Sunday, August 18, 2013

Yo Bug Hunter, whatcha going to do if your confirm-a-bug got rejected?!

Hi guys, Its been a while. Lately there's a havoc regarding a person named Khalil got his Facebook Bug submission got rejected. In case you dont know it yet, read it Here Hmm..this case quite similar to the 13 year old guy that got his Paypal bug rejected previously.But this 13 year old bug afaik, his bug already found by somebody else. But still, since both of them (Khalil and this guy) make a Public Disclosure, the Bug Bounty Program might get some impact on it. Maybe researcher will try to avoid to join their BB program after this. I did give a comment on this when Casey the founder/CEO of Bugcrowd ask in one of FB Group.


To be honest, even I had some experiences when my bug rejected not just from Facebook,also from Paypal,Google and even Bugcrowd! :P Why this happen? For sure these are some reasons why mine got rejected;

1 - Not in scope. Rules violation
  Read the rules first to check what is in scope and what is not!!

2 - Lack of techies step to let their side to reproduce the bug.
 Please,their side need to counter at least more than 100+ reports per staff..so,we want their reward, we need to help them as well.

3 - The impact is not worth to be called as bug!
 Here are some shots for my rejected bug.

So, whose fault? I dont blame much to any side. Just took it as another experience with BB program. So next time I wont repeat the same thing. But, in case your bug is really a BUG! and they said it as "Not a Bug" or "No Impact", proof to them! As what happen to me recently with Paypal BB Program. I found a Self/Stored XSS in Paypal's domain and give them the step to repro it as usual. But, this what I got in my latest status update!


My bug claimed by them as invalid?!! I ask them and this is their reply.



Because I dont really agree with them, I ask them to recheck on it with a more details on the issue. I got a good response from them, and they ask me to show the impact with a proper step. I did,and this is the result;


Now I can sit back and relax..time to hunt another bug..soon.. :)

Tuesday, June 25, 2013

Bug Bounty - Is it similar? NO!

Hi,
I'm going to share another case where I attempt from bug bounty program.
The issue I found initially was from Paypal Bug Bounty Program. And few weeks ago, I found a similar issue in Google's service. So did I rewarded from both of them? Lets check it out.

The issue I found is Sensitive Information Leakage. Where user's personal email used for registration for that application exposed to the attacker with a simple method.

In Paypal Bug Bounty Program, the URL affected was

https://www.paypal-communications.com/Zone/Registration.aspx
As we can see from above screenshot, there's a form for us to "Retrieve Password" a.k.a Forgot Password.

If we submit a non-exist user, the application will throw a message "No User Found" 


So? what's the issue actually? its normal aint it?!


Nothing's wrong?! Hah! Look on image below then!


Got it? Yeah! If we put a valid username on that form,the message will show user's personal email. As shown above, I test for username administrator and I can see his/her personal email used for this application. This might be used for some Social Engineering attack.

For this issue, Paypal rewarded me $100. 

So how about the case with Google Bug Bounty? Did they reward me as well?
Yeah,Google did not accept that issue as a risk. I'm not going to deny their judgement. Its up to their company. Each company do have their own severity level identification.
Below is the screenshot I sent to Google team.


I think that's all guys. Till next time with another sharing from me :)

EDIT

some of you might noticed that this post disappear with sudden previously. This is due to another reply I got from Google;


Yes, Google also take this issue as a threat/bug as well. So I need to draft the post until the issue fixed. Just checked just now and seems the issue was resolved.

Adios
@yappare

Friday, June 21, 2013

Google Bug Bounty - Dont Waste Your Time XSSing the Sandbox Domain

Hi All,
In this post I'm going to share some of XSSes I found for Google Bug Bounty. However all of these findings are located in their sandbox-domain.

Eventhough there's still a risk for user such as phishing,malware,jdb and so on,still under Google Bug Bounty Program,it is not acceptable.

This info is mentioned at their page
http://www.google.com/about/appsecurity/reward-program/#notavuln

If you still trying to send bugs found in sandbox-domain,this kind of email will appear in your inbox

The domain in which the feature is hosted is specifically meant as a
compartmentalized "sandbox" for various types of potentially unsafe,
user-controlled content. This domain is isolated from any sensitive
content due to the same-origin policy.
 Since there's no reward for sandbox-domain, I asked their permission to publish the bug in my blog and got their permission :)


Below are some of XSSes I found in their sandbox-domain and of course,rejected -_-"

*.googleapis.com
bug existed due to old version of Jplayer

*.googledrive.com
similar issue found in googleapis.com, old version Jplayer

*.googleusercontent.com
Stored XSS. Can found this in Google Current. However,there's someone else found this previously

*.2mdn.net
This one found after Internetwache posted in his blog trying to bypass limited char XSS.

I think that's all! See you again! 

adios
@yappare

Wednesday, June 19, 2013

Facebook Bug Bounty - Time Based SQLi in FB's Acquisition

Hi,
I'm back.
Previous post I talked about how long the FB's Security team will reply you for your 1st reward (in my case almost a month)

Here's the POC for my finding.
Owh btw, I'll censored the URL. Why? I'm quite sure there's still more bugs in this acquisition. So, for a real bug hunter, with these images, they'll know how to find the real site :D Goodluck!

Time Based SQLi in FB's Acquisition
----------------------------------------------

I checked out on their forgot password form. By testing with single quote (') there's a weird but well-known error appear.yes,SQL error.

Hmm..lets try to close the quote.



 auwwwwwwwwww...SQLi! 

Now lets try to give some POC. Use a simple testing with 1 or 1=1 thingy.

hmm unknown error? so this is TRUE/FALSE response.

hah! different error.this might be its FALSE/TRUE response then.

I'm on the right track! but its still not enough for a POC!

Try to figure out a valid column? Lets try the same thing I used for my bounty in Paypal's bounty.

Testing to check if xxxxx is a valid column..NO!

Testing if user is a valid column. YEAH!!!

Final touch-up..lets try with Time-Based testing!



Finally..My bug accepted by Facebook and will join the FB's whitepage. Mission accomplished and..

Adios.
@yappare

Facebook Bug Bounty - Finally :D

Facebook Inc have their own Bug Bounty Program which you can find it here. The reward quite interesting.
On 9th May, I found a SQLi Bug in one of their acquisition. I submitted to their team and they acknowledge it.


On 29th May, I noticed that the bug had been fixed, and I shoot an email on that to their team asking for confirmation and of course waiting for my reward :P


However, there's no reply. At first its quite frustrating, but after thinking back when my first reward with Paypal bug bounty, they took quite a time as well. So I just waiting patiently. Even one of my buddy, Prakhar in his comment for this blog


So today,that day has come :D
The email that I have been waiting for was sent to my inbox.


Another mission accomplished!!


The POC? I'll share it on my next post :)

Thursday, May 23, 2013

Few XSSes found for Google BugBounty Program.

Hello,
Its been a while for me to update this blog. Here are some XSSes I found and were fixed by the Google Team.

thinkwithgoogle.com Reflected XSS via search form - rewarded

v1.zeromomentoftruth.com Stored XSS via CommentBox - HoF

Google Transliterate Self XSS - Dupe

sharegoogleapps.com Reflected and Stored XSS via email invitation - rewarded

sharegoogleapps.com Stored XSS via Google Contacts import - rewarded

afaik, all of these issues have been fixed.
There are two more issues will be shared with you guys in future :)

Thanks,
@yappare

Thursday, April 18, 2013

Ihack 2013 - Forensic Challenge - Writeup Collections.

So, I'll put all of them in 1 post so everyone can refer it easier :)

10 Points
-----------
- just find my twitter on that day.

50 Points
------------
- http://www.youtube.com/watch?v=MJXww8aizAM
- look at the phone numbers

100 Points
--------------
1 - Pokemon Cryptography - here
2 - Kamen Rider Image Forensic - here
3 - Snow White - here

200 Points
-------------
1 - XOR Crypto - By BeardBazen
2 - Packet Analysis - By Naja

300 Points
-------------
1 - VM Forensic - here
2 - File Recovery - By Naja

400 Points
-------------
1 - Packet Analysis - By BeardBazen
2 - Audio/Video Forensic - By BeardBazen

500 Points
-------------
1 - File Recovery - By BeardBazen
2 - File Recovery - By Nafiez
3 - QR Code - here


Complete! And again congratz to all participants. :)

Ihack2013 - Forensic Writeup Challenge 500 Point - QReption

Hopefully this last writeup will complete the solutions for all forensic questions in Ihack2013. BeardBazen, you owe me writeups for any puzzle that is(are) not published yet :P

This is the another question that no one able to solve. Yes,I made this one for that purpose LOL. This is my trump card in case any team manage to solve other questions.

Team was given with this QR image
The clue? Look at the question.
Leonardo asked if you guys ever watched inception. Its a story where a person jump into others dream and so on.. same as this puzzle. there'll be QR code in another Qr code and so on.
hahahaha..that's the real thing that you guys should do actually..BUT....
































I uploaded a wrong qr file. so its impossible to solve it.muahahahahahahahahahhahahahahahaha just noticed it few minutes ago. ROFL!

guys,i'm sorry.haha



Wednesday, April 17, 2013

Ihack2013 - Forensic Writeup Challenge 100 Point - Snow White

Hi again, another writeup from me for you guys to learn especially the 1st timer in Ihack. Most of the team really give their best in solving each puzzle/challenge. Its good to see that kind of passion in youngsters. Do send me your CV if once you graduated :P

For this challenge each team was given this kind of task

again, the clue is right in front of you..SPACEWHITE..what kind of IT related to the SPACEWHITE? its a whitespace programming.
read it here

Can see lots of contestants give some efforts in googling..but less of them give an effort to READ them carefully.
Patience young padawan. Read if you must, dont too depend on the online tools.
From the wikipedia, can see that this whitespace programming
"Onlyspacestabs and linefeeds have meaning"
Read more about it.

"Data is represented in binary using spaces (0) and tabs (1), followed by a linefeed, space-space-space-tab-space-tab-tab-linefeed is the number 11"
Yes. That's the right way to understand how to solve this puzzle. Look at the Snow White poem given during the game. Each paragraph,there'll be a weird spacing..Decode each of them to get a binary code and you'll get the flag on the spot once its been decoded.
How I can decode those spaces and tabs into binary? Simple.Use notepad++ :)



Once you replaced all the tabs and spaces available ( note that just change those between paragraph,else your poem will be messy )

the flag is th1s_!5_s0_s1mPl3


Tuesday, April 16, 2013

Ihack2013 - Forensic Writeup Challenge 300 Point - VM Forensic

As requested by Mr Ramadhan, here's the writeup!
The question was
So each team was given with this file 695f616d5f7468655f6861786f72.7z.
Extract it will gives them another folder and in it there's a file named ihaxor.
What kind of file is that? Again, use FILE command.
Yes. Its a tar archive. Extract it again will give you a virtualbox image. Import it in your virtualbox machine.

Hello Slitaz! Its a slitaz VM. Dont know the password? Please,google it.

Ok now I'm in. What's next? Most of the teams were confused with the files exist in this slitaz. Everyone keep thinking the way to be a root user..But its not the right way to solve it! Why those folders existed? Yeah, of course I put it as a troll LOL!

Read the question "Dont think too hard". As a Pro Hacker, please..a basic step. Look for ALL files available first.

Yeah. There's a .ash_history  file. Look at that file. Its a common thing once you get into someone's PC in order to do some forensic investigation.
Viewed the file and will noticed that there's a weird file named wipipipipi.txt. Did you guys try to look for that file??
Woot!! I found the file. Its in the /log folder. (and its one of the folder that a forensic investigator should look at )
Found,lets look what is inside.
TADAAAAAA!!! there's your flag!
flag is f0r3ns!c.is.3asy

muahahahaha..easy right?! Trolled hard?yeah you got trolled. Stop claiming yourself as a hacker now. LOL