[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-disclosure] Fastweb MyFastpage Authentication Bypass



Fastweb, an Italian service provider, have a XSS flaw that permits to bypass
authentication and log into users account control panels.

The attacker must lure Fastweb users into a malicious web page to steal
authentication token with XSS. The control panels called MyFastPage permits
to change Fastweb account password, FastMail password, on line billing,
configure home lan portmapping, private datas, address and billing
informations, and buy additional services charging cost to the user.


Here the working POC [italian]: http://disse.cting.org/codes/fastweb.html
Here the blog article [italian]:
http://disse.cting.org/security-2/fastweb-myfastpage-panel-control-hack/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/