Bobinas P4G
  • Login
  • Public

    • Public
    • Groups
    • Popular
    • People

Conversation

Notices

  1. Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 15-Nov-2022 21:39:45 UTC Tinker ☀️ Tinker ☀️
    • Gareth Heyes :verified:
    • James Kettle

    Lol, when a bunch of hackers migrate to new services, they tend to kick the tires a bit 😂.

    Here, some hackers found a way to steal Mastodon passwords by manipulating the way Mastodon allows (and sidestepping the way Mastodon protects) HTML imbedded into posts.

    It also highlights the ways that third party plugins (here Glitch, found on the Mastodon server infosec(dot)exchange and others) introduce interesting attack vectors that core maintainers don't initially control (thoughts go out to Wordpress).

    The hackers then reported the issues to the Mastodon team and the Glitch team so they could issue security patches.

    Big shoutout for finding/reporting the vuln:

    • @gaz
    • @albinowax

    Kudos to the Mastodon & Glitch teams for coordinating and issuing a timely security patch.

    I expect we'll see a lot of more of these initially (this is good, means the website is getting more secure).

    Takeaways:

    • Users: Consider changing your Mastodon password. Implement Multi-Factor Authentication.
    • Admins: Update to the latest Mastodon version. Update any plugins as well.

    Full writeup here: https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp

    #infosec #WebAppPentesting #hacking #BugHunting

    In conversation Tuesday, 15-Nov-2022 21:39:45 UTC from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Stealing passwords from infosec Mastodon - without bypassing CSP
      The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP. Everybody on our Twitter feed seemed to be jumping ship to the infose

    Feeds

    • Activity Streams
    • RSS 2.0
    • Atom
    • Help
    • About
    • FAQ
    • Privacy
    • Source
    • Version
    • Contact

    Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.

    Creative Commons Attribution 3.0 All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.