Skype Videomood Vulnerability

Marco Ramilli
Date
18 January 2008
Read
Share

In new skype video chat, every user is able to insert a video in his own mood.
And this is the result:

1) Prepare your XSS injection

(Pics from critical)

2) Exploit it !


(Pics from critical)

It seems that skype trusts on 3rd part links without control-it !

We were able to find some permanent XSS vectors in dailymotion.com: videos have a 'Title' field, which is not properly filtered and returned to user in certain conditions. So it becomes possible to execute malicious script content when user is searching for a video to add to his mood. You may also test it by entering word 'saugumas' in dailymotion.com video search field.

Original post: ( https://seclists.org/fulldisclosure/2008/Jan/0328.html )

Marco Ramilli
Date
18 January 2008
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier