| View previous topic :: View next topic |
| Author |
Message |
Aviar³ Grandmaster Cheater
Reputation: 50
Joined: 03 Jan 2008 Posts: 655 Location: Canada
|
Posted: Fri Jun 01, 2012 3:20 pm Post subject: Anyone used cross site scripting before? |
|
|
And have any idea how to do it?
_________________
This is the inception of deception, checking the depth of your perception.
 |
|
| Back to top |
|
 |
Cryoma Member of the Year
Reputation: 198
Joined: 14 Jan 2009 Posts: 1819
|
Posted: Fri Jun 01, 2012 3:27 pm Post subject: |
|
|
| Uh, I'm not sure what you mean but if it's php related, sure.
|
|
| Back to top |
|
 |
Up2Admin I'm a spammer
Reputation: 126
Joined: 17 Oct 2007 Posts: 6548 Location: Texas
|
Posted: Fri Jun 01, 2012 3:43 pm Post subject: |
|
|
Like, just sending and receiving information between 2 different sites? Or are you thinking of something more advanced?
I've never tried it with separate hosts (and I'm not sure how much it matters), but I've done it plenty of time with separate domains that utilize different directories on the same host.
_________________
|
|
| Back to top |
|
 |
Slugsnack Grandmaster Cheater Supreme
Reputation: 71
Joined: 24 Jan 2007 Posts: 1857
|
Posted: Fri Jun 01, 2012 3:56 pm Post subject: |
|
|
| Cryoma. Doesn't know what it is. 'YEP PROBABLY DONE IT BEFORE'
|
|
| Back to top |
|
 |
Cryoma Member of the Year
Reputation: 198
Joined: 14 Jan 2009 Posts: 1819
|
Posted: Fri Jun 01, 2012 4:06 pm Post subject: |
|
|
| I know what it is, he's just being vague.
|
|
| Back to top |
|
 |
Aniblaze Grandmaster Cheater Supreme
Reputation: 138
Joined: 23 Apr 2006 Posts: 1757 Location: The Netherlands
|
Posted: Fri Jun 01, 2012 4:15 pm Post subject: |
|
|
Not really. Only situation that came close is when I had two versions of the same web application, and I had to use the old version to login, and then login to the new version and redirect to there. But in the end I had to add the server that logged in to the trusted domains on the new server (with the new version), which doesn't really count as real cross-site scripting.
I do know that in PHP you can use the cURL lib to log onto a remote server. I suppose you could make a window application that logs in and feeds you whatever the server returns. Doesn't really count IMO as you aren't doing anything to the client side of it. I suppose you could use it for phishing purposes. Like I said, do not have any experience on the subject.
|
|
| Back to top |
|
 |
gogodr I post too much
Reputation: 125
Joined: 19 Dec 2006 Posts: 2041
|
Posted: Fri Jun 01, 2012 4:34 pm Post subject: |
|
|
| Slugsnack wrote: | | Cryoma. Doesn't know what it is. 'YEP PROBABLY DONE IT BEFORE' |
sometimes I don't remember doing something until I see it again.
|
|
| Back to top |
|
 |
Aviar³ Grandmaster Cheater
Reputation: 50
Joined: 03 Jan 2008 Posts: 655 Location: Canada
|
Posted: Fri Jun 01, 2012 4:43 pm Post subject: |
|
|
Pretty much the situation is this, the place where I live pays for one internet package to be shared across 14 people. Thus, there is a router set up to the principal modem. The router, however, belongs to a certain someone, and I believe he is limiting everyones connection, and hence me getting 9KB dl almost anytime of day or night (the lines max is 300 KB). I tried logging onto the WebConsole for the router and using the standard user/pass (admin/admin), as well as no pass no user, and it fails. Thus, I can only assume he has set a particular pass. I looked up the router and it is vulnerable to XSS, and am interested in knowing if that particular detail can be exploiter to gain access to the router either by capturing his personal session when he logs on, or by bypassing the login.
P.S.: The modem is a TPLink WR740N.
_________________
This is the inception of deception, checking the depth of your perception.
 |
|
| Back to top |
|
 |
Fafaffy Cheater
Reputation: 65
Joined: 12 Dec 2007 Posts: 28
|
Posted: Fri Jun 01, 2012 6:39 pm Post subject: |
|
|
http://ha.ckers.org/xss.html
yw
also, use ff, not chrome, chrome blocks xss like a baws.
_________________
| Brillia wrote: | | I FUCKING FUCK SEX |
|
|
| Back to top |
|
 |
Cryoma Member of the Year
Reputation: 198
Joined: 14 Jan 2009 Posts: 1819
|
|
| Back to top |
|
 |
potaters Grandmaster Cheater
Reputation: 72
Joined: 13 Apr 2009 Posts: 969
|
Posted: Sat Jun 02, 2012 12:11 am Post subject: |
|
|
| There are tons of XSS tools online. But you probably won't be able to do it. Get a tool like Nessus or OpenVAS. If you are on his local network there is so much shit you can do. I recommend you get Backtrack 5 as there are many tools on it that will aid you in it. You could just make a phisher for the login page and wait until he attempts to log in. Or infect his computer with a payload from Metasploit.
|
|
| Back to top |
|
 |
|