Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 49 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow XSS Attack - Busting Browsers to Root!
EH-Net
May 21, 2013, 01:20:05 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: XSS Attack - Busting Browsers to Root!  (Read 3987 times)
0 Members and 1 Guest are viewing this topic.
t0rh4cker
Newbie
*
Offline Offline

Posts: 10


View Profile
« on: July 23, 2011, 08:22:08 AM »

This video will demonstrate how a simple XSS vulnerability can be leveraged to gain complete control of your web-browser and eventually lead to a complete system compromise.

1) We will use a cross-site scripting vulnerability as the initial attack vector
2) Exploit XSS by redirecting the user’s browser to the Evil_IP with a JavaScript loop (every 2 secs)
3) Exploit the victim’s browser to gain system ‘root’ or ‘shell’ access
4) Elevate our privileges to system-level

QUIZ: There is at least 6 security controls that could prevent several steps in the video including vulnerabilities or user errors.  Can you spot them all? 

FREEBIE: DVWA web server & IE8 browser security settings allow unencrypted XSS attack string to be sent during an SSL session.  "Submit non-encrypted form data- ENABLED"
What else? Huh

http://vimeo.com/26751019

Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #1 on: July 23, 2011, 01:24:46 PM »

QUIZ: There is at least 6 security controls that could prevent several steps in the video including vulnerabilities or user errors.  Can you spot them all? 

FREEBIE: DVWA web server & IE8 browser security settings allow unencrypted XSS attack string to be sent during an SSL session.  "Submit non-encrypted form data- ENABLED"
What else? Huh

http://vimeo.com/26751019



I didn't watch the video yet, however now I'm just guessing the security controls, I get free cookies if I win right?  Grin

Security Controls / Applications Preventing XSS:
- NoScript (Browser Addon)
- Anti-Virus System (Some detects and blocks XSS payloads)
- HIPS (Host-based Intrusion Prevention System, similar to an Anti-Virus system somewhat.)
- Patch Management (Staying updated and patched from known vulnerabilities.)
- Other browsers with Sandboxes (e.g. Chrome), or sandboxing a browser.
- Virtual Machines / Jailing (Using a browser in a virtual machine that is only used for that.)
- Enforced Proxy (Filters malicious data, similar to an IPS system somewhat.)
- SPI Firewall (Can detect and remove malicious data.)

And so forth.. Just a few ideas I had  Smiley
Logged

I'm an InterN0T'er
t0rh4cker
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #2 on: July 23, 2011, 08:48:48 PM »

ding! ding! ding! and Maxe the cyborg takes the lead!

#2 - Patch Management (Staying updated and patched from known vulnerabilities.)

Updating to the latest browser versions like IE8 has a built-in XSS filter.  It was disabled for the video.

#3 - Enforced Proxy (Filters malicious data, similar to an IPS system somewhat.)
Use the proxy to block outbound access to a known "Evil_IP" or Egress Filtering? So technically your proxy server answer should do the trick.

Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #3 on: July 24, 2011, 02:06:03 PM »

ding! ding! ding! and Maxe the cyborg takes the lead!

#3 - Enforced Proxy (Filters malicious data, similar to an IPS system somewhat.)
Use the proxy to block outbound access to a known "Evil_IP" or Egress Filtering? So technically your proxy server answer should do the trick.

I laughed IRL, and yeah that's what I meant about the proxy server too.   Smiley
Logged

I'm an InterN0T'er
jonas
Newbie
*
Offline Offline

Posts: 46


View Profile
« Reply #4 on: July 24, 2011, 03:15:20 PM »

Great Video! Thanks.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.067 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.