diff --git a/README.md b/README.md index da12c55..97befd6 100644 --- a/README.md +++ b/README.md @@ -1,29 +1,30 @@ -Paywall Issue +Paywall Issue
www.aachener-zeitung.de
www.aachener-nachrichten.de
-0. information +0. information
The websites are offering a mixture of free and payed articles hidden by paywall. (http://www.aachener-zeitung.de/zva/pc/) The websites use AESUtils and CryptoJS to hide articles. -The provider leaks sensitive data like password, IV and salt which are used for encryption and can be used to decrypt the articles. +The provider leaks sensitive data like password, IV and salt which are used for encryption and can be used to decrypt the articles. +This issue does not leak any personal data of (registered) users. free article: http://www.aachener-zeitung.de/lokales/juelich/zukunft-von-haus-overbach-ist-langfristig-gesichert-1.1610013 hidden article: http://www.aachener-zeitung.de/lokales/juelich/feierabendmarkt-in-juelich-mit-bilderbuchstart-1.1622101 -1. timeline +1. timeline
-2. PoC ---- +2. PoC
+Code will be released after fix or responsible disclosure -3. responsible disclosure +3. responsible disclosure
disclosure until 04.08.2017