<div class="separator"><a href="https://thehackernews.com/images/-wH0JC4QEgkM/YQzq1nF9FUI/AAAAAAAADdg/mV080ef-hqUEdFPLcHhykJNsDUfDpKakACLcBGAsYHQ/s0/koo-app.jpg"></a></div> <p>Koo, India’s homegrown Twitter clone, recently patched a serious security vulnerability that could have been exploited to execute arbitrary JavaScript code against hundreds of thousands of its users, spreading the attack across the platform.</p> <p>The vulnerability involves a <a href="https://www.imperva.com/learn/application-security/cross-site-scripting-xss-attacks/" rel="noopener" target="_blank">stored cross-site scripting flaw</a> (also known as persistent XSS) in Koo’s web application that allows malicious scripts to be embedded directly into the affected web application.</p> <p>To carry out the attack, all a malicious actor had to do was log into the service via the web application and post an XSS-encoded payload to its timeline, which automatically gets executed on behalf of all users who saw the post.</p> <div class="ad_two clear"><center class="cf"><a href="https://go.thn.li/1-free-300-7" rel="nofollow noopener sponsored" target="_blank" title="Stack Overflow Teams"><img alt="Stack Overflow Teams" class="lazyload" src="https://thehackernews.com/images/-9r3EBoAeEj4/YMt1nGWkOMI/AAAAAAAA4Qk/feJCltGJrFcMPYuba5Ihr7WgYxNB6oG-gCLcBGAsYHQ/s300-e100/free-ad-7-300.png"></a></center></div> <p>The issue was discovered by security researcher <a href="https://servicenger.com/blog/mobile/koo-app-stored-xss-vulnerability-cloudflare-bypass" rel="noopener" target="_blank">Rahul Kankrale</a> in July, following which a fix was rolled out by Koo on July 3.</p> <p>Using cross-site scripting, an attacker can perform actions on behalf of users with the same privileges as the user and steal web browser’s secrets, such as authentication cookies.</p> <p>Due to the fact that malicious JavaScript has access to all objects that the website can access, it could allow adversaries to sneak into sensitive data such as private messages, or spread misinformation, or display spam using users’ profiles.</p> <p><iframe loading="lazy" width="560" height="315" src="https://www.youtube.com/embed/Pvnj9kLyBSk" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="">[embedded content]</iframe></p> <p>The end result of this vulnerability in Koo, also known as XSS worm, is more worrisome because it automatically propagates malicious code among a website’s visitors to infect other users—without any user interaction, like a chain reaction.</p> <p>Koo, which launched in November 2019, bills itself as an Indian alternative to Twitter and boasts of 6 million active users on its platform. The Bengaluru-based company has also emerged as the social media service of choice in Nigeria after the country indefinitely banned Twitter for deleting a tweet by Nigerian President Muhammadu Buhari.</p> <div class="ad_two clear"><center class="cf"><a href="https://go.thn.li/privileged_728" rel="nofollow noopener sponsored" target="_blank" title="Prevent Data Breaches"><img alt="Prevent Data Breaches" class="lazyload" src="https://thehackernews.com/images/-hkQDbi8WuFc/YLy9N5FVDyI/AAAAAAAA4BQ/EWc29W968mAbwiuVzSw1vYyepjgzwGHawCLcBGAsYHQ/s728-e100/privileged_728.jpg"></a></center></div> <p>Aprameya Radhakrishna, co-founder, and chief executive officer of Koo, announced the entry of the app into the Nigerian market earlier this week.</p> <p>Also patched was a <a href="https://www.imperva.com/learn/application-security/reflected-xss-attacks/" rel="noopener" target="_blank">reflected XSS</a> vulnerability associated with the hashtag feature, thus allowing an adversary to pass malicious JavaScript code in the endpoint used for searching for a specific hashtag (“https://www[.]kooapp[.]com/tag/).</p> <p>The disclosure comes a little over a month after similar <a href="https://thehackernews.com/2021/06/microsoft-edge-bug-couldve-let-hackers.html" rel="noopener" target="_blank">XSS-related vulnerabilities</a> were uncovered in Microsoft’s Edge browser, which can be exploited to trigger an attack simply by adding a comment to a YouTube video or sending a Facebook friend request from an account that contains non-English language content accompanied by an XSS payload.</p> <p></p> <p>The post <a rel="nofollow" href="https://patabook.com/technology/2021/08/07/indias-koo-a-twitter-like-service-found-vulnerable-to-critical-worm-attacks/">India’s Koo, a Twitter-like Service, Found Vulnerable to Critical Worm Attacks</a> appeared first on <a rel="nofollow" href="https://patabook.com/technology">Patabook Technology</a>.</p>
source https://patabook.com/blogs/105340/India-s-Koo-a-Twitter-like-Service-Found-Vulnerable-to
Subscribe to:
Post Comments (Atom)
Antifa Groups Charged with Violently Countering California ‘Patriot March’
Prosecutors have charged approximately seven individuals, described as self-identified anti-fascists, regarding eight alleged assaults in Ja...
-
Prosecutors have charged approximately seven individuals, described as self-identified anti-fascists, regarding eight alleged assaults in Ja...
-
source https://www.todayonline.com/world/portugal-urged-seek-international-help-covid-19-deaths-hit-record
-
source https://www.todayonline.com/world/five-injured-hundreds-evacuated-after-massive-blaze-indonesia-oil-refinery
No comments:
Post a Comment