XSS Shell 07-24-2011, 10:36 AM
#1
First you need to download XSS Shell
http://ferruh.mavituna.com/xss-tunnellin...-tool-oku/
You need web hosting which has ASP
best is www.7host.com
Than download FlashFXP
http://www.flashfxp.com/
And you need notepad ++
http://notepad-plus.sourceforge.net/uk/site.htm
When you uploaded it you'll have Xssshell.asp
Open it and find SERVER CONFIG
When you found it type in server name like this
Your homepage address is http://user.7host.com/HeR97
And don't forget to save it
Than open this
XSSShell - v0.6.2\admin\db.asp
Now you need to find DATABASE to find it type this in notepad ++
<%
response.Write Server.MapPath(".")
%>
Save it like blah.asp
To upload it open FlashFXP
Press F8
When you are connected upload blah.asp
When you done that open your web browser and type URL of your web site
It should look like http://user.7host.com/HeR97
At the end add /blah.asp
It should look like http://user.7host.com/HeR97/blah.asp
Press enter and we'll see where's our database
It should look like D:\user\HeR97
And post that in db.asp
When we done this go to FlashFXP and upload XSSShell on the host
When we done this type http://user.7host.com/HeR97/admin/
The password is w00t and press login
After that type in your web browser http://user.7host.com/HeR97/sample_victim/
When it's opened type ctr+u and find <!-- attacker payload, assume that you injected it by XSS vulnerability -->
There type your webpage in <script src=.......................
To make that open xssshell folder and go in sample_victim and open default.asp
And enter your page
After that with FlashFXP upload file back
Here is a video tutorial if you didn't uderstood this
http://www.youtube.com/watch?v=vgrxDZVApdI
Enjoy
http://ferruh.mavituna.com/xss-tunnellin...-tool-oku/
You need web hosting which has ASP
best is www.7host.com
Than download FlashFXP
http://www.flashfxp.com/
And you need notepad ++
http://notepad-plus.sourceforge.net/uk/site.htm
When you uploaded it you'll have Xssshell.asp
Open it and find SERVER CONFIG
When you found it type in server name like this
Your homepage address is http://user.7host.com/HeR97
And don't forget to save it
Than open this
XSSShell - v0.6.2\admin\db.asp
Now you need to find DATABASE to find it type this in notepad ++
<%
response.Write Server.MapPath(".")
%>
Save it like blah.asp
To upload it open FlashFXP
Press F8
When you are connected upload blah.asp
When you done that open your web browser and type URL of your web site
It should look like http://user.7host.com/HeR97
At the end add /blah.asp
It should look like http://user.7host.com/HeR97/blah.asp
Press enter and we'll see where's our database
It should look like D:\user\HeR97
And post that in db.asp
When we done this go to FlashFXP and upload XSSShell on the host
When we done this type http://user.7host.com/HeR97/admin/
The password is w00t and press login
After that type in your web browser http://user.7host.com/HeR97/sample_victim/
When it's opened type ctr+u and find <!-- attacker payload, assume that you injected it by XSS vulnerability -->
There type your webpage in <script src=.......................
To make that open xssshell folder and go in sample_victim and open default.asp
And enter your page
After that with FlashFXP upload file back

Here is a video tutorial if you didn't uderstood this
http://www.youtube.com/watch?v=vgrxDZVApdI
Enjoy

![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)
But it's good ! ![[Image: 1308031172619.gif?w=356&h=140]](http://thechive.files.wordpress.com/2011/06/1308031172619.gif?w=356&h=140)