Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


html injektion

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Random spam
View previous topic :: View next topic  
Author Message
the the the
Master Cheater
Reputation: 46

Joined: 15 Jun 2008
Posts: 429

PostPosted: Sat Jun 02, 2012 8:56 pm    Post subject: html injektion Reply with quote

http://www.cheathappens.com/show_user.asp?userID=1378189
Back to top
View user's profile Send private message
potaters
Grandmaster Cheater
Reputation: 72

Joined: 13 Apr 2009
Posts: 969

PostPosted: Sat Jun 02, 2012 9:01 pm    Post subject: Reply with quote

I've seen like 1 or 2 papers on HTML injection but never read. Can you exploit further?
Back to top
View user's profile Send private message
the the the
Master Cheater
Reputation: 46

Joined: 15 Jun 2008
Posts: 429

PostPosted: Sat Jun 02, 2012 9:08 pm    Post subject: Reply with quote

potaters wrote:
I've seen like 1 or 2 papers on HTML injection but never read. Can you exploit further?
yes but its difficult, this site doesn't let you submit anything with "javascript" or "SCRIPT" I think. also they blocked me from registering now too lol. basically register using anything and fake email and then edit profile and on the city field just do
Code:
"><marquee>any html you want</marquee>
i did <iframe> and also <img> kind of works

also get web developer addon for firefox and remove maximum field length so you can type more
Back to top
View user's profile Send private message
Fafaffy
Cheater
Reputation: 65

Joined: 12 Dec 2007
Posts: 28

PostPosted: Sat Jun 02, 2012 9:10 pm    Post subject: Reply with quote

This is something we call Persistent XSS.
_________________
Brillia wrote:
I FUCKING FUCK SEX
Back to top
View user's profile Send private message Send e-mail
the the the
Master Cheater
Reputation: 46

Joined: 15 Jun 2008
Posts: 429

PostPosted: Sat Jun 02, 2012 9:12 pm    Post subject: Reply with quote

blablfy. wrote:
This is something we call Persistent XSS.
Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability.

edit just read on wikipedia


Last edited by the the the on Sat Jun 02, 2012 9:14 pm; edited 1 time in total
Back to top
View user's profile Send private message
potaters
Grandmaster Cheater
Reputation: 72

Joined: 13 Apr 2009
Posts: 969

PostPosted: Sat Jun 02, 2012 9:13 pm    Post subject: Reply with quote

I just read you can embed .swf's and java applets. Java applets could be where the money is. Seeing as you could make it a JDB and no-one would suspect a thing.
Back to top
View user's profile Send private message
Fafaffy
Cheater
Reputation: 65

Joined: 12 Dec 2007
Posts: 28

PostPosted: Sat Jun 02, 2012 9:14 pm    Post subject: Reply with quote

asciicat wrote:
blablfy. wrote:
This is something we call Persistent XSS.
Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability.

http://en.wikipedia.org/wiki/Cross-site_scripting

That + youtube tells you everything you need to really know.

_________________
Brillia wrote:
I FUCKING FUCK SEX
Back to top
View user's profile Send private message Send e-mail
the the the
Master Cheater
Reputation: 46

Joined: 15 Jun 2008
Posts: 429

PostPosted: Sat Jun 02, 2012 9:16 pm    Post subject: Reply with quote

potaters wrote:
I just read you can embed .swf's and java applets. Java applets could be where the money is. Seeing as you could make it a JDB and no-one would suspect a thing.
well now I can't register anymore, fuck

gotta make an auto register-er

blablfy. wrote:
asciicat wrote:
blablfy. wrote:
This is something we call Persistent XSS.
Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability.

http://en.wikipedia.org/wiki/Cross-site_scripting

That + youtube tells you everything you need to really know.
Yeah I edited my post.

Last edited by the the the on Sat Jun 02, 2012 9:17 pm; edited 1 time in total
Back to top
View user's profile Send private message
potaters
Grandmaster Cheater
Reputation: 72

Joined: 13 Apr 2009
Posts: 969

PostPosted: Sat Jun 02, 2012 9:16 pm    Post subject: Reply with quote

blablfy. wrote:
asciicat wrote:
blablfy. wrote:
This is something we call Persistent XSS.
Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability.

http://en.wikipedia.org/wiki/Cross-site_scripting

That + youtube tells you everything you need to really know.

I know you have a JDB applet, test please <3?
Back to top
View user's profile Send private message
Fafaffy
Cheater
Reputation: 65

Joined: 12 Dec 2007
Posts: 28

PostPosted: Sat Jun 02, 2012 9:19 pm    Post subject: Reply with quote

potaters wrote:
blablfy. wrote:
asciicat wrote:
blablfy. wrote:
This is something we call Persistent XSS.
Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability.

http://en.wikipedia.org/wiki/Cross-site_scripting

That + youtube tells you everything you need to really know.

I know you have a JDB applet, test please <3?
Java Driveby? I used to have those, but I lost interest, as they weren't very effective.
_________________
Brillia wrote:
I FUCKING FUCK SEX
Back to top
View user's profile Send private message Send e-mail
the the the
Master Cheater
Reputation: 46

Joined: 15 Jun 2008
Posts: 429

PostPosted: Sat Jun 02, 2012 9:21 pm    Post subject: Reply with quote

blablfy. wrote:
potaters wrote:
blablfy. wrote:
asciicat wrote:
blablfy. wrote:
This is something we call Persistent XSS.
Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability.

http://en.wikipedia.org/wiki/Cross-site_scripting

That + youtube tells you everything you need to really know.

I know you have a JDB applet, test please <3?
Java Driveby? I used to have those, but I lost interest, as they weren't very effective.
id like to put a shell in the site lol
Back to top
View user's profile Send private message
Fafaffy
Cheater
Reputation: 65

Joined: 12 Dec 2007
Posts: 28

PostPosted: Sat Jun 02, 2012 9:23 pm    Post subject: Reply with quote

asciicat wrote:
blablfy. wrote:
potaters wrote:
blablfy. wrote:
asciicat wrote:
blablfy. wrote:
This is something we call Persistent XSS.
Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability.

http://en.wikipedia.org/wiki/Cross-site_scripting

That + youtube tells you everything you need to really know.

I know you have a JDB applet, test please <3?
Java Driveby? I used to have those, but I lost interest, as they weren't very effective.
id like to put a shell in the site lol
Search for c99.php, and unless you sql inject it, I doubt you could do it. With XSS though, I know you can steal cookies, and run something SIMILAR to a botnet which controls every user that loads the page (due to hidden iframe)
_________________
Brillia wrote:
I FUCKING FUCK SEX
Back to top
View user's profile Send private message Send e-mail
the the the
Master Cheater
Reputation: 46

Joined: 15 Jun 2008
Posts: 429

PostPosted: Sat Jun 02, 2012 9:52 pm    Post subject: Reply with quote

blablfy. wrote:
asciicat wrote:
blablfy. wrote:
potaters wrote:
blablfy. wrote:
asciicat wrote:
blablfy. wrote:
This is something we call Persistent XSS.
Tell me more. Also I read the xss thing you posted, and tried it here cause I knew this site had xss vulnerability.

http://en.wikipedia.org/wiki/Cross-site_scripting

That + youtube tells you everything you need to really know.

I know you have a JDB applet, test please <3?
Java Driveby? I used to have those, but I lost interest, as they weren't very effective.
id like to put a shell in the site lol
Search for c99.php, and unless you sql inject it, I doubt you could do it. With XSS though, I know you can steal cookies, and run something SIMILAR to a botnet which controls every user that loads the page (due to hidden iframe)
oh sick thanks
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Random spam All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites