[FD] Yahoo! Bug Bounty #25 Flickr API - Persistent Service Vulnerability

Vulnerability Lab <[email protected]> Mon, 07 Jul 2014 15:31:52 +0200
Newsgroups gmane.comp.security.fulldisclosure,gmane.comp.security.full-disclosure
Message-ID <[email protected]>
Document Title:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Yahoo! Bug Bounty #25 Flickr API - Persistent Service Vulnerability


References (Source):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
http://www.vulnerability-lab.com/get_content.php?id=3D1132


Release Date:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
2014-07-06


Vulnerability Laboratory ID (VL-ID):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
1132


Common Vulnerability Scoring System:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
4.1


Product & Service Introduction:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D
Flickr is an image hosting and video hosting website, and web services suit=
e that was created by Ludicorp in 2004 and acquired by Yahoo 2005. =

In addition to being a popular website for users to share and embed persona=
l photographs, and effectively an online community, the service is =

widely used by photo researchers and by bloggers to host images that they e=
mbed in blogs and social media.

The Verge reported in March 2013 that Flickr had a total of 87 million regi=
stered members and more than 3.5 million new images uploaded daily.
In August 2011 the site reported that it was hosting more than 6 billion im=
ages and this number continues to grow steadily according to =

reporting sources. Photos and videos can be accessed from Flickr without th=
e need to register an account but an account must be made in order =

to upload content onto the website. Registering an account also allows user=
s to create a profile page containing photos and videos that the =

user has uploaded and also grants the ability to add another Flickr user as=
 a contact. For mobile users, Flickr has official mobile apps for =

iOS, Android, PlayStation Vita, and Windows Phone operating systems.

(Copy of the Homepage: http://en.wikipedia.org/wiki/Flickr )


Abstract Advisory Information:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D
The Vulnerability Laboratory Research team discovered a persistent input va=
lidation web vulnerability in the official Yahoo Flickr! website web-applic=
ation and api.


Vulnerability Disclosure Timeline:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D
2013-11-03:	Researcher Notification & Coordination (Ateeq ur Rehman Khan - =
Vulnerability Lab)
2013-11-04:	Vendor Notification (Yahoo! Security Team - Bug Bounty Program)
2014-01-09:	Vendor Response/Feedback (Yahoo! Security Team - Bug Bounty Pro=
gram)
2014-06-22:	Vendor Fix/Patch (Yahoo! Developer Team - HackerOne Reward: 100=
0$)
2014-07-06:	Public Disclosure (Vulnerability Laboratory)


Discovery Status:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Published


Affected Product(s):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Yahoo!
Product: Flickr Web Application - YPL API  2013 Q3


Exploitation Technique:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Remote


Severity Level:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Medium


Technical Details & Description:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D
A persistent input validation vulnerability has been discovered in the offi=
cial Yahoo Flickr! website web-application and api.
The vulnerability allows remote attackers to inject own malicious script co=
des to the application-side of the online-service.

The vulnerability is located in the flickr `invite` mail notification modul=
e. Remote attackers are able to inject payloads to =

the `message` value of the web-application notification service after the r=
egistration. The remote attacker can send invitation =

mails through the yahoo online-service module with manipulated message body=
 context. The attack vector of the issue is located =

on the application-side and the request method to inject own malicious code=
s is POST.

The security risk of the persistent remote web vulnerability is estimated a=
s medium with a cvss (common vulnerability scoring =

system) count of 4.1. Exploitation of the vulnerability requires low user i=
nteraction and a low privileged flickr web-application =

user account. Successful exploitation of the vulnerability result in sessio=
n hijacking (customers), account steal via persistent =

web attack (mail), persistent phishing or persistent manipulation of notifi=
cation mails module context.

Vulnerable Service(s):
				[+] Yahoo! > Flickr

Vulnerable Module(s):
				[+] Invite (Invitation of Users)

Vulnerable Module(s):
				[+] Notification Service (eMails)

Vulnerable Parameter(s):
				[+] message (body)


Proof of Concept (PoC):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The persistent input validation web vulnerability can be exploited by remot=
e attackers with low privileged yahoo web application user account =

and low user interaction. For demonstration or to reproduce the security vu=
lnerability follow the provided information and steps below to continue.

PoC: Flickr Message - Invitation Attachment > Message Body

    <tr style=3D"mso-yfti-irow:1">
      <td style=3D"padding:1.5pt 1.5pt 1.5pt 1.5pt">
      <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"A=
rial","sans-serif""> <o:p></o:p></span></p>
      </td>
     </tr>
     <tr style=3D"mso-yfti-irow:2">
      <td style=3D"border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC =
.75pt;
      padding:7.5pt 7.5pt 7.5pt 7.5pt">
      <p class=3D"MsoNormal" style=3D"line-height:13.5pt"><span style=3D"fo=
nt-size:
      10.0pt;font-family:"Arial","sans-serif"">I want to share my Flickr
      photostream with you. If you get bored of that, there's loads of other
      things to see there too. '%3d[PERSISTENT INJECTED SCRIPT CODE VIA MES=
SAGE VALUE!!!]'>"><b><span style=3D"color:#E83DA6">free</span></b>
      and takes less than a minute with your Yahoo! ID.<o:p></o:p></span></=
p>
      </td>
     </tr>

Note: pTest:> bugbountyevo-/[email protected]

Reference(s):
http://www.flickr.com/invite/
http://www.flickr.com/


Solution - Fix & Patch:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The vulnerability can be patched by a secure parse and encode of the vulner=
able message body value input.
Filter or encode also the outgoing mails with the vulnerable db stored mess=
age body context to prevent script cod executions.


Security Risk:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The security risk of the persistent input validation web vulnerability is e=
stimated as medium(+).


Credits & Authors:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Vulnerability Laboratory [Research Team] - Ateeq ur Rehman Khan (ateeq@evol=
ution-sec.com) [www.vulnerability-lab.com]


Disclaimer & Information:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The information provided in this advisory is provided as it is without any =
warranty. Vulnerability Lab disclaims all warranties, either =

expressed or implied, including the warranties of merchantability and capab=
ility for a particular purpose. Vulnerability-Lab or its suppliers =

are not liable in any case of damage, including direct, indirect, incidenta=
l, consequential loss of business profits or special damages, even =

if Vulnerability-Lab or its suppliers have been advised of the possibility =
of such damages. Some states do not allow the exclusion or limitation =

of liability for consequential or incidental damages so the foregoing limit=
ation may not apply. We do not approve or encourage anybody to break =

any vendor licenses, policies, deface websites, hack into databases or trad=
e with fraud/stolen material.

Domains:    www.vulnerability-lab.com   	- www.vuln-lab.com			       		- ww=
w.evolution-sec.com
Contact:    [email protected] 	- [email protected] 	=
       		- admin-sRlC7LJHFRmvt2SHZzvQTwC/[email protected]
Section:    dev.vulnerability-db.com	 	- forum.vulnerability-db.com 		     =
  		- magazine.vulnerability-db.com
Social:	    twitter.com/#!/vuln_lab 		- facebook.com/VulnerabilityLab 	    =
   		- youtube.com/user/vulnerability0lab
Feeds:	    vulnerability-lab.com/rss/rss.php	- vulnerability-lab.com/rss/rs=
s_upcoming.php   		- vulnerability-lab.com/rss/rss_news.php
Programs:   vulnerability-lab.com/submit.php  	- vulnerability-lab.com/list=
-of-bug-bounty-programs.php	- vulnerability-lab.com/register/

Any modified copy or reproduction, including partially usages, of this file=
 requires authorization from Vulnerability Laboratory. Permission to =

electronically redistribute this alert in its unmodified form is granted. A=
ll other rights, including the use of other media, are reserved by =

Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advi=
sories, source code, videos and other information on this website =

is trademark of vulnerability-lab team & the specific authors or managers. =
To record, list (feed), modify, use or edit our material contact =

([email protected] or [email protected]) to get a pe=
rmission.

				Copyright =A9 2014 | Vulnerability Laboratory [Evolution Security]



-- =

VULNERABILITY LABORATORY RESEARCH TEAM
DOMAIN: www.vulnerability-lab.com
CONTACT: [email protected]



_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/