Upgrade to Pro — share decks privately, control downloads, hide ads and more …

SITCON 2018 夏令營同樂會閃電講

k1tten
August 21, 2018

SITCON 2018 夏令營同樂會閃電講

k1tten

August 21, 2018
Tweet

Other Decks in Technology

Transcript

  1. Plurk Stored XSS 噗幣訊息 Stored XSS APP Show Stored XSS

    APP State Stored XSS APP ⾴⾯ Stored XSS APP EDIT ⾴⾯ Stored XSS
  2. Plurk Bountys 當然還有挖到其他的啦 XDD DoS Hardcode salt(⽤之前那份 leak) CSRF Bypass

    未使⽤ https 的⾴⾯(直接攔 cookie) 沒修好的 postscript 弱點
  3. iclass stored xss 然後我就 fuzzing 了⼀下 沒多久就發現可以透過留⾔板 Stored XSS 其他漏洞,透過

    restful api 可以直接更改 ⾃⼰姓名跟其他資訊(原本不能改) 上課點名:「meow」有來上課嗎︖