Facebook Hacking | Hacking Tools | Facebook Hacking Tool | Twitter Hacking | Crash Website | Hack Gmail Account

Found XSS Vulnerability in Blogger

Posted by Deepanker Verma Thursday, June 14, 2012 0 comments
I am a blogger and use Google's Blogger platform to publish my posts. This blog is also hosted on Blogger. Few days back, i noticed something strange on blogger. Then i tried to do some research on that.


After few minutes of research, I found XSS on blogger. 

If you are a regular user of Blogger, you notice an alert error box of blogger which generally prompts on the screen. This experiment deals with that. I am not revealing details as i have contacted with Google regarding the issue. 


Here are few snapshots:


A prompt Box

Cookies On Alert Box
Custom Message on Alert box


After writing the post, when i saw the preview of the post, these boxes were also there.
I gave the preview link of post to other users logged in their blogger account, they were also able to see their cookies.

0 comments:

Post a Comment

Featured FREE Resource:




Security Tools

Share
Get This

About Me

My Photo
Deepanker Verma
I am Deepanker Verma. A computer geek, Security researcher blogger and software developer. I have deep interest and Information security and web development and try to learn new things. you will see my blogs on hackingtricks, TechlomediaWebtips and Usethistip.

I was also honoured by Apple, Ebay, Symantec, PandaSecurity and various other computer software giants for my security work for their company. I also contribute on some opensource projects regularly.

I also own a web app called NoteDIP that allows users to send self-destructive messages with password protection.

You can add me to circles to get my daily tips :)

View my complete profile

Partners

Blog Archive