Fourteen Years of Service
Posts: 944
Threads: 67
RE: [XSS challenge]http://www.leksikon.org[Easy] 05-15-2012, 09:25 AM
#2
Do you have sufficient evidence that this is your site . ?
How do we know that this isnt your friends site and you want to play some joke . ?
<?php echo "Very inactive at this current moment in time"; ?>
•
Fourteen Years of Service
Posts: 1,398
Threads: 51
RE: [XSS challenge]http://www.leksikon.org[Easy] 05-15-2012, 09:36 AM
#3
Do you know anything about XSS? By making an alert box will not harm the site in ANY way. This is a way to proof that the site is vulnerable. You are not going to hack the site by doing this. You are not getting access to any data on their server. Yes you can exploit it, but by making an alert box you wan't hurt the website or it's owners.
-Anima Templi-
•
Fourteen Years of Service
Posts: 944
Threads: 67
RE: [XSS challenge]http://www.leksikon.org[Easy] 05-15-2012, 09:38 AM
#4
okaay Challenge accepted.!
<?php echo "Very inactive at this current moment in time"; ?>
•
Fourteen Years of Service
Posts: 1,398
Threads: 51
RE: [XSS challenge]http://www.leksikon.org[Easy] 05-15-2012, 09:39 AM
#5
Some websites are even paying you for finding this, for an example Facebook and Google are paying you for reporting xss vulnerabilities on their sites to them.
•
Fourteen Years of Service
Posts: 176
Threads: 21
RE: [XSS challenge]http://www.leksikon.org[Easy] 05-15-2012, 11:10 AM
#8
I'm trying it atm, but the website is so SLOW!
I did it!!
How:
Spoiler:
In the index page, you type in the XSS in the search bar. After doing so, I had an alert came up.
Also, this URL was at my awesome bar (ofc I use FireFox):
Spoiler:
*snip*
Oh, also you can just do:
[spoiler]
1) Type something in the search bar
2) Replace ?val=[whatever you typed] with any XSS thing like: <script>alert("kaz_crack was here! Please refine your security.

");</script>
3) After notifying the admin, celebrate for being such a good hacker!
[/spoiler
To hack is a skill, but a skill may or may not be to hack.
•
Fourteen Years of Service
Posts: 3,799
Threads: 957
RE: [XSS challenge]http://www.leksikon.org[Easy] 05-15-2012, 08:34 PM
#9
Hello, hacking requests or encouraging in hacking a website is against the rules. Even if it is non-persistent XSS, it can be used in a malicious way and I do NOT tolerate this.
If you provide enough evidence that you actually own the website, then its fine. Feel free to pm me.
Thread closed.
Staff will never ever ask you for your personal information.
We know everything about you anyway.
•