More
See all Show me
1. Google YouTube crossdomain security flaw
1 year ago
In doing some crossdomain.xml Flash research I noticed that YouTubes policy file trusted *.google.com. Theyve since removed it after I privately disclosed the following security flaw to Google. My idea was if an attacker could upload an arbitrary Flash movie (SWF) anywhere on the google.com domain they could leverage that trust. So if an authenticated YouTube user visited an attacker-controlled page anywhere on the Web, the attacker could SRC in the google.com hosted SWF, and use it compromise the victims YouTube username, email address, first/last name, viewing history, and even comment or post/delete videos. Billy Rios blogged in the past about being able to upload arbitrary files to google.com, but the only place I could locate that allowed SWFs when I checked was Gmail. Maybe others? Anyway, I emailed a SWF attachment to a Gmail account and located the download URL. Perfect, but the next problem was even with the correct URL the victim is not authorized to view the file unless they are authenticated on THAT particular Gmail account. This is where the login-CSRF / identity misbinding trick the Stanford guys wrote up came in quite handy. Heres the step by step. 1) Attacker emails a special SWF to a Gmail account they control and locates the attachment download URL on google.com. 2) Logged-in YouTube user visits an attacker controlled page 3) Attacker forces their victim to authenticate to the attackers Gmail account (identify misbinding / CSRF). 4) Attacker embeds SWF from the Gmail account into the web page 5) Attacker now has read write access on YouTube.com as the victim's account. Clever eh? :) Im sure the Google/YouTube arent the only places where this scenario is possible.
This conversation is missing your voice. Take five seconds to join Vimeo or log in.

Advertisement

Statistics

  •  
    plays
    likes
    comments
  • Total
    plays 1,649
    likes 2
    comments 0
  • Dec 25th
    plays 0
    likes 0
    comments 0
  • Dec 24th
    plays 1
    likes 0
    comments 0
  • Dec 23rd
    plays 0
    likes 0
    comments 0
  • Dec 22nd
    plays 5
    likes 0
    comments 0
  • Dec 21st
    plays 1
    likes 0
    comments 0
  • Dec 20th
    plays 2
    likes 0
    comments 0
  • Dec 19th
    plays 0
    likes 0
    comments 0
  • Dec 18th
    plays 2
    likes 0
    comments 0
Previous Week

Downloads

Please join Vimeo or log in to download the original file. It only takes a few seconds.