{"id":32,"date":"2014-04-25T08:42:16","date_gmt":"2014-04-25T03:42:16","guid":{"rendered":"http:\/\/www.chmosama.com\/blog\/?p=32"},"modified":"2017-12-24T15:16:46","modified_gmt":"2017-12-24T10:16:46","slug":"dom-cross-site-scripting-xss-found-in-lookout","status":"publish","type":"post","link":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/","title":{"rendered":"DOM-Cross Site Scripting (XSS) Found in Lookout"},"content":{"rendered":"<p style=\"text-align: justify;\">Ch. Muhammad Osama, an independent vulnerability researcher has discovered a DOM Cross-Site Scripting (XSS) vulnerability in Lookout\u00a0website www.lookout.com, which can be exploited by an attacker to conduct XSS attacks.<\/p>\n<p style=\"text-align: justify;\"><strong>DOM Cross-Site Scripting\u00a0:-<\/strong><\/p>\n<p style=\"text-align: justify;\">DOM Based XSS (or as it is called in some texts, \u201ctype-0 XSS\u201d) is an XSS attack wherein the attack payload is executed as a result of modifying the DOM \u201cenvironment\u201d in the victim\u2019s browser used by the original client side script, so that the client side code runs in an \u201cunexpected\u201d manner. That is, the page itself (the HTTP response that is) does not change, but the client side code contained in the page executes differently due to the malicious modifications that have occurred in the DOM environment.<\/p>\n<p style=\"text-align: justify;\">This is in contrast to other XSS attacks (stored or reflected), wherein the attack payload is placed in the response page (due to a server side flaw).<\/p>\n<p style=\"text-align: justify;\"><strong>Proof of Concept :-<\/strong><\/p>\n<p style=\"text-align: justify;\">URL :-\u00a0<a href=\"https:\/\/www.lookout.com\/&lt;svg\/onload=prompt(1)&gt;\" target=\"_blank\" rel=\"noopener\">POC Link Here<\/a><\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-35\" src=\"http:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-aurora-1024x528.png\" alt=\"lookout-poc-aurora\" width=\"525\" height=\"271\" srcset=\"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-aurora-1024x528.png 1024w, https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-aurora-300x155.png 300w, https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-aurora-768x396.png 768w, https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-aurora.png 1366w\" sizes=\"auto, (max-width: 525px) 100vw, 525px\" \/><\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-34\" src=\"http:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera-1024x547.png\" alt=\"lookout-poc-opera\" width=\"525\" height=\"280\" srcset=\"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera-1024x547.png 1024w, https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera-300x160.png 300w, https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera-768x410.png 768w, https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera.png 1366w\" sizes=\"auto, (max-width: 525px) 100vw, 525px\" \/><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-34\" src=\"http:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera-1024x547.png\" alt=\"lookout-poc-opera\" width=\"525\" height=\"280\" srcset=\"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera-1024x547.png 1024w, https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera-300x160.png 300w, https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera-768x410.png 768w, https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/lookout-poc-opera.png 1366w\" sizes=\"auto, (max-width: 525px) 100vw, 525px\" \/><\/p>\n<p style=\"text-align: justify;\">Video Explanation :-<\/p>\n<p style=\"text-align: center;\"><iframe loading=\"lazy\" width=\"800\" height=\"460\" src=\"https:\/\/www.youtube.com\/embed\/EO8SW2Anp70\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p style=\"text-align: justify;\"><strong>Conclusion :-<\/strong><\/p>\n<p style=\"text-align: justify;\">This vulnerability has been confirmed and patched by Lookout\u00a0Security Team. I would like to thank them for their quick response to my report.<\/p>\n<p style=\"text-align: center;\"><strong>Status : Fixed!<\/strong><br \/>\n<strong>Hall of Fame : Yes!<\/strong><br \/>\n<strong>Bounty: No!<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ch. Muhammad Osama, an independent vulnerability researcher has discovered a DOM Cross-Site Scripting (XSS) vulnerability in Lookout\u00a0website www.lookout.com, which can be exploited by an attacker to conduct XSS attacks. DOM Cross-Site Scripting\u00a0:- DOM Based XSS (or as it is called in some texts, \u201ctype-0 XSS\u201d) is an XSS attack wherein [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":33,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[16,15,6,8],"class_list":["post-32","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-poc","tag-dom-xss","tag-lookout","tag-poc","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DOM-Cross Site Scripting (XSS) Found in Lookout - Blog - Choudhary Muhammad Osama<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DOM-Cross Site Scripting (XSS) Found in Lookout - Blog - Choudhary Muhammad Osama\" \/>\n<meta property=\"og:description\" content=\"Ch. Muhammad Osama, an independent vulnerability researcher has discovered a DOM Cross-Site Scripting (XSS) vulnerability in Lookout\u00a0website www.lookout.com, which can be exploited by an attacker to conduct XSS attacks. DOM Cross-Site Scripting\u00a0:- DOM Based XSS (or as it is called in some texts, \u201ctype-0 XSS\u201d) is an XSS attack wherein [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Choudhary Muhammad Osama\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/chmosama\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/chmosama\" \/>\n<meta property=\"article:published_time\" content=\"2014-04-25T03:42:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-12-24T10:16:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/Lookout.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"3633\" \/>\n\t<meta property=\"og:image:height\" content=\"2179\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Choudhary Muhammad Osama\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ChMuhammadOsama\" \/>\n<meta name=\"twitter:site\" content=\"@ChMuhammad\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Choudhary Muhammad Osama\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/\",\"url\":\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/\",\"name\":\"DOM-Cross Site Scripting (XSS) Found in Lookout - Blog - Choudhary Muhammad Osama\",\"isPartOf\":{\"@id\":\"https:\/\/www.chmosama.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/Lookout.jpg\",\"datePublished\":\"2014-04-25T03:42:16+00:00\",\"dateModified\":\"2017-12-24T10:16:46+00:00\",\"author\":{\"@id\":\"https:\/\/www.chmosama.com\/blog\/#\/schema\/person\/1e5073e7a2fb381ec0503b87b16ba4c7\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#primaryimage\",\"url\":\"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/Lookout.jpg\",\"contentUrl\":\"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/Lookout.jpg\",\"width\":3633,\"height\":2179,\"caption\":\"Lookout\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.chmosama.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DOM-Cross Site Scripting (XSS) Found in Lookout\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.chmosama.com\/blog\/#website\",\"url\":\"https:\/\/www.chmosama.com\/blog\/\",\"name\":\"Blog - Choudhary Muhammad Osama\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.chmosama.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.chmosama.com\/blog\/#\/schema\/person\/1e5073e7a2fb381ec0503b87b16ba4c7\",\"name\":\"Choudhary Muhammad Osama\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.chmosama.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3d3ebe72135073f739b9d6cc1c93ea0a0f40e9393eb5305a78f0d70435ad2f6c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3d3ebe72135073f739b9d6cc1c93ea0a0f40e9393eb5305a78f0d70435ad2f6c?s=96&d=mm&r=g\",\"caption\":\"Choudhary Muhammad Osama\"},\"description\":\"This is Choudhary Muhammad Osama, a highly accomplished Penetration Tester, Security Analyst and Linux Administration enthusiast, with extensive experience in implementing, maintaining, securing and pentesting web applications and networks.\",\"sameAs\":[\"https:\/\/www.chmosama.com\",\"https:\/\/www.facebook.com\/chmosama\",\"https:\/\/x.com\/ChMuhammadOsama\"],\"url\":\"http:\/\/www.chmosama.com\/blog\/author\/chmosama\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DOM-Cross Site Scripting (XSS) Found in Lookout - Blog - Choudhary Muhammad Osama","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/","og_locale":"en_US","og_type":"article","og_title":"DOM-Cross Site Scripting (XSS) Found in Lookout - Blog - Choudhary Muhammad Osama","og_description":"Ch. Muhammad Osama, an independent vulnerability researcher has discovered a DOM Cross-Site Scripting (XSS) vulnerability in Lookout\u00a0website www.lookout.com, which can be exploited by an attacker to conduct XSS attacks. DOM Cross-Site Scripting\u00a0:- DOM Based XSS (or as it is called in some texts, \u201ctype-0 XSS\u201d) is an XSS attack wherein [&hellip;]","og_url":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/","og_site_name":"Blog - Choudhary Muhammad Osama","article_publisher":"https:\/\/www.facebook.com\/chmosama","article_author":"https:\/\/www.facebook.com\/chmosama","article_published_time":"2014-04-25T03:42:16+00:00","article_modified_time":"2017-12-24T10:16:46+00:00","og_image":[{"width":3633,"height":2179,"url":"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/Lookout.jpg","type":"image\/jpeg"}],"author":"Choudhary Muhammad Osama","twitter_card":"summary_large_image","twitter_creator":"@ChMuhammadOsama","twitter_site":"@ChMuhammad","twitter_misc":{"Written by":"Choudhary Muhammad Osama","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/","url":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/","name":"DOM-Cross Site Scripting (XSS) Found in Lookout - Blog - Choudhary Muhammad Osama","isPartOf":{"@id":"https:\/\/www.chmosama.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#primaryimage"},"image":{"@id":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#primaryimage"},"thumbnailUrl":"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/Lookout.jpg","datePublished":"2014-04-25T03:42:16+00:00","dateModified":"2017-12-24T10:16:46+00:00","author":{"@id":"https:\/\/www.chmosama.com\/blog\/#\/schema\/person\/1e5073e7a2fb381ec0503b87b16ba4c7"},"breadcrumb":{"@id":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#primaryimage","url":"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/Lookout.jpg","contentUrl":"https:\/\/www.chmosama.com\/blog\/wp-content\/uploads\/2017\/08\/Lookout.jpg","width":3633,"height":2179,"caption":"Lookout"},{"@type":"BreadcrumbList","@id":"https:\/\/www.chmosama.com\/blog\/dom-cross-site-scripting-xss-found-in-lookout\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.chmosama.com\/blog\/"},{"@type":"ListItem","position":2,"name":"DOM-Cross Site Scripting (XSS) Found in Lookout"}]},{"@type":"WebSite","@id":"https:\/\/www.chmosama.com\/blog\/#website","url":"https:\/\/www.chmosama.com\/blog\/","name":"Blog - Choudhary Muhammad Osama","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.chmosama.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.chmosama.com\/blog\/#\/schema\/person\/1e5073e7a2fb381ec0503b87b16ba4c7","name":"Choudhary Muhammad Osama","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.chmosama.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3d3ebe72135073f739b9d6cc1c93ea0a0f40e9393eb5305a78f0d70435ad2f6c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3d3ebe72135073f739b9d6cc1c93ea0a0f40e9393eb5305a78f0d70435ad2f6c?s=96&d=mm&r=g","caption":"Choudhary Muhammad Osama"},"description":"This is Choudhary Muhammad Osama, a highly accomplished Penetration Tester, Security Analyst and Linux Administration enthusiast, with extensive experience in implementing, maintaining, securing and pentesting web applications and networks.","sameAs":["https:\/\/www.chmosama.com","https:\/\/www.facebook.com\/chmosama","https:\/\/x.com\/ChMuhammadOsama"],"url":"http:\/\/www.chmosama.com\/blog\/author\/chmosama\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/posts\/32","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/comments?post=32"}],"version-history":[{"count":2,"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/posts\/32\/revisions"}],"predecessor-version":[{"id":201,"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/posts\/32\/revisions\/201"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/media\/33"}],"wp:attachment":[{"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/media?parent=32"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/categories?post=32"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.chmosama.com\/blog\/wp-json\/wp\/v2\/tags?post=32"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}