exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Microsoft Internet Explorer 8 IMG Tag Hijacking

Microsoft Internet Explorer 8 IMG Tag Hijacking
Posted Apr 23, 2010
Authored by Vladimir Vorontsov

Microsoft Internet Explorer 8 suffers from an IMG tag hijacking vulnerability.

tags | exploit
SHA-256 | 14cae374c30383554e1157f59baef5bc518a0a67261e113077b9cf4c685d7681

Microsoft Internet Explorer 8 IMG Tag Hijacking

Change Mirror Download
Hello Full disclosure!

Once again, unwinding theme HiJacking found a fun way to get the very
least information about the target resource when the user is located at the
attacker.

Already crocked <img> tag opens new opportunities using the method
fileSize, described here: http://msdn.microsoft.com/en-us/library/ms533752
(v = VS.85). Aspx

Consider a simple example - a Web application after authentication
provides some sort of picture for the user, for example:

http://example.com/getImage.php?image=myAvatar

The attacker, knowing this can create a page to read:

<img id="onsec" src="http://example.com/getImage.php?image=myAvatar">

<input type="button" onclick="if (onsec.fileSize> 0) (alert ('authorized
on example.com') else (alert ('not authorized on example.com')}">

Thus, the attacker learns the simplest case, whether the target user
access to example.com.

Continuing the theme, I want to note that in some cases, can obtain
additional information from the very values of the size of the picture. It
can be any logical information Web applications, say, the same script can
show administrators a picture of the same size, and users - of another.
Thus, we obtain the user rights. And so on.

I'd like to return the size of the method is not only "valid" images, but
also HTML pages, JSON, etc. But, unfortunately, does not work. Maybe, of
course, there are exceptions, call to investigate the matter.

I have some thoughts on the study of vector images in XML format, because
HTML is often valid XML, and then ...

Check for the test version IE9, but he did not support SVG inside tag
<img>, but only as a separate tag.

Works in IE8, in Opera 10.52 does not work on check writing, if not
difficult.

Original at russian language: http://oxod.ru/?p=113

--
Best regards,
Vladimir Vorontsov
ONsec security expert

Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    0 Files
  • 7
    May 7th
    0 Files
  • 8
    May 8th
    0 Files
  • 9
    May 9th
    0 Files
  • 10
    May 10th
    0 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close