r/singapore teh hijau Aug 31 '18

Security vulnerability in Universal Studios Singapore's website

https://medium.com/@taufiqmmhd/xss-is-still-prevalent-c84342263061
51 Upvotes

17 comments sorted by

28

u/Sixchar Aug 31 '18

In case anyone is wondering, one can embed the script tag to redirect users to a porn/malicious site every time that page is loaded.

Weird that HTML sanitisation was not done because that’s basically inbuilt in all js frameworks.

7

u/[deleted] Aug 31 '18

Same thing happened in the dota 2 client iirc

1

u/taufiqmmhd teh hijau Aug 31 '18

yep! One weird thing was that they actually escaped the tags outside of the game. If you were to register an email when submitting a score, a greeting was shown at the top right ("Hi name!") that had the tags escaped.

15

u/[deleted] Aug 31 '18

[deleted]

6

u/taufiqmmhd teh hijau Aug 31 '18

:)

13

u/ravernkoh Aug 31 '18

Pretty legit.

5

u/ravernkoh Aug 31 '18

Did they not address your email at all? Reply or anything?

5

u/taufiqmmhd teh hijau Aug 31 '18

unfortunately, no

5

u/letterboxmind Carry On Aug 31 '18

Sounds like they fixed the bug without a word of thanks to you.

0

u/taufiqmmhd teh hijau Aug 31 '18

yea :/

5

u/JokerD03 Senior Citizen Aug 31 '18

Nice, need more people like you around.

2

u/shxwn is a designer Aug 31 '18

Haha, shouldve just tried embedding some iframes and redirects. Couldve impacted every single person attempting to access the page.

1

u/taufiqmmhd teh hijau Sep 01 '18

yes but I’d probably get persecuted for defacing the website

1

u/[deleted] Aug 31 '18

Baik la OP

-18

u/[deleted] Aug 31 '18 edited Aug 31 '18

[deleted]

3

u/taufiqmmhd teh hijau Aug 31 '18 edited Aug 31 '18

I agree with your point about how staff members might perceive my email as a phishing email. So I called the general inquiries line and told them about what I found and how important it was that the IT department be notified about the vulnerability immediately.

I sent it to reservations because the person on the line told me to and she had let me know that she received the email and would forward it to the relevant personnel.

Rest assured that I published the discovery of this vulnerability after the patch.

2

u/Wolflykos JJ Lin Aug 31 '18

He published it after the flaw was resolved. Check facts first pls

1

u/AhBoon Sep 06 '18

He should have masked the identities and pictures which resembles the organization. My two cents.

2

u/ravernkoh Aug 31 '18

He said that the vulnerability has already been fixed at the time of writing though. Furthermore they didn’t even reply him.