[FD] Yahoo! Bug Bounty #25 Flickr API - Persistent Service Vulnerability
Vulnerability Lab <[email protected]> Mon, 07 Jul 2014 15:31:52 +0200
| Newsgroups | gmane.comp.security.fulldisclosure,gmane.comp.security.full-disclosure |
|---|---|
| Message-ID | <[email protected]> |
Document Title:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Yahoo! Bug Bounty #25 Flickr API - Persistent Service Vulnerability
References (Source):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
http://www.vulnerability-lab.com/get_content.php?id=3D1132
Release Date:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
2014-07-06
Vulnerability Laboratory ID (VL-ID):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
1132
Common Vulnerability Scoring System:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
4.1
Product & Service Introduction:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D
Flickr is an image hosting and video hosting website, and web services suit=
e that was created by Ludicorp in 2004 and acquired by Yahoo 2005. =
In addition to being a popular website for users to share and embed persona=
l photographs, and effectively an online community, the service is =
widely used by photo researchers and by bloggers to host images that they e=
mbed in blogs and social media.
The Verge reported in March 2013 that Flickr had a total of 87 million regi=
stered members and more than 3.5 million new images uploaded daily.
In August 2011 the site reported that it was hosting more than 6 billion im=
ages and this number continues to grow steadily according to =
reporting sources. Photos and videos can be accessed from Flickr without th=
e need to register an account but an account must be made in order =
to upload content onto the website. Registering an account also allows user=
s to create a profile page containing photos and videos that the =
user has uploaded and also grants the ability to add another Flickr user as=
a contact. For mobile users, Flickr has official mobile apps for =
iOS, Android, PlayStation Vita, and Windows Phone operating systems.
(Copy of the Homepage: http://en.wikipedia.org/wiki/Flickr )
Abstract Advisory Information:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D
The Vulnerability Laboratory Research team discovered a persistent input va=
lidation web vulnerability in the official Yahoo Flickr! website web-applic=
ation and api.
Vulnerability Disclosure Timeline:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D
2013-11-03: Researcher Notification & Coordination (Ateeq ur Rehman Khan - =
Vulnerability Lab)
2013-11-04: Vendor Notification (Yahoo! Security Team - Bug Bounty Program)
2014-01-09: Vendor Response/Feedback (Yahoo! Security Team - Bug Bounty Pro=
gram)
2014-06-22: Vendor Fix/Patch (Yahoo! Developer Team - HackerOne Reward: 100=
0$)
2014-07-06: Public Disclosure (Vulnerability Laboratory)
Discovery Status:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Published
Affected Product(s):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Yahoo!
Product: Flickr Web Application - YPL API 2013 Q3
Exploitation Technique:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Remote
Severity Level:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Medium
Technical Details & Description:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D
A persistent input validation vulnerability has been discovered in the offi=
cial Yahoo Flickr! website web-application and api.
The vulnerability allows remote attackers to inject own malicious script co=
des to the application-side of the online-service.
The vulnerability is located in the flickr `invite` mail notification modul=
e. Remote attackers are able to inject payloads to =
the `message` value of the web-application notification service after the r=
egistration. The remote attacker can send invitation =
mails through the yahoo online-service module with manipulated message body=
context. The attack vector of the issue is located =
on the application-side and the request method to inject own malicious code=
s is POST.
The security risk of the persistent remote web vulnerability is estimated a=
s medium with a cvss (common vulnerability scoring =
system) count of 4.1. Exploitation of the vulnerability requires low user i=
nteraction and a low privileged flickr web-application =
user account. Successful exploitation of the vulnerability result in sessio=
n hijacking (customers), account steal via persistent =
web attack (mail), persistent phishing or persistent manipulation of notifi=
cation mails module context.
Vulnerable Service(s):
[+] Yahoo! > Flickr
Vulnerable Module(s):
[+] Invite (Invitation of Users)
Vulnerable Module(s):
[+] Notification Service (eMails)
Vulnerable Parameter(s):
[+] message (body)
Proof of Concept (PoC):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The persistent input validation web vulnerability can be exploited by remot=
e attackers with low privileged yahoo web application user account =
and low user interaction. For demonstration or to reproduce the security vu=
lnerability follow the provided information and steps below to continue.
PoC: Flickr Message - Invitation Attachment > Message Body
<tr style=3D"mso-yfti-irow:1">
<td style=3D"padding:1.5pt 1.5pt 1.5pt 1.5pt">
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"A=
rial","sans-serif""> <o:p></o:p></span></p>
</td>
</tr>
<tr style=3D"mso-yfti-irow:2">
<td style=3D"border:solid #CCCCCC 1.0pt;mso-border-alt:solid #CCCCCC =
.75pt;
padding:7.5pt 7.5pt 7.5pt 7.5pt">
<p class=3D"MsoNormal" style=3D"line-height:13.5pt"><span style=3D"fo=
nt-size:
10.0pt;font-family:"Arial","sans-serif"">I want to share my Flickr
photostream with you. If you get bored of that, there's loads of other
things to see there too. '%3d[PERSISTENT INJECTED SCRIPT CODE VIA MES=
SAGE VALUE!!!]'>"><b><span style=3D"color:#E83DA6">free</span></b>
and takes less than a minute with your Yahoo! ID.<o:p></o:p></span></=
p>
</td>
</tr>
Note: pTest:> bugbountyevo-/[email protected]
Reference(s):
http://www.flickr.com/invite/
http://www.flickr.com/
Solution - Fix & Patch:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The vulnerability can be patched by a secure parse and encode of the vulner=
able message body value input.
Filter or encode also the outgoing mails with the vulnerable db stored mess=
age body context to prevent script cod executions.
Security Risk:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The security risk of the persistent input validation web vulnerability is e=
stimated as medium(+).
Credits & Authors:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Vulnerability Laboratory [Research Team] - Ateeq ur Rehman Khan (ateeq@evol=
ution-sec.com) [www.vulnerability-lab.com]
Disclaimer & Information:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The information provided in this advisory is provided as it is without any =
warranty. Vulnerability Lab disclaims all warranties, either =
expressed or implied, including the warranties of merchantability and capab=
ility for a particular purpose. Vulnerability-Lab or its suppliers =
are not liable in any case of damage, including direct, indirect, incidenta=
l, consequential loss of business profits or special damages, even =
if Vulnerability-Lab or its suppliers have been advised of the possibility =
of such damages. Some states do not allow the exclusion or limitation =
of liability for consequential or incidental damages so the foregoing limit=
ation may not apply. We do not approve or encourage anybody to break =
any vendor licenses, policies, deface websites, hack into databases or trad=
e with fraud/stolen material.
Domains: www.vulnerability-lab.com - www.vuln-lab.com - ww=
w.evolution-sec.com
Contact: [email protected] - [email protected] =
- admin-sRlC7LJHFRmvt2SHZzvQTwC/[email protected]
Section: dev.vulnerability-db.com - forum.vulnerability-db.com =
- magazine.vulnerability-db.com
Social: twitter.com/#!/vuln_lab - facebook.com/VulnerabilityLab =
- youtube.com/user/vulnerability0lab
Feeds: vulnerability-lab.com/rss/rss.php - vulnerability-lab.com/rss/rs=
s_upcoming.php - vulnerability-lab.com/rss/rss_news.php
Programs: vulnerability-lab.com/submit.php - vulnerability-lab.com/list=
-of-bug-bounty-programs.php - vulnerability-lab.com/register/
Any modified copy or reproduction, including partially usages, of this file=
requires authorization from Vulnerability Laboratory. Permission to =
electronically redistribute this alert in its unmodified form is granted. A=
ll other rights, including the use of other media, are reserved by =
Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advi=
sories, source code, videos and other information on this website =
is trademark of vulnerability-lab team & the specific authors or managers. =
To record, list (feed), modify, use or edit our material contact =
([email protected] or [email protected]) to get a pe=
rmission.
Copyright =A9 2014 | Vulnerability Laboratory [Evolution Security]
-- =
VULNERABILITY LABORATORY RESEARCH TEAM
DOMAIN: www.vulnerability-lab.com
CONTACT: [email protected]
_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/