Sinisterly
What do you think? - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: What do you think? (/Thread-What-do-you-think--91603)

Pages: 1 2


What do you think? - Mr.Kurd - 09-16-2017

In The Name Of Allah
Al-Salam Alekum

What do you think?!
https://cxsecurity.com/issue/WLB-2017090127
Isn't it XSS?!

Wa Salam Alekum


RE: What do you think? - Mr.Kurd - 09-16-2017

[Image: p_6248vjnx0.jpg]


RE: What do you think? - mothered - 09-17-2017

Moved to the Website & Server Hacking forum.

I'm running late for lunch and logging off Immediately after this post, I shall have a look later tonight.


RE: What do you think? - mothered - 09-17-2017

(09-16-2017, 06:19 PM)Mr.Kurd Wrote: What do you think?!
https://cxsecurity.com/issue/WLB-2017090127
Isn't it XSS?!

Are you actually referring to this?

Quote: '=''or'

If so, It's an SQLi command that exploits a security vulnerability In the database, by Injecting the command Into the SQL Statement(s) via Input from the form-based login page. I don't know why they've made a big deal out of It. It's a very basic form of exploitation.


RE: What do you think? - Mr.Kurd - 09-17-2017

(09-17-2017, 02:44 PM)mothered Wrote:
(09-16-2017, 06:19 PM)Mr.Kurd Wrote: What do you think?!
https://cxsecurity.com/issue/WLB-2017090127
Isn't it XSS?!

Are you actually referring to this?

Quote: '=''or'

If so, It's an SQLi command that exploits a security vulnerability In the database, by Injecting the command Into the SQL Statement(s) via Input from the form-based login page. I don't know why they've made a big deal out of It. It's a very basic form of exploitation.

Let me ask again Biggrin
I opened that link above, then that alert appeared for me, so I asked if it is or not XSS.


RE: What do you think? - Anime! - 09-17-2017

(09-17-2017, 10:36 PM)Mr.Kurd Wrote:
(09-17-2017, 02:44 PM)mothered Wrote:
(09-16-2017, 06:19 PM)Mr.Kurd Wrote: What do you think?!
https://cxsecurity.com/issue/WLB-2017090127
Isn't it XSS?!

Are you actually referring to this?

Quote: '=''or'

If so, It's an SQLi command that exploits a security vulnerability In the database, by Injecting the command Into the SQL Statement(s) via Input from the form-based login page. I don't know why they've made a big deal out of It. It's a very basic form of exploitation.

Let me ask again Biggrin
I opened that link above, then that alert appeared for me, so I asked if it is or not XSS.

Didn't pop up for me. Could have been a bunch of things.


RE: What do you think? - mothered - 09-18-2017

(09-17-2017, 10:36 PM)Mr.Kurd Wrote: Let me ask again  Biggrin
I opened that link above, then that alert appeared for me, so I asked if it is or not XSS.

As with @Anime! above, upon clicking the link nothing happened on my end.

Without experiencing the alert/popup, It's not possible to say the type of vulnerability (If any).


RE: What do you think? - Mr.Kurd - 09-18-2017

(09-18-2017, 06:17 AM)mothered Wrote:
(09-17-2017, 10:36 PM)Mr.Kurd Wrote: Let me ask again Biggrin
I opened that link above, then that alert appeared for me, so I asked if it is or not XSS.

As with @Anime! above, upon clicking the link nothing happened on my end.

Without experiencing the alert/popup, It's not possible to say the type of vulnerability (If any).

I didn't get the alert on my PC but I'm still getting that alert on my Phone.
My Phone browser version is old, so it seems to be XSS for me.


RE: What do you think? - Bish0pQ - 09-19-2017

An alert doesn't necessarily mean that you can perform an XSS attack, though it's obvious a script is executed. To be sure what script is executed and if you can change it requires very little resource and if you find the right script you can easily check if xss is possible by changing the alert text or running a different simple script.


RE: What do you think? - Mr.Kurd - 09-20-2017

(09-19-2017, 09:13 AM)Bish0pQ Wrote: An alert doesn't necessarily mean that you can perform an XSS attack, though it's obvious a script is executed. To be sure what script is executed and if you can change it requires very little resource and if you find the right script you can easily check if xss is possible by changing the alert text or running a different simple script.

Yep, my bro. Thank you.