https://joshcsimmons.com/post/eNpTVlaoKC5WSEnNzefisilOLsosKL...
(this just injects a <script> alert but.... that's bad)
just tried contacting the author via linkedin (since I don't see an email address on their site)
@joshcsimmons are you around?
https://joshcsimmons.com/post/eNpTVlaoKC5WSEnNzefisilOLsosKL...
(this just injects a <script> alert but.... that's bad)
just tried contacting the author via linkedin (since I don't see an email address on their site)
@joshcsimmons are you around?
> Every post that I want to publicly claim authorship of lives at the root of this site. If you are reading a post that I have claimed it will look like this page. Posts of unknown authorship have a disclaimer at the top of the page.
https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...
Since the website is vulnerable to XSS, you could inject a script that removes the disclaimer.
base64 generates slashes, so the site (and I) run encodeURIComponent in the devtools on the resulting base64 to make sure it's completely url-safe.
---
the poc "payload" is
eNqzKU4uyiwosUvJTy7NTc0r0UtPLXHNSQUxi50qnXMSi4v9EnNTNdRzMtMzStQ1ow1i9YpSc%2FPLUjU0bfShmrm4lBVKMjKLFYAoKTEFACeDHYg%3D
which uri-component-decodes to:
eNqzKU4uyiwosUvJTy7NTc0r0UtPLXHNSQUxi50qnXMSi4v9EnNTNdRzMtMzStQ1ow1i9YpSc/PLUjU0bfShmrm4lBVKMjKLFYAoKTEFACeDHYg=
which un-base64+gzip's to (using the site I posted above):
<script>document.getElementsByClassName('light')[0].remove()</script>
# this is badthe second they start hosting any application/backend/cookie-enabled thing on this domain name, anyone could inject a script via their /post/ gzip-base64 scheme, and do bad things...?
I don't think html sanitization would go against the principle of this idea. just... at the very least strip the tags! :-)