Stored XSS in Yahoo!

in #bugbounty6 years ago

Sharing is Caring :)
When we share, we open doors to a new beginning...../

Well, This is Shahzada Al Shahriar Khan. And I am from Bangladesh.
Now I am going to share how I found Stored Cross-Site Scripting (XSS) in Yahoo.

Steps to Reproduce:

Go to https://www.yahoo.com/news

Screen Shot 2018-04-27 at 11.17.54 AM.png

Comment this payload: "><img src=x onerror=confirm(1);>

Screen Shot 2018-04-27 at 11.18.57 AM.png

Now what? Voila! We get the famous confirm(1) to popup! :D

Screen 1.png

I am trying another payload that I can write something in popup box, and found this payload: <img src=x onerror=prompt(1337)>
That moment I feel like a boss!

Ironman.jpg

Screenshot 2.png

Here is the video PoC:

Timeline:

31/03/2018 - Initial Report.
01/04/2018 - HackerOne staff asked for 'Needs more info.'
01/04/2018 - More Info Submitted.
04/04/2018 - Triaged and a $300 initial bounty rewarded.
06/04/2018 - Bug Resolved.
11/04/2018 - $1700 bounty rewarded.

Thanks for reading..../

./TheShahada

Sort:  

@theshahzada, let me be the first to welcome you to Steemit! Congratulations on making your first post!

I gave you a $.05 vote!

Would you be so kind as to follow me back in return?

You should post this on reddit.com/r/xss

. Nice find.

Good suggestion, I will post this on reddit soon.

Thank you :)

I used to try my luck at bugbounties but it is a race against time and very competitive. Not sure if you familiar with xssposed which is now https://www.openbugbounty.org , definately worth checking out.

Congratulations @theshahzada! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 1 year!

You can view your badges on your Steem Board and compare to others on the Steem Ranking

Do not miss the last post from @steemitboard:

Are you a DrugWars early adopter? Benvenuto in famiglia!
Vote for @Steemitboard as a witness to get one more award and increased upvotes!

Congratulations @theshahzada! You received a personal award!

Happy Steem Birthday! - You are on the Steem blockchain for 2 years!

You can view your badges on your Steem Board and compare to others on the Steem Ranking

Do not miss the last post from @steemitboard:

Downvote challenge - Add up to 3 funny badges to your board
Vote for @Steemitboard as a witness to get one more award and increased upvotes!

Coin Marketplace

STEEM 0.17
TRX 0.12
JST 0.027
BTC 61414.81
ETH 2984.62
USDT 1.00
SBD 2.46