Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2024-0002·content-spoofing

Content spoofing via parameters url, w, and q (unauthenticated and wallet-connected)

Acknowledgedpentestblackboxnextjs
TL;DR

The url, w, and q parameters on /_next/image were modifiable on the fly, allowing an attacker to substitute images and produce defacement-style content spoofing variants without script execution.

Severity
MEDIUM
Impact
MEDIUM
Likelihood
MEDIUM
Method
MManual review
CAT.
Complexity
LOW
Exploitability
MEDIUM
02Section · Description

Description

Browsing the dedprz.virtual.tech site emitted requests like:

GET /_next/image?url=%2Ftails-button-active.png&w=640&q=75 HTTP/2 Host: dedprz.virtual.tech

The url, w, and q parameters had predictable values that could be modified in-flight by an attacker controlling the user's network or by hooking into the page. Substituting url swapped the rendered image, allowing self-defacement style content spoofing while components were loading (e.g., swapping the "tails" image for "heads").

03Section · Impact

Impact

  • Content spoofing inside the trusted origin — useful for social-engineering or screenshots-as-proof.
  • Lower threshold for follow-on attacks if any image substitution path interacts with game state.
04Section · Recommendation

Recommendation

  • Validate url server-side against a closed allowlist of expected static assets rather than passing arbitrary paths through Next's image optimizer.
  • Constrain w and q to a fixed set of allowed values.
  • HTML-encode and bound any reflected text content that derives from these parameters.

Dedprz: Acknowledged. Zealynx: Acknowledged.

F-2024-0002