Konuyu Oyla:
  • Toplam: 1 Oy - Ortalama: 5
  • 1
  • 2
  • 3
  • 4
  • 5
   
Konu: PA Palace LLC 2018 © Open Redirection Vulnerability
KingSkrupellos
*
avatar
Hacktivist
Durum: Çevrimdışı
Seviye Puanı: 55
Yaşam Puanı: 1,372 / 1,372
Deneyim: 91 / 100
Rep Sayısı: 2769
Mesaj Sayısı: 6325
Üyelik Tarihi: 21.08.2013
     
Yorum: #1
PA Palace LLC 2018 © Open Redirection Vulnerability
30.06.2018 13:09
################################################################################​###########################

# Exploit Title : PA Palace is only located on the internet PA Palace, LLC 2018 © Open Redirection Vulnerability
# Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army
# Date : 30/06/2018
# Vendor Homepage : papalace.com
# Tested On : Windows
# Category : WebApps
# Exploit Risk : Medium
# CWE : CWE-601 [ URL Redirection to Untrusted Site ('Open Redirect') ]

################################################################################​###########################

# Description for the Vulnerability :

URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.
This simplifies phishing attacks.An http parameter may contain a URL value and could cause the web application to redirect the request to the specified URL.
By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
Because the server name in the modified link is identical to the original site, phishing attempts have a more trustworthy appearance.
Phishing is a general term for deceptive attempts to coerce private information from users that will be used for identity theft.

# Google Dork : intext:''PA Palace is only located on the internet. [email protected] PA Palace, LLC 2018 ©''

# Exploit : /pashop/checkout.php?id=&redirect=http://www.REDIRECTIONADDRESS.gov

################################################################################​###########################

# Example Site => papalace.com/pashop/checkout.php?id=&redirect=https://cxsecurity.com => [ Proof of Concept ] => archive.is/WYwco

################################################################################​###########################

# Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team

################################################################################​###########################

We don't care what people think about us, we are proud of us, we not gonna change for anyone. I do not have own no website. No Contact. # KingSkrupellos # Cyberizm Digital Security Technological Turkish Moslem Army.



Alinti



1 Ziyaretçi