Uploaded by jeremiahgrossman on Sep 18, 2008
In doing some crossdomain.xml Flash research I noticed that YouTubes policy file trusted *.google.com. Theyve since removed it after I privately disclosed the following security flaw to Google. My idea was if an attacker could upload an arbitrary Flash movie (SWF) anywhere on the google.com domain they could leverage that trust. So if an authenticated YouTube user visited an attacker-controlled page anywhere on the Web, the attacker could SRC in the google.com hosted SWF, and use it compromise the victims YouTube username, email address, first/last name, viewing history, and even comment or post/delete videos. Billy Rios blogged in the past about being able to upload arbitrary files to google.com, but the only place I could locate that allowed SWFs when I checked was Gmail. Maybe others? Anyway, I emailed a SWF attachment to a Gmail account and located the download URL. Perfect, but the next problem was even with the correct URL the victim is not authorized to view the file unless they are authenticated on THAT particular Gmail account. This is where the login-CSRF / identity misbinding trick the Stanford guys wrote up came in quite handy. Heres the step by step. 1) Attacker emails a special SWF to a Gmail account they control and locates the attachment download URL on google.com. 2) Logged-in YouTube user visits an attacker controlled page 3) Attacker forces their victim to authenticate to the attackers Gmail account (identify misbinding / CSRF). 4) Attacker embeds SWF from the Gmail account into the web page 5) Attacker now has read write access on YouTube.com as the victim's account. Clever eh? :) Im sure the Google/YouTube arent the only places where this scenario is possible.
Category:
Tags:
License:
Standard YouTube License
-
5 likes, 0 dislikes
9:01Flash Player Vulnerability - Demosby skilltutos2,061 views
2:40My.Brute Create a Black Bruteby marlontoyo697 views
6:43Local Wisdom \\Share EP5:Loading XML through fl...by lwinc380 views
1:36How to put SWF files in Bloggerby Kidlogicwiz8,705 views
5:41#3 myvideo security bug #csrf clickjacking by u...by demens0crew467 views
5:36Web Application Security with Jeremiah Grossmanby helpnetsecurity5,908 views
1:08Restaurant City :Collaborative Gifts Generator ...by nofil20005,159 views
10:00Flash, PHP, MySQL Integration Login/Register Tu...by BokoNOM6,046 views
3:39Cross Domain Requests (xdr)by DeveloperVideos409 views
5:56Jeremiah Grossman TV interview with ABC News (AU)by WhiteHatSecurity2,133 views
3:28Ataques Web: XSS, CSRF y aplicaciones AJAX vuln...by Casidiablo1,003 views
3:05ebaY Hacked! Redirect Exploit and Fake Page Res...by cappnonymous670 views
3:34Black Hat 2008: How Hackers Get Rich (& other s...by TechWebTV28,757 views
10:31TubeGuardian users, do you need help?by joshTheGoods1,149 views
3:32Hacking the Juniper 5GT Firewall CVE-2008-6096by spiderjacked4,619 views
2:09MyBrute Tutorial - How To Get A Black Bruteby Macellaro37,772 views
4:01How To Get Listed On the First Page of Google w...by DreamstarVideo1,023 views
1:36Securityby kevinmakesvideos2,078 views
2:21Test of Free walk program for FSXby yutasknight8,312 views
0:52Chat en flashby aduermael2,920 views
- Loading more suggestions...
Link to this comment:
All Comments (0)