Content Spoofing On *.line.me
What Is Content Spoofing ?
Content spoofing, also referred to as content injection or virtual defacement, is an attack targeting a user made possible by an injection vulnerability in a web application. When an application does not properly handle user supplied data, an attacker can supply content to a web application, typically via a parameter value, that is reflected back to the user. This presents the user with a modified page under the context of the trusted domain.This attack is typically used as, or in conjunction with, social engineering because the attack is exploiting a code-based vulnerability and a user's trust.
PoC
Reference
- https://www.owasp.org/index.php/Content_Spoofing
- https://hackerone.com/reports/181594
- https://hackerone.com/reports/154921
Respond Line :
- Has been patched the bug, but decide to reject because not include in their TOS
Last Word
I know this is low risk, so will be difficult when you report it to big website (e.g: google ) , and also i have found another content spoofing on line , but i decide to not report it XD , because waste my time.
Comments
Post a Comment