Benjamin Flesch = definitely rocks.”> hi5 Antiphishing Departement (Update) ~ mybeNi websecurity, web security and hack stuff.

web securitymybeNi websecurity

hi5 Antiphishing Departement (Update)

March 24th, 2007

This evening I was searching for another “Social Community Platform” to abuse err… play with, and I found hi5, Alexa’s current #17 in traffic raking.

After some time I had set up a fresh user account and a couple of minutes later I found the first XSS vulnerability, which allowed me to execute my own Javascript on the User Profile.

Combined with hi5’s custom CSS and custom Subdomain features I served a hi5 Antiphishing Departement to the hi5 community out there which I am very proud of :-).

Together with our Myspace Antiphishing Departement (blogged here), the hi5 Antiphishing Departement proves, that Homepages that allow content and design entirely set by the users can easily abused for Phishing and other bad purposes.

UPDATE: They finally finished this vulnerability, so my hi5 Antiphishing Departement will be offline the next few weeks, but nevermind it was a great example for persistent XSS on a trusted Domain plus a good-looking URI: antiphishing.hi5.com. !




2 Responses to “hi5 Antiphishing Departement (Update)”:

  1. Philipp Says:

    That’s a good find!

    It would be nice if you contact me, for a little talk.


  2. beNi Says:

    thanks & done.


Leave a Reply


Google Traffic (7 days)

250
200
150
100
50
196
190
190
199
219
173
119
38.107.191.101