Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


[XSS challenge]*snip*[Easy] filter_list
Author
Message
[XSS challenge]*snip*[Easy] #1
Hello Hackcommunity

I'm curious about how good you guys are to xss. Therefore i'm setting up a little challenge. If you know the basics of xss this will be an fairly easy challenge. This is just to see which level you guys are on.

If you guys find this to easy i will make some more challenges just a little harder Smile

Target:

*snip*

Rules:
  • No vector sharing with others --> otherwise it wouldn't be a challenge
  • You should make a pop-up box containing your name
  • Post PoC in the thread
  • PM me the query so that I can confirm


PoC:





Top ten solvers:

Reply

RE: [XSS challenge]http://www.leksikon.org[Easy] #2
Do you have sufficient evidence that this is your site . ?
How do we know that this isnt your friends site and you want to play some joke . ?
<?php echo "Very inactive at this current moment in time"; ?>
[Image: Z8KDe.png]

Reply

RE: [XSS challenge]http://www.leksikon.org[Easy] #3
Do you know anything about XSS? By making an alert box will not harm the site in ANY way. This is a way to proof that the site is vulnerable. You are not going to hack the site by doing this. You are not getting access to any data on their server. Yes you can exploit it, but by making an alert box you wan't hurt the website or it's owners.

-Anima Templi-

Reply

RE: [XSS challenge]http://www.leksikon.org[Easy] #4
okaay Challenge accepted.!
<?php echo "Very inactive at this current moment in time"; ?>
[Image: Z8KDe.png]

Reply

RE: [XSS challenge]http://www.leksikon.org[Easy] #5
Some websites are even paying you for finding this, for an example Facebook and Google are paying you for reporting xss vulnerabilities on their sites to them.

Reply

RE: [XSS challenge]http://www.leksikon.org[Easy] #6
(05-15-2012, 09:39 AM)Anima Templi Wrote: Some websites are even paying you for finding this, for an example Facebook and Google are paying you for reporting xss vulnerabilities on their sites to them.

Yes i have heard about this , i know that Google chrome each year purposely put vulnerabilities into there site and offer cash to any hacker that can obtain and find it
<?php echo "Very inactive at this current moment in time"; ?>
[Image: Z8KDe.png]

Reply

RE: [XSS challenge]http://www.leksikon.org[Easy] #7
This isn't nearly the same. Xss is only a website "attack method". And you can't do xss in Google Chrome, they have a filter that blocks this type of website hacking method.

I think you are thinking about the "pwn2own" hacking contest? That contest is only about software vulnerabilities last time i checked. I think I'm going to write a tutorial about xss, the ones who's already here are missing something. They are only focussing on the bad side of it.

I was really thinking people on here knew more about xss. It's one of the most popular website hacking methods. The only thing i can mention that's more used is SQLi.

Good luck Smile

-Anima Templi-

Reply

RE: [XSS challenge]http://www.leksikon.org[Easy] #8
I'm trying it atm, but the website is so SLOW! Sad

I did it!!

How:
Spoiler:
In the index page, you type in the XSS in the search bar. After doing so, I had an alert came up.


Also, this URL was at my awesome bar (ofc I use FireFox):
Spoiler:
*snip*


Oh, also you can just do:
[spoiler]
1) Type something in the search bar
2) Replace ?val=[whatever you typed] with any XSS thing like: <script>alert("kaz_crack was here! Please refine your security. Wink");</script>
3) After notifying the admin, celebrate for being such a good hacker!
[/spoiler
To hack is a skill, but a skill may or may not be to hack.

Reply

RE: [XSS challenge]http://www.leksikon.org[Easy] #9
Hello, hacking requests or encouraging in hacking a website is against the rules. Even if it is non-persistent XSS, it can be used in a malicious way and I do NOT tolerate this.

If you provide enough evidence that you actually own the website, then its fine. Feel free to pm me.

Thread closed.
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply