| View previous topic :: View next topic |
| Author |
Message |
the the the Master Cheater
Reputation: 46
Joined: 15 Jun 2008 Posts: 429
|
|
| Back to top |
|
 |
potaters Grandmaster Cheater
Reputation: 72
Joined: 13 Apr 2009 Posts: 969
|
Posted: Sat Jun 02, 2012 9:01 pm Post subject: |
|
|
| I've seen like 1 or 2 papers on HTML injection but never read. Can you exploit further?
|
|
| Back to top |
|
 |
the the the Master Cheater
Reputation: 46
Joined: 15 Jun 2008 Posts: 429
|
Posted: Sat Jun 02, 2012 9:08 pm Post subject: |
|
|
| potaters wrote: | | I've seen like 1 or 2 papers on HTML injection but never read. Can you exploit further? | yes but its difficult, this site doesn't let you submit anything with "javascript" or "SCRIPT" I think. also they blocked me from registering now too lol. basically register using anything and fake email and then edit profile and on the city field just do | Code: | | "><marquee>any html you want</marquee> | i did <iframe> and also <img> kind of works
also get web developer addon for firefox and remove maximum field length so you can type more
|
|
| Back to top |
|
 |
Fafaffy Cheater
Reputation: 65
Joined: 12 Dec 2007 Posts: 28
|
Posted: Sat Jun 02, 2012 9:10 pm Post subject: |
|
|
This is something we call Persistent XSS.
_________________
| Brillia wrote: | | I FUCKING FUCK SEX |
|
|
| Back to top |
|
 |
the the the Master Cheater
Reputation: 46
Joined: 15 Jun 2008 Posts: 429
|
Posted: Sat Jun 02, 2012 9:12 pm Post subject: |
|
|
| blablfy. wrote: | | This is something we call Persistent XSS. | Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability.
edit just read on wikipedia
Last edited by the the the on Sat Jun 02, 2012 9:14 pm; edited 1 time in total |
|
| Back to top |
|
 |
potaters Grandmaster Cheater
Reputation: 72
Joined: 13 Apr 2009 Posts: 969
|
Posted: Sat Jun 02, 2012 9:13 pm Post subject: |
|
|
| I just read you can embed .swf's and java applets. Java applets could be where the money is. Seeing as you could make it a JDB and no-one would suspect a thing.
|
|
| Back to top |
|
 |
Fafaffy Cheater
Reputation: 65
Joined: 12 Dec 2007 Posts: 28
|
Posted: Sat Jun 02, 2012 9:14 pm Post subject: |
|
|
| asciicat wrote: | | blablfy. wrote: | | This is something we call Persistent XSS. | Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability. |
http://en.wikipedia.org/wiki/Cross-site_scripting
That + youtube tells you everything you need to really know.
_________________
| Brillia wrote: | | I FUCKING FUCK SEX |
|
|
| Back to top |
|
 |
the the the Master Cheater
Reputation: 46
Joined: 15 Jun 2008 Posts: 429
|
Posted: Sat Jun 02, 2012 9:16 pm Post subject: |
|
|
| potaters wrote: | | I just read you can embed .swf's and java applets. Java applets could be where the money is. Seeing as you could make it a JDB and no-one would suspect a thing. | well now I can't register anymore, fuck
gotta make an auto register-er
| blablfy. wrote: | | asciicat wrote: | | blablfy. wrote: | | This is something we call Persistent XSS. | Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability. |
http://en.wikipedia.org/wiki/Cross-site_scripting
That + youtube tells you everything you need to really know. | Yeah I edited my post.
Last edited by the the the on Sat Jun 02, 2012 9:17 pm; edited 1 time in total |
|
| Back to top |
|
 |
potaters Grandmaster Cheater
Reputation: 72
Joined: 13 Apr 2009 Posts: 969
|
Posted: Sat Jun 02, 2012 9:16 pm Post subject: |
|
|
| blablfy. wrote: | | asciicat wrote: | | blablfy. wrote: | | This is something we call Persistent XSS. | Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability. |
http://en.wikipedia.org/wiki/Cross-site_scripting
That + youtube tells you everything you need to really know. |
I know you have a JDB applet, test please <3?
|
|
| Back to top |
|
 |
Fafaffy Cheater
Reputation: 65
Joined: 12 Dec 2007 Posts: 28
|
Posted: Sat Jun 02, 2012 9:19 pm Post subject: |
|
|
| potaters wrote: | | blablfy. wrote: | | asciicat wrote: | | blablfy. wrote: | | This is something we call Persistent XSS. | Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability. |
http://en.wikipedia.org/wiki/Cross-site_scripting
That + youtube tells you everything you need to really know. |
I know you have a JDB applet, test please <3? | Java Driveby? I used to have those, but I lost interest, as they weren't very effective.
_________________
| Brillia wrote: | | I FUCKING FUCK SEX |
|
|
| Back to top |
|
 |
the the the Master Cheater
Reputation: 46
Joined: 15 Jun 2008 Posts: 429
|
Posted: Sat Jun 02, 2012 9:21 pm Post subject: |
|
|
| blablfy. wrote: | | potaters wrote: | | blablfy. wrote: | | asciicat wrote: | | blablfy. wrote: | | This is something we call Persistent XSS. | Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability. |
http://en.wikipedia.org/wiki/Cross-site_scripting
That + youtube tells you everything you need to really know. |
I know you have a JDB applet, test please <3? | Java Driveby? I used to have those, but I lost interest, as they weren't very effective. | id like to put a shell in the site lol
|
|
| Back to top |
|
 |
Fafaffy Cheater
Reputation: 65
Joined: 12 Dec 2007 Posts: 28
|
Posted: Sat Jun 02, 2012 9:23 pm Post subject: |
|
|
| asciicat wrote: | | blablfy. wrote: | | potaters wrote: | | blablfy. wrote: | | asciicat wrote: | | blablfy. wrote: | | This is something we call Persistent XSS. | Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability. |
http://en.wikipedia.org/wiki/Cross-site_scripting
That + youtube tells you everything you need to really know. |
I know you have a JDB applet, test please <3? | Java Driveby? I used to have those, but I lost interest, as they weren't very effective. | id like to put a shell in the site lol | Search for c99.php, and unless you sql inject it, I doubt you could do it. With XSS though, I know you can steal cookies, and run something SIMILAR to a botnet which controls every user that loads the page (due to hidden iframe)
_________________
| Brillia wrote: | | I FUCKING FUCK SEX |
|
|
| Back to top |
|
 |
the the the Master Cheater
Reputation: 46
Joined: 15 Jun 2008 Posts: 429
|
Posted: Sat Jun 02, 2012 9:52 pm Post subject: |
|
|
| blablfy. wrote: | | asciicat wrote: | | blablfy. wrote: | | potaters wrote: | | blablfy. wrote: | | asciicat wrote: | | blablfy. wrote: | | This is something we call Persistent XSS. | Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability. |
http://en.wikipedia.org/wiki/Cross-site_scripting
That + youtube tells you everything you need to really know. |
I know you have a JDB applet, test please <3? | Java Driveby? I used to have those, but I lost interest, as they weren't very effective. | id like to put a shell in the site lol | Search for c99.php, and unless you sql inject it, I doubt you could do it. With XSS though, I know you can steal cookies, and run something SIMILAR to a botnet which controls every user that loads the page (due to hidden iframe) | oh sick thanks
|
|
| Back to top |
|
 |
|