PayPal.com XSS Vulnerability
seclists.org
seclists.org
Kudos for them being honest with both the bug and their age regardless.
The future is probably filled with teenagers discovering things, good and bad.
Teenagers are still prosecuted as adults but legally treated as less for other responsibilities.
* a 12 years old found a stack overflow bug in firefox's document.write, in 2010: http://www.mercurynews.com/san-jose-neighborhoods/ci_1640189... (https://news.ycombinator.com/item?id=1822117)
* "Pinkie Pie" is an anonymous teenager, he won $60k at Pwnium, and did it again at Pwnium 2
* @CimStordal, 15 (at the time), found XSS in Facebook, Apple, Google and Microsoft sites: http://www.internet-security.ca/internet-security-news-archi...
Tech has always been filled with teenagers discovering things, now more than ever. Most bounty handlers treat them as valued contributors, Paypal — as usual — shits all over everything.
2. well, fuck paypal!
3. not a good way to show PoC. Is there antiCSRF on search form? Can I see the whole flow?
The next person who'll discover something, will probably monetize it on the black market.
This kid just blamed Paypal for one of our country's many idiotic federal laws.
This choice should be considered a career limiting decision by any hiring manager.
(Obviously this is country/state specific)
Are you saying that you're holding a 17 year old student in Germany responsible for not understanding US labor laws?
You make it sound like if you hacked into Paypal from Germany you'd be completely immune to American law on the matter because you're not in the US.
That's simply not true.
Still very poorly handled. Should've gone something like:
1. "Hey, that's awesome that you found that, thanks!"
2. "For very good reasons (a), (b) and (c) we can't actually pay you, that really sucks :("
3. "But hey we like your style, so how about we fly you over for an internship when you've finished school / investigate if Germany has different rules / look at scholorship options and a great reference / [one of a million other things you could do to help a kid out"
Payment is paid through a verified Paypal account, which you must be 18 years of age to use their services according to their user agreement.
Hopefully not forever. When I was young and stupid and the net was a much simpler place I casually fully disclosed the problem with posting your Cisco configs with "encrypted" passwords to Usenet:
https://groups.google.com/d/msg/comp.dcom.sys.cisco/WjuKAOQL...
I would not do something like this today, especially not in such a full-of-myself douchey manner.
Sadly a lot of postings to the internet are basically "forever" at this point and combined with the insistence of so many companies that real names be used, we're going to have generations of younger folks who say or do something stupid (because they are young and stupid) that they can never get rid of. And that's unfortunate.
I completely agree. I also think that this kind of post on full-disclosure should be used as an example of what-not-to-do.
I've always treated vuln reward programs as resume enhancers. If you submit a bug and get it fixed, you get to show two incredibly valuable and rare skills in the infosec community:
1) technical chops 2) interpersonal skill
Disclosers who have the patience to endure some of the bullshit that comes up in these programs are going to be successful in the security industry. The hardest problems in infosec are not technical. They are cultural. Publicly flaming a vuln reward program because they didn't pay you for what you see as an arbitrary reason is exactly the kind of reason execs do not want to do vuln reward programs. Someone had to fight to get that program set up at paypal. It had to be within the laws of the country that governs the company. This kid just through a temper tantrum in public and signed his name on the email. Any advocates he had at paypal are probably re-evaluating their support of him. So short sighted.
who knew people were saving stuff back in 94-95. hell anyway 18 year old me didn't care, but luckily I can cover for him.
There is a reason that you read about minors running their own businesses all the time. The laws are targeted at employment that is exploitative or interferes with a child's education. Not at things like this.
Google has a lot more freedom and track record for asking forgiveness instead of permission than Paypal (i.e. wifi sniffing in google cars). They are not a payment processing company.
This stuff is complicated. Never attribute to malice that which is adequately explained by stupidity.
This link can be embedded on a different site, or sent via email, and because the link itself points to paypal.com - it is much more likely to be trusted by unsuspecting users.
Doesn't seem like that is the case here. The bug is in the search form, which is POST only. It wouldn't be enough to share the link to the search page, you'd need something that does the search on your behalf.
Note that _if_ the form is already CSRF-protected, then attackers won't easily be able to POST from a different domain either, which would drastically reduce the attack surface.
I didn't test this, but I'm not sure the form is fully CSRF protected though. I tried to explain the potential exploit from this discovered vulnerability. Perhaps I should have stated more clearly that this is more a general comment, and not specific to this particular case.
<form action="https://www.paypal.com/de/cgi-bin/searchscr?cmd=_sitewide-search" method="post">
<input type="text" name="queryString" value="xss code" />
</form>
Then, just as the page loads, submit that form and you're executing JS on a paypal.com page. This would work great for phishing or session hijacking.Once the form has been submitted on behalf of the user, you have javascript execution in the context of paypal.com, and can do pretty much anything. Send the contents of your account to another address, shut down the account, exfiltrate past transaction data, etc.
It seems quite possible that CSRF checks could have been omitted in not expecting this to be a source of woe. Just goes to show... :P
Just to name a few, http://www.xssed.com/search?key=paypal.com
(From memory, he also took a few photos of it also).
Would be interested to hear your response as it might give this another angle entirely, haha.
My personal experience with PayPal isn't particularly great, I'm a security researcher who's just turned 18, and even when I was underage I never actually disclosed that but regardless I had the following knocked back;
(Whole heap of non-critical XSS's, and two critical stored ones, The ability to edit titles on some PayPal subdomains (without giving too much information out) - This vulnerability still exists but I was told it was quote "not serious" even though the title field was vulnerable to stored XSS.
Full path disclosures, open administrative panels, whole variety of cookie/SSL/TSL based issues which I was told did not warrant a bounty.
Also had a personal friend (the same guy who found the XSS you've posted here) find a couple SQLi's on a few PayPal domains (post-auth) and he still hasn't heard back from them.
I'm not going to be the guy to accuse PayPal of not playing fair here, but my friend has also reported vulnerabilities I had previously reported and gotten paid for them. (Might be because he reports them from his security company email, whereas I was reporting them as an individual).
Anyway, Sad to hear you didn't get a bounty!
Also, if you don't have it here's a pretty good bug bounty list; http://bugcrowd.com/list-of-bug-bounty-programs/
Can you use something like Ghostery to allow any site to do its own JS but not external JS, besides whitelisted sites/externals?
That's exactly what noscript does. Use the option "Temporarily allow top-level sites by default->Base 2nd level Domains".
I suppose it might be useful with a browser extension/feature that allowed you to lock access to certain site's cookies until you have explicitly granted use. Sort of like how the keychain works on os x.