it to them and not advertise it here
slowerpoke is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Seraphim of Chaos The Riverside Inn 23 Dec 04, 2006 11:33 AM // 11:33
3 man build for Oro/FA (pic of proof) skreet preacha The Campfire 16 May 29, 2006 09:24 PM // 21:24
3 man build for Oro/FA (pic of proof) skreet preacha The Campfire 11 Apr 26, 2006 03:12 PM // 15:12
Shanaeri Rynale Screenshot Exposition 10 Jan 13, 2006 11:58 PM // 23:58


All times are GMT. The time now is 09:31 PM // 21:31.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("