RSS Forums RSS
Please support our DaniWeb Community Feedback advertiser: Programming Forums
Views: 3018 | Replies: 37
Reply
Join Date: Jul 2006
Location: Deptford, London
Posts: 987
Reputation: MattEvans has a spectacular aura about MattEvans has a spectacular aura about MattEvans has a spectacular aura about 
Rep Power: 6
Solved Threads: 52
Moderator
Featured Poster
MattEvans's Avatar
MattEvans MattEvans is offline Offline
Posting Shark

Message preview seems to allow unfiltered markup... XSS?

  #1  
Jul 26th, 2007
<iframe src="http://fusiongroups.net/test.html" />

I noticed this a while back... it seems that any html in the first part of the body of a message gets interpreted in that little preview box that shows the first part of a thread when you mouse over the title in a forum view... is this known about/considered a problem? If my suspicions are correct; mousing over this thread's title on the daniweb community board listing page title will execute some javascript from another server in a child context of a daniweb page = not good.
Plato forgot the nullahedron..
AddThis Social Bookmark Button
Reply With Quote  
Join Date: Jun 2005
Location: Tokyo, Japan
Posts: 1,481
Reputation: WolfPack has a spectacular aura about WolfPack has a spectacular aura about WolfPack has a spectacular aura about 
Rep Power: 8
Solved Threads: 102
Moderator
WolfPack's Avatar
WolfPack WolfPack is offline Offline
Mentally Challenged Mod.

Re: Message preview seems to allow unfiltered markup... XSS?

  #2  
Jul 26th, 2007
Yes. A Hello World Dialog box pops up when you hover the mouse over this thread listing the the Feedback forum page.
Attached Images
File Type: jpg fusiongroups.JPG (6.4 KB, 13 views)
Reply With Quote  
Join Date: Dec 2005
Posts: 2,857
Reputation: The Dude is an unknown quantity at this point 
Rep Power: 8
Solved Threads: 23
The Dude's Avatar
The Dude The Dude is offline Offline
Posting Maven

Re: Message preview seems to allow unfiltered markup... XSS?

  #3  
Jul 27th, 2007
That shouldnt work because HTML is disabled on this site......

EDIT:

Doesnt work when i hover over this thread.... (Using MyIE2 (IE engine))
Last edited by The Dude : Jul 27th, 2007 at 1:23 am.
Reply With Quote  
Join Date: Apr 2006
Location: Canada
Posts: 4,556
Reputation: John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all John A is a name known to all 
Rep Power: 17
Solved Threads: 284
Moderator
Featured Blogger
John A's Avatar
John A John A is offline Offline
Vampirical Moderator

Re: Message preview seems to allow unfiltered markup... XSS?

  #4  
Jul 27th, 2007
>That shouldnt work because HTML is disabled on this site......
It's only disabled when you view a thread. Matt's point was that it comes through via the thread preview window (which happens to me also, by the way).
tuxation.com - Linux articles, tutorials, and discussions
Reply With Quote  
Join Date: Jul 2006
Location: Deptford, London
Posts: 987
Reputation: MattEvans has a spectacular aura about MattEvans has a spectacular aura about MattEvans has a spectacular aura about 
Rep Power: 6
Solved Threads: 52
Moderator
Featured Poster
MattEvans's Avatar
MattEvans MattEvans is offline Offline
Posting Shark

Re: Message preview seems to allow unfiltered markup... XSS?

  #5  
Jul 27th, 2007
Hm. I'm using Opera, but I checked on Firefox aswell.

It wouldn't be a browser issue. If the forum software is putting unfilterered HTML into that part of the output; any browser should process it.
Plato forgot the nullahedron..
Reply With Quote  
Join Date: Dec 2005
Posts: 2,857
Reputation: The Dude is an unknown quantity at this point 
Rep Power: 8
Solved Threads: 23
The Dude's Avatar
The Dude The Dude is offline Offline
Posting Maven

Re: Message preview seems to allow unfiltered markup... XSS?

  #6  
Jul 28th, 2007
I had everything enabled when i tried it and it didnt popup!

It shouldnt as HTML is disabled globally on this base......

What browsers are you guys running that get this popup?

Last edited by The Dude : Jul 28th, 2007 at 4:47 am.
Reply With Quote  
Join Date: Jul 2006
Location: Deptford, London
Posts: 987
Reputation: MattEvans has a spectacular aura about MattEvans has a spectacular aura about MattEvans has a spectacular aura about 
Rep Power: 6
Solved Threads: 52
Moderator
Featured Poster
MattEvans's Avatar
MattEvans MattEvans is offline Offline
Posting Shark

Re: Message preview seems to allow unfiltered markup... XSS?

  #7  
Jul 28th, 2007
Go to the list of all threads in this forum, or to anywhere where a hyperlink to this thread exists ( including user control panel it seems ), mouse over the link to this thread until the summary of the message content pops up ( little yellow box )..

Screenshot attached. Do you normally get a little yellow summary box when you mouse over a message? If you don't for whatever reason ( browser etc ), then you're 'immune'..

HTML isn't disabled globally. If it was, we'd be looking at plaintext and manufacturing our own post requests.. It's disabled in posts because it is escaped; seemingly at point-of-request rather than at point-of-receipt... or perhaps the summary is extracted at point of receipt, before the escaping has been done. Either way; it's a security risk.
Attached Images
File Type: png ss6.png (229.3 KB, 16 views)
Plato forgot the nullahedron..
Reply With Quote  
Join Date: Dec 2005
Posts: 2,857
Reputation: The Dude is an unknown quantity at this point 
Rep Power: 8
Solved Threads: 23
The Dude's Avatar
The Dude The Dude is offline Offline
Posting Maven

Re: Message preview seems to allow unfiltered markup... XSS?

  #8  
Jul 29th, 2007
OK your using Opera that might explain it....

Im uisng MyIE2 and it doesnt popup for me (I dont expect it should)

Maybe Opera still executes the script locally instead of from the site?? (Im telling you 'HTML' is disabled on this site!!)

<a href="http://www.daniweb.com/forums">See what i mean?</a>

Now is that formatted correctly for you?? (It shouldnt be if it is)

Ah well......
Reply With Quote  
Join Date: May 2006
Location: Bellevue, WA
Posts: 1,546
Reputation: Infarction has a spectacular aura about Infarction has a spectacular aura about Infarction has a spectacular aura about 
Rep Power: 8
Solved Threads: 51
Sponsor
Infarction's Avatar
Infarction Infarction is offline Offline
Battle Programmer

Re: Message preview seems to allow unfiltered markup... XSS?

  #9  
Jul 29th, 2007
Yeah, I get it in IE and Opera, but not FF. Nice find...
Reply With Quote  
Join Date: Feb 2002
Location: Lawn Guylen, NY
Posts: 11,073
Reputation: cscgal is just really nice cscgal is just really nice cscgal is just really nice cscgal is just really nice cscgal is just really nice 
Rep Power: 33
Solved Threads: 118
Admin
Staff Writer
cscgal's Avatar
cscgal cscgal is offline Offline
The Queen of DaniWeb

Re: Message preview seems to allow unfiltered markup... XSS?

  #10  
Jul 29th, 2007
I've fixed this bug. Thank you for pointing it out!
Dani the Computer Science Gal
Reply With Quote  
Reply

Only community members can participate in forum threads. You must register or log in to contribute.

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 

Thread Tools Display Modes
Forums | Blogs | Tutorials | Code Snippets | Whitepapers | RSS Feeds | Advertising
All times are GMT -4. The time now is 5:54 am.
Newsletter Archive - Sitemap - Privacy Statement - Acceptable Use Policy - Contact Us
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC