Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Fixes and Improvements

June 11th, 2012, 07:28 GMT · By

Researchers Find Critical XSS Vulnerability in Tumblr

SHARE:

Adjust text size:

Proof of vulnerability in Tumblr
Enlarge picture
Independent Indian security researchers Aditya Gupta and Subho Halder have identified a dangerous cross-site scripting (XSS) vulnerability in the popular blog hosting platform Tumblr.

According to the experts, the security hole is not something that should be left unaddressed since it poses a lot of risks for the site’s customers. The screenshot provided by the researchers shows how the vulnerability could be leveraged.

“As you can see, I could get the cookies of any user who visits my profile page. They are the actual Tumblr authentication cookies, which means I could use the cookies to login to the respective user accounts,” Gupta explained.

And apparently stealing user sessions is not the only thing that could be achieved by using this weakness. An attacker could leverage this flaw to cause even more serious damage.

“Also, I could make a complete worm out of it, so when one person views my profile, he would repost my post and everyone in his list who would see it would then be doing the same. All automatically and without the user’s knowledge,” he told us.

While the vulnerability seems highly dangerous, the researchers claim that so far Tumblr has ignored their findings.

“I have tried to contact them via Twitter and mail earlier, but no response from their side. So we have decided to release it. Well, not exactly where the vulnerability is, but just to let them know that it is vulnerable,” Gupta said.

Hopefully Tumblr will act on addressing the issue before a cybercriminal mastermind sees a “business opportunity” in it.

The experts have provided a working proof-of-concept, which of course we will not make public, at least not until the bug is fixed.
FILED UNDER:
XSS
Tumblr
worm
Gupta
Halder


2,833 hits · 4 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Iranian Hackers Compromise NASA SSL Certificate, Agency Investigates

Hacker Publishes XSS Flaws in US Army and Media Sites After Exploiting Them

Hacker Reports XSS Flaws to US Department of Energy, NASDAQ, NASA

Holy Lulz Crusade: Hackers Target Canadian Government and University Sites

Big Bang Theory Inspires Hacker to Find SQL Injection Flaw on ORNL Site

READER COMMENTS:


Comment #1 by: cyberaditya on 11 Jun 2012, 07:45 UTC reply to this comment

congrats to @aditya gupta :)


Comment #2 by: Awijit on 11 Jun 2012, 10:11 UTC reply to this comment

They are stealing it.. it was originally discovered by Cyberzeist.

Comment #2.1 by: Aditya Gupta on 12 Jun 2012, 15:21 GMT

Haha. Nothing like that. Once the bug has been patched, we'll be posting how we found that bug, and the method we used to exploit it.
Can assure you that, THAT xss hasn't been found by him. Maybe some other one on tumblr itself.


Comment #3 by: seriously?!? on 12 Jun 2012, 15:03 UTC reply to this comment

These are all just Google Analytics cookies! This doesn't even remotely work.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM