ejobs.ro security screwed again (XSS and DNS)

ejobs.ro security screwed again (XSS and DNS)

05/30/08 | by zveriu | Categories: Software, DailySpammer, Hack, XSS

First part article showing ejobs.ro security weaknesses is here

Now we continue with a XSS-with-DNS experiment.

First, it allows as a *feature* for the users to create some kind of subdomains on ejobs.ro which get linked to either Romanian or English version of the CV. Even though it looks like a cool feature, it wasn’t given a thought:

Now to the experiment part :). ejobs.ro and bestjobs.ro are two competing HR/Recruitment firms (at least they pose themselves on the market like this - who knows, maybe the same shadow-person owns both :D)

Using stored XSS attack with iframe and using the sub-domain feature we get the below:

Ejobs.ro serves Bestjobs.ro :)
Ejobs.ro serves Bestjobs.ro :)

In CV section of your ejobs.ro account, in the Objectives text-box use the following iframe injection code to check the proof:

Code:

<iframe
src=http://www.bestjobs.ro
width=800
height=240
>
</iframe >
 
 
<iframe
src=http://www.ejobs.ro
width=800
height=240
>
</iframe >

For sure they miss something in their security approach towards web application development.

That’s it for now. See you next time.

DISCLAIMER: this post is intended purely for security research and educative purposes as well as intended to urge the vendor to fix the problems posing threats to its customers. Any use of this information is sole responsibility of the reader and the author is not to be held liable for any miss-use of the above informative technical details.

Comments, Pingbacks:

No Comments/Pingbacks for this post yet...

Leave a comment:

Your email address will not be displayed on this site.
Your URL will be displayed.

Allowed XHTML tags: <p, ul, ol, li, dl, dt, dd, address, blockquote, ins, del, span, bdo, br, em, strong, dfn, code, samp, kdb, var, cite, abbr, acronym, q, sub, sup, tt, i, b, big, small>
(Line breaks become <br />)
(Set cookies for name, email and url)
(Allow users to contact you through a message form (your email will NOT be displayed.))
This is a captcha-picture. It is used to prevent mass-access by robots.
Please enter the characters from the image above. (case insensitive)

Cognitive and Scientific Brainology

A deep dive into brain's curiosities

September 2010
Sun Mon Tue Wed Thu Fri Sat
 << <   > >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Categories

Misc

XML Feeds

What is RSS?

powered by b2evolution free blog software