F-2024-0002·content-spoofing
Content spoofing via parameters url, w, and q (unauthenticated and wallet-connected)
TL;DR
The url, w, and q parameters on /_next/image were modifiable on the fly, allowing an attacker to substitute images and produce defacement-style content spoofing variants without script execution.
Severity
MEDIUM
Impact
MEDIUM
Likelihood
MEDIUM
Method
MManual review
CAT.
Complexity
LOW
Exploitability
MEDIUM
02Section · Description
Description
Browsing the dedprz.virtual.tech site emitted requests like:
GET /_next/image?url=%2Ftails-button-active.png&w=640&q=75 HTTP/2
Host: dedprz.virtual.tech
The url, w, and q parameters had predictable values that could be modified in-flight by an attacker controlling the user's network or by hooking into the page. Substituting url swapped the rendered image, allowing self-defacement style content spoofing while components were loading (e.g., swapping the "tails" image for "heads").
03Section · Impact
Impact
- Content spoofing inside the trusted origin — useful for social-engineering or screenshots-as-proof.
- Lower threshold for follow-on attacks if any image substitution path interacts with game state.
04Section · Recommendation
Recommendation
- Validate
urlserver-side against a closed allowlist of expected static assets rather than passing arbitrary paths through Next's image optimizer. - Constrain
wandqto a fixed set of allowed values. - HTML-encode and bound any reflected text content that derives from these parameters.
Dedprz: Acknowledged. Zealynx: Acknowledged.