Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   234

Client side injection allows privilege and alternative probability

by Heavenscent - 11 October, 2020 - 12:04 AM
This post is by a banned member (Heavenscent) - Unhide
319
Posts
104
Threads
5 Years of service
#1
(This post was last modified: 11 October, 2020 - 12:17 AM by Heavenscent.)
Cloned the site first of all so I had all your code to test - I'm not gonna rape a site I respect and use.

Basically you just have to bet a few times whilst paying very close attention

You make an injectable payload bypassing/changing whatever parameters you need to I was able to bypass ALL sellix as their API is public

I could create coupons as the seller for 99.99% off - this can also be done if you make a shitty website and post links to shit you want from sellix then inject at your hearts content

Some of this can even be done my pushing F+12 and posting in console

Not to mention your authentication system is on gihub (not sure if you've changed it) but a program could be made bruteforcing (or the other one I can't mind the name) the request to add Upgrades or credits

Also using AI programmed in a bot you can go from.a premium Auth key to supreme after a little machine learning

Burp suite will help you here as well as other tools no low quality GitHub branches your need the good software (Dr.ZarZar) has top 3 to find the stuff I did to fake admin privileges

You just need to change the code up slightly perhaps an apply and acceptance to certain areas of the forum?

I wish I didn't delete this now cus I could've send the code or at least screen recorded the process..

But yea HQ dev tools and pentesting

Also here is a resource i used to make up the injection:
https://github.com/danielmiessler/SecLists

Everything I did I could put in software easily and j was tempted just for the sheer fact of testing it out.... So done nulled & breakingin Sam's attacks work

https://github.com/swisskyrepo/PayloadsAllTheThings

https://github.com/fuzzdb-project/fuzzdb

I'd pay close attention to those when testing

Advanced user status can be gained by injecting fake cookies sometimes to

@Liars

@Darkness @Teken

Also just wanna reiterate I haven't used this on here as you can see my stats are the same - I cloned the site and self hosted and performed everything on the clone
[Image: be_1.gif]
This post is by a banned member (Barry) - Unhide
Barry  
Staff
17.981
Posts
6
Threads
Staff Team
6 Years of service
#2
Good work by raising critical issues regarding forum security.

Hope @florain and @J_S will work on this stuff.
 
[Image: blgL61y.gif]
.
.
[Image: CUfRmpx.gif]
[Image: ezgif-3-47cb4ec9e5.gif]
 
Important Notice: I am not affiliated with any of the ads above.
Beware of Impersonators! Always confirm via on-site PM. I do not use Discord or Telegram, and I do not sell, exchange, or trade anything.
This post is by a banned member (Heavenscent) - Unhide
319
Posts
104
Threads
5 Years of service
#3
(11 October, 2020 - 04:46 PM)Barry Wrote: Show More
Good work by raising critical issues regarding forum security.

Hope @florain and @J_S will work on this stuff.

It was honestly by accident trying to bypass the payment on a LQ ebook purchase and I realized that you can view the sellers ID which is all the API needs so you can create products/coupons etc remotely if you install the API elsewhere

I'd actually recommend not having sellix directly implemented into the forum for that reason specifically Smart
[Image: be_1.gif]
This post is by a banned member (KSZ) - Unhide
KSZ  
Supreme
4.701
Posts
53
Threads
7 Years of service
#4
(11 October, 2020 - 05:03 PM)DeanMartin Wrote: Show More
(11 October, 2020 - 04:46 PM)Barry Wrote: Show More
Good work by raising critical issues regarding forum security.

Hope @florain and @J_S will work on this stuff.

It was honestly by accident trying to bypass the payment on a LQ ebook purchase and I realized that you can view the sellers ID which is all the API needs so you can create products/coupons etc remotely if you install the API elsewhere

I'd actually recommend not having sellix directly implemented into the forum for that reason specifically Smart

You are just full of bullshit and so is your thread. Let people deal with those things that actually have a clue about it

[Image: I4kF791.gif]

Important note: Do not private message me for IntenseProxy support, instead send an email to support@intenseproxy.com
 

 

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.



Forum Jump:


Users browsing this thread: 1 Guest(s)