..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

..:: AHSAN HACKING STUFF ::..

This is the personal blog of Ahsan Tahir (Cyber Security Researcher) You can see his PoCs and other hacking tips/tricks here!

Wednesday, 11 May 2016

Clikjacking in HootSuite, found by Ahsan Tahir





Hey, I found a clickjacking vulnerability in HootSuite.
Risk: Low
Steps to reproduce:
1. Make a new html file, code:

<html>
   <head>
     <title>Clickjack test page</title>
   </head>
   <body>
     <iframe src="https://site.com" width="500" height="500"></iframe>
   </body>
</html>

Instead of site.com, we have to enter the site, which we want to test!
They did not patched the bug, as they think that they don't have time to patch low impact bugs!

But, I was listed in their Hall of Fame!
Link: https://hootsuite.com/security/