You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{%pdf https://hackmd.io/@Whale120/iframe_dos_demo%}
{%pdf https://william957-web.github.io/meow_dos.html%}# whale
The whale is the biggest creature under the sea.
Meowing whale, is that correct?
After a short period of time, users will be unable to add new articles (429 error).
The text was updated successfully, but these errors were encountered:
HackMD can iframe a pdf file through its url like this:
{%pdf https://example.com/meow.pdf%}
However, it doesn't filter the url well and it would lead to a XSS (though couldn't still cookie...)
POC: https://hackmd.io/@Whale120/DEMO_XSS
What's more?
Attack can construct a simple site like this:
And iframe the attacker's site:
PoC: https://hackmd.io/@Whale120/iframe_dos_demo
After a short period of time, users will be unable to add new articles (429 error).
The text was updated successfully, but these errors were encountered: