AdSense AdLogger 1.1 XSS vulnerabilities fix

Discussion in 'Reporting & Stats' started by sztojka, Aug 31, 2006.

  1. #1
    I hope I could fix some XSS security holes in AdLogger 1.1. I hardly recommend to download it.

    Link: http://hac.kers.hu/AdSense-AdLogger-1.1-XSS-vulnerabilities-fix_t32.html
     
    sztojka, Aug 31, 2006 IP
  2. Ponynugget

    Ponynugget Peon

    Messages:
    1,183
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    0
    #2
    I could be wrong but I'd be very wary of visiting that link. Take a look at the URL before even thinking of copying and pasting that into your address bar.

    Apologies if I'm wrong. ;)
     
    Ponynugget, Aug 31, 2006 IP
  3. sztojka

    sztojka Guest

    Messages:
    5
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Pony, you're right, but it's your turn.

    I made it for myself, and I share with the community. It contains the fixed version of 'trackclick.php' and 'trackpageview.php'. So, it's your biz to determine if you would like to download it. :)
     
    sztojka, Aug 31, 2006 IP
  4. sztojka

    sztojka Guest

    Messages:
    5
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    I have a little bit more time than yesterday, so here is what i am talking about:

    Tracking cliks: trackclick.php
    check line: 7. and 19-39.​
    Oh my god, I can fake all the get variables and my user_agent! I can insert any type of html/js code!

    And what about the log? Check the clickinfo.php file for example:
    check line: 100-123.​
    Oh shit, that's the sucks:) That's what Im talking about!

    So I've fixed this shit bug in trackpageview.php and trackclick.php, and you can download these files from my forum.
    If you download it, you will recognise this is a very simple and short patch, and I don't want to fuck with you or with the community. Pony's post made me a little bit angry yesterday, that's why I write this long post:) (sorry guys for my bad english :( )

    I'm curious about your opinion!
    And Pony: fuck you, you should apology! :) It's my forum, not some crap site. Pls, somebody check it and tell the truth that it's ok.
     
    sztojka, Sep 1, 2006 IP
  5. Ponynugget

    Ponynugget Peon

    Messages:
    1,183
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Lovely use of language there. Well done. :)
     
    Ponynugget, Sep 2, 2006 IP
  6. sztojka

    sztojka Guest

    Messages:
    5
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Newest version of AdLogger is released, XSS bugs have been fixed! Download it guys.
     
    sztojka, Sep 3, 2006 IP
  7. TooHappy

    TooHappy Guest

    Messages:
    504
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    0
    #7
    You are quite a salesperson as is evident in the way you promote your product!
     
    TooHappy, Sep 3, 2006 IP
  8. sztojka

    sztojka Guest

    Messages:
    5
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    TooHappy: you're wrong :) Im not a salesperson, and AdLogger isn't my product. I just found a bug in it...
     
    sztojka, Sep 3, 2006 IP