Skip to content

Commit c9b87c1

Browse files
authored
Update README.md
1 parent 58dd782 commit c9b87c1

1 file changed

Lines changed: 8 additions & 7 deletions

File tree

README.md

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,29 +1,30 @@
1-
<b>Paywall Issue</b>
1+
<b>Paywall Issue</b></br>
22

33
www.aachener-zeitung.de</br>
44
www.aachener-nachrichten.de</br>
55

6-
<b>0. information</b>
6+
<b>0. information</b></br>
77

88
The websites are offering a mixture of free and payed articles hidden by paywall. (http://www.aachener-zeitung.de/zva/pc/)
99
The websites use AESUtils and CryptoJS to hide articles.
1010

11-
The provider leaks sensitive data like password, IV and salt which are used for encryption and can be used to decrypt the articles.
11+
The provider leaks <b>sensitive data like password, IV and salt which are used for encryption</b> and can be used to decrypt the articles.
12+
<b>This issue does not leak any personal data of (registered) users.</b>
1213

1314
free article: http://www.aachener-zeitung.de/lokales/juelich/zukunft-von-haus-overbach-ist-langfristig-gesichert-1.1610013
1415
hidden article: http://www.aachener-zeitung.de/lokales/juelich/feierabendmarkt-in-juelich-mit-bilderbuchstart-1.1622101
1516

16-
<b>1. timeline</b>
17+
<b>1. timeline</b></br>
1718

1819
<ul>
1920
<li>04.05.2017 20:53: informed "AZ - Lokales" via facebook pages about the possibility to read all hidden content (https://www.facebook.com/azlokalesaachen/)</li>
2021
<li>04.05.2017 21:04: response with information that the issue will be forwarded</li>
2122
</ul>
2223

23-
<b>2. PoC</b>
24-
---
24+
<b>2. PoC</b></br>
25+
Code will be released after fix or responsible disclosure
2526

2627

27-
<b>3. responsible disclosure</b>
28+
<b>3. responsible disclosure</b></br>
2829
disclosure until 04.08.2017
2930
</ul>

0 commit comments

Comments
 (0)