https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...
https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...
The client-side XSS is mostly harmless (assuming you don't have any other sensitive services running with cookies scoped to this domain), although it's technically a persistent XSS, which means it could be indexed by search engines.
But is there a server-side component to this? I noticed that the "disclaimer" is added in the source returned by the server, so I assume there is some code that checks whether the post is present on the home page? If so, that could be dangerous, if there is a bug in that code such that a malicious payload in the URL could get RCE in your server process.
TBH I haven't thought about most of these things. Nobody typically reads my blogs when I've made them before and this is likely the only interest it will get for quite a while.
Can't promise I won't circumvent it when I've got some time...
If the wrong person publishes the wrong link, you can get your domain banned from Google and tons of other sites as a "security risk", which can spread to your email (if you use @joshcsimmons.com).
It's fine if you don't care about blacklists of course, but this kind of abuse can easily sneak up on you.
Doesn't need to release tools... gzip, base64 and uri encode uh huh.
> Every post that I want to publicly claim authorship of lives at the root of this site. If you are reading a post that I have claimed it will look like this page. Posts of unknown authorship have a disclaimer at the top of the page.
https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...
(His permalinks are horrible, lol)
Problem is, the posts can contain <script> elements. So it's easy to just write a little JavaScript that removes the disclaimer at the top. See this hastily-made, immature example of mine:
https://joshcsimmons.com/post/H4sIABO8LmUC/3VT0W7aQBB85yu2QV...
As it stands, this really isn't the most secure system. Something much more malicious could be injected into this!
Either way, considering the submission we’re commenting on, the author of the blog may appreciate your humour.
EDIT: understand you are not the OP btw, just wondering out loud.
It’s not a good use case IMO, but that is all I can think of lol