• XSS.stack #1 – первый литературный журнал от юзеров форума

apple.com Reflected XSS

В этой теме можно использовать автоматический гарант!

vincent

floppy-диск
Пользователь
Регистрация
23.05.2020
Сообщения
6
Реакции
2
i'm selling Reflected XSS on *.apple.com subdomain

Benefits:
*the XSS in very important subdomain
*Gaining trust of any user simply because it's real apple.com domain!
*XSS working on Chrome/Mozilla/Opera/Edge latest version
if you're a spammer you can use it TO:
use real apple.com domain name to redirect to your scam
key-logging user email/password or personal information
many scenarios etc...
OR if you hijacked a iPhone and you want to remove/hack the iCloud from it you can simply gain trust of original phone user to enter his/her password because it's APPLE.COM HTTPS real domain name

Price : 10K/or make an offer
 
i'm selling Reflected XSS on *.apple.com subdomain

Benefits:
*the XSS in very important subdomain
*Gaining trust of any user simply because it's real apple.com domain!
*XSS working on Chrome/Mozilla/Opera/Edge latest version
if you're a spammer you can use it TO:
use real apple.com domain name to redirect to your scam
key-logging user email/password or personal information
many scenarios etc...
OR if you hijacked a iPhone and you want to remove/hack the iCloud from it you can simply gain trust of original phone user to enter his/her password because it's APPLE.COM HTTPS real domain name

Price : 10K/or make an offer
доказать?
 
self-xss?
No it's not Self-XSS
This vulnerability affect any user/visitor on any browser, doesn't require any user-interaction just a One-Click from user to exploit it, and that's obvious and anyone will trust apple.com domain because it's official Apple domain name.
 


Напишите ответ...
Верх