MotionPoint postMessage — proof of concept in two stages

This page is served from an origin that contains . Both listeners in the MotionPoint chain accept any origin that merely contains their configured host, so this one passes both checks.

Stage 1 posts a JSON object to MpStorage.listener (registered by mpel.js, which loads on every page in every country). That object becomes userPref and makes the page request /mpel/mpel?…&lang=es&country=US&curr=USD, whose answer loads mpel_redirect.js. Stage 2 posts the string continue, which mpel_redirect.js turns into MP.switchLanguage(userPref.siteurl, …) — a <script> whose host is the value I supplied.

waiting…

Both payloads are benign markers: they set document.title and report document.domain, the URL and how many cookies / storage keys are script-readable. Nothing is written and nothing leaves this browser.