Hot to Gain Administrative Privileges on any Blogger

Marco Ramilli
Date
14 March 2011
Read
Share
Last night I received an email from Nir, who wanted to share with me its great work on the 1337$ Google Reward Program he completed.
The vulnerability he found could be used by an attacker to get administrator privilege over any blogger account thanks to the HTTP Parameter Pollution vulnerability in Blogger that allows an attacker to add himself as an administrator on the victim’s blogger account.

Nir exploited a vulnerability due to the inconsistency of parameter evaluation and parameter elaboration as the volloging attack vector shows:

security_token=attackertoken&blogID=attackerblogidvalue&
blogID=victimblogidvalue&authorsList=goldshlager19test%40gmail.com
(attacker email)&ok=Invite

There are two blogid values in the post request (blogID=attackerblogidvalue&blogID=victimblogidvalue)

The server checks the first blogid value and executes the second blogid value: the attacker one.
In the same way Nir injects the memberID gaining admin privileges.
Here the great video he made.

[youtube https://www.youtube.com/watch?v=AdIWl0gkynk&w=480&h=390]


Well, what to say now.... Thank you for sharing and for have waited my own post instead of put it by yourself ! 😉
Marco Ramilli
Date
14 March 2011
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier