About Group (about.com) All Topics (At least 99.88% links) Vulnerable to XSS & Iframe Injection Security Attacks, About.com Open Redirect Web Security Vulnerabilities
Vulnerability Description:
About.com all âtopic sitesâ are vulnerable to XSS (Cross-Site Scripting) and Iframe Injection (Cross Frame Scripting) attacks. This means all sub-domains of about.com are affected. Based on a self-written program, 94357 links were tested. Only 118 links do not belong to the topics (Metasites) links. Meanwhile, some about.com main pages are vulnerable to XSS attack, too. This means no more than 0.125% links are not affected. At least 99.875% links of About Group are vulnerable to XSS and Iframe Injection attacks. In fact, for about.comâs structure, the main domain is something just like a cover. So, very few links belong to them.
Simultaneously, the About.com main pageâs search field is vulnerable to XSS attacks, too. This means all domains related to about.com are vulnerable to XSS attacks.
For the Iframe Injection vulnerability. They can be used to do DDOS (Distributed Denial-of-Service Attack) to other websites, too.
Here is one example of DDOS based on Iframe Injection attacks of others.
http://www.incapsula.com/blog/world-largest-site-xss-ddos-zombies.html
In the last, some âOpen Redirectâ vulnerabilities related to about.com are introduced. There may be large number of other Open Redirect Vulnerabilities not detected. Since About.com are trusted by some the other websites. Those vulnerabilities can be used to do âCovert Redirectâ to these websites.
Vulnerability Disclosure:
Those vulnerabilities were reported to About on Sunday, Oct 19, 2014. No one replied. Until now, they are still unpatched.
Vulnerability Discover:
Wang Jing, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. (@Justqdjing)
http://www.tetraph.com/wangjing
(1) Some Basic Background
(1.1) Domain Description:
http://www.about.com/
http://www.alexa.com/siteinfo/about.com
âFor March 2014, 61,428,000 unique visitors were registered by comScore for About.com, making it the 16th-most-visited online property for that month.â (The New York Times)
âAbout.com, also known as The About Group (formerly About Inc.), is an Internet-based network of content that publishes articles and videos about various subjects on its âtopic sites,â of which there are nearly 1,000. The website competes with other online resource sites and encyclopedias, including those of the Wikimedia Foundation, and, for March 2014, 61,428,000 unique visitors were registered by comScore for About.com, making it the 16th-most-visited online property for that month. As of August 2012, About.com is the property of IAC, owner of Ask.com and numerous other online brands, and its revenue is generated by advertising.â (Wikipedia)
"As of May 2013, About.com was receiving about 84 million unique monthly visitors.â (TechCrunch. AOL Inc.)
âAccording to Aboutâs online media kit, nearly 1,000 "Expertsâ (freelance writers) contribute to the site by writing on various topics, including healthcare and travel.â (About.com)
(1.2) Topics Related to About.com
"The Revolutionary About.com Directory and Community Metasite. Hundreds of real live passionate Guides covering Arts, Entertainment, Business, Industry, Science, Technology, Culture, Health, Fitness, Games,Travel, News, Careers, Jobs, Sports, Recreation, Parenting, Kids, Teens, Moms, Education, Computers, Hobbies and Local Information.â (azlist.about.com)
Reference: azlist.about.com/
In fact, those are not all topics of about.com. Some of the topics are not listed here such as,
http://specialchildren.about.com
So, there are more than 1000 topics related to about.com.
(1.3) Result of Exploiting XSS Attacks
XSS may allow a remote attacker to create a specially crafted request that would execute arbitrary script code in a userâs browser session within the trust relationship between their browser and the server.
Base on Acunetix, exploited XSS is commonly used to achieve the following malicious results:
 Accessing sensitive or restricted information
 Gaining free access to otherwise paid for content
 Spying on userâs web browsing habits
 Altering browser functionality
 Public defamation of an individual or corporation
 Web application defacement
 Denial of Service attacks (DOS)
More:
http://seclists.org/fulldisclosure/2015/Feb/9
Related Articles:
http://permalink.gmane.org/gmane.comp.security.fulldisclosure/1547
http://marc.info/?l=full-disclosure&m=142289980219878&w=4
https://packetstormsecurity.com/files/130211/About.com-Cross-Site-Scripting.html
http://computerobsess.blogspot.com/2015/06/about-group-aboutcom-all-topics-at.html
https://www.facebook.com/computersecurities/posts/384674738385985
http://www.weibo.com/1644370627/Clk7CaKvL?from=page_1005051644370627
http://guyuzui.lofter.com/post/1ccdcda4_6f03224
https://twitter.com/yangziyou/status/607145647037284352
http://webtechhut.blogspot.com/2015/06/about-group-aboutcom-all-topics-at.html
https://computertechhut.wordpress.com/2015/02/02/about-group-about-com-https://www.facebook.com/permalink.php?story_fbid=1043670099006327
http://inzeed.tumblr.com/post/118845379331/securitypost-about-group-99-88-xss
https://dailymem.wordpress.com/2015/02/11/about-group
http://mathdaily.lofter.com/post/1cc75b20_7340000
http://xingti.tumblr.com/post/120847740060/itinfotech-about-group-xss-xfs
http://diebiyi.com/articles/security/xss-vulnerability/about-group-xss-xrf-open-redirect/
http://www.tetraph.com/blog/xss-vulnerability/about-group-xss-xrf-open-redirect/