diff --git a/README.md b/README.md index 5d80108..0ff0c34 100644 --- a/README.md +++ b/README.md @@ -1,11 +1,11 @@ # JSONBee A ready to use JSONP endpoints to help bypass content security policy of different websites. -The tool was presented during HackIT 2018 in Keiv. The presentation can be found here (not sure why format of the slides is screwed :D): https://www.slideshare.net/Hacken_Ecosystem/ebrahem-hegazy-bug-hunters-manual-for-bypassing-contentsecuritypolicy +The tool was presented during HackIT 2018 in Kiev. The presentation can be found here (not sure why format of the slides is screwed :D): https://www.slideshare.net/Hacken_Ecosystem/ebrahem-hegazy-bug-hunters-manual-for-bypassing-contentsecuritypolicy # What is JSONBee? -The main idea behind this tool is to find the JSONP endpoint(s) that would help you bypass content security policy for your target website in an automated way. JSONBee takes an input of a url name (i.e. https://www.facebook.com), parses the CSP (Content-Security Policy), and automatically suggest the XSS payload that would bypass the CSP. It mainly focuses on JSONP endpoints gathered during my bug bounty hunting activities, and could be used to bypass the CSP. +The main idea behind this tool is to find the JSONP endpoint(s) that would help you bypass content security policy for your target website in an automated way. JSONBee takes an input of a url name (i.e. https://www.facebook.com), parses the CSP (Content-Security-Policy), and automatically suggest the XSS payload that would bypass the CSP. It mainly focuses on JSONP endpoints gathered during my bug bounty hunting activities, and could be used to bypass the CSP. JSONBee relies on 3 methods to gather the JSONP endpoints: * The repository within this project; diff --git a/jsonp.txt b/jsonp.txt index 58ec2fa..d96353d 100644 --- a/jsonp.txt +++ b/jsonp.txt @@ -1,18 +1,20 @@ #Google.com: -"> -"> -"> -"> +"> +"> +"> +"> +"> +"> #Blogger.com: -"> +"> #Yandex: -"> -"> +"> +"> #VK.com: -"> +"> #Marketo.com -"> -"> +"> +"> #AlibabaGroup: "> "> @@ -23,11 +25,18 @@ "> #Uber.com: "> +#Buzzfeed.com +"> +#Yahoo JP (Thanks to @nizam0906) +"> +"> #AOL/Yahoo "> "> "> "> +">x +"> "> "> "> @@ -41,14 +50,14 @@ "> "> "> -"> "> "> "> "> "> "> -#GoogleAPI's +#Google API's "> "> ng-app"ng-csp ng-click=$event.view.alert(1337)> +">