Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 Imgur: De-anonymization Attack: Cross Site Information Leakage

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Imgur: De-anonymization Attack: Cross Site Information Leakage


💡 Newskategorie: Sicherheitslücken
🔗 Quelle: vulners.com


image
Dear Imgur Security Team, We are researchers at the IMDEA Software Institute in Madrid, Spain. We have been working on analyzing Cross-Site Browser Leaks (xsleaks) and building a tool for finding instances of it on target web sites. Recently we tested imgur.com and discovered a flaw that can affect Imgur users. We would like to responsibly disclose it and support you to mitigate the issue. The details follow. Attack Overview: Events-Fired xsLeak: a cross-domain attack website, say attacker.org, could embed specific resources from imgur.com in a script Tag, and check if an error or load event is triggered in one state but not in the other. Based on which events are triggered for each vulnerable resource, the attacker can infer the victim state (e.g. logged in vs logged out, or owner of a specific profile). This happens because the leaky endpoint return a 2xx HTTP response in one state but a 4xx in the other. In particular, we have found 2 vulnerable (leaky) endpoints: The first one can be used for login detection (onerror =  logged out, onload = logged in):https://api.imgur.com/3/larynx/history?IMGURPLATFORM=web&IMGURUIDJAFO=9d77969d8b3a7a6ac6cb78943c96e48cd0bd74e02b29839f9f19aea827429db6&SESSIONCOUNT=3&client_id=546c25a59c58ad7 2.  The second one can be used to track and deanonymize the owner of a Imgur profile across origins. For this, the attacker leverages the resource: https://.imgur.com/all  where is the username of  the victim to be fingerprinted... ...



📌 Imgur: Stored XSS on imgur profile


📈 41 Punkte

📌 EvilNet - Network Attack Wifi Attack Vlan Attack Arp Attack Mac Attack Attack Revealed Etc...


📈 32.16 Punkte

📌 ZombieLoad: Cross Privilege-Boundary Data Leakage - a new side-channel attack affecting Intel CPUs


📈 25.68 Punkte

📌 The vulnerability is one of many with the same root cause: cross-process information leakage.


📈 24.07 Punkte

📌 Imgur—Popular Image Sharing Site Was Hacked In 2014; Passwords Compromised


📈 23.34 Punkte

📌 Attack of the week: searchable encryption and the ever-expanding leakage function


📈 22.76 Punkte

📌 Attack of the week: searchable encryption and the ever-expanding leakage function


📈 22.76 Punkte

📌 Intel CPUs Vulnerable to Sensitive Data Leakage in NetCAT Attack


📈 22.76 Punkte

📌 New Type of Side-Channel Attack Impacts Intel CPUs and Allows Data Leakage


📈 22.76 Punkte

📌 Apple news: iLeakage attack, MAC address leakage bug


📈 22.76 Punkte

📌 Microsoft Edge Array.join Information Leakage


📈 21.15 Punkte

📌 Bugtraq: [CVE-2016-8741] Apache Qpid Broker for Java - Information Leakage


📈 21.15 Punkte

📌 Microsoft Edge Array.join Information Leakage


📈 21.15 Punkte

📌 Bugtraq: [CVE-2016-8741] Apache Qpid Broker for Java - Information Leakage


📈 21.15 Punkte

📌 Axis Communications MPQT/PACS Heap Overflow / Information Leakage


📈 21.15 Punkte

📌 Axis Communications MPQT/PACS Heap Overflow / Information Leakage


📈 21.15 Punkte

📌 #0daytoday #Axis Communications MPQT/PACS Heap Overflow / Information Leakage Vulnerabilities [#0day #Exploit]


📈 21.15 Punkte

📌 [remote] Axis Communications MPQT/PACS - Heap Overflow / Information Leakage


📈 21.15 Punkte

📌 Christmas Calendar: Error messages and information leakage


📈 21.15 Punkte

📌 Cisco Small Business Switch Information Leakage / Open Redirect


📈 21.15 Punkte

📌 Cisco Small Business Switch Information Leakage / Open Redirect


📈 21.15 Punkte

📌 How Can Information Leakage Happen in Organisation?


📈 21.15 Punkte

📌 Sifchain: Open S3 Bucket | information leakage


📈 21.15 Punkte

📌 U.S. Dept Of Defense: IDOR leads to Leakage an ██████████ Login Information


📈 21.15 Punkte

📌 Cry Ransomware Uses UDP, Imgur, Google Maps


📈 20.5 Punkte

📌 'How I Hacked Imgur for Fun and Profit'


📈 20.5 Punkte

📌 Cry Ransomware Uses UDP, Imgur, Google Maps


📈 20.5 Punkte

📌 Netz-Phänomen bei Imgur: Gruppenfoto wird wegen eines Details tausendfach ...


📈 20.5 Punkte

📌 Imgur confirms email addresses, passwords stolen in 2014 hack


📈 20.5 Punkte

📌 Datendiebstahl: Bilderdienst imgur gibt Hack von 2014 bekannt


📈 20.5 Punkte

📌 Bilder-Plattform Imgur: Millionen Zugänge in Hack von 2014 gestohlen


📈 20.5 Punkte

📌 How a Security Researcher Convinced Imgur's CEO to Increase Bug Bounty Rewards


📈 20.5 Punkte

📌 CryLocker Ransomware Uses Imgur, Pastee, and Google Maps


📈 20.5 Punkte











matomo