![]() |
|
XSS Shell - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: Hacking (https://sinister.ly/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.ly/Forum-Website-Server-Hacking) +--- Thread: XSS Shell (/Thread-XSS-Shell) Pages:
1
2
|
XSS Shell - HeR97 - 07-24-2011 First you need to download XSS Shell http://ferruh.mavituna.com/xss-tunnelling-paper-and-xss-tunnel-tool-oku/ You need web hosting which has ASP best is www.7host.com Than download FlashFXP http://www.flashfxp.com/ And you need notepad ++ http://notepad-plus.sourceforge.net/uk/site.htm When you uploaded it you'll have Xssshell.asp Open it and find SERVER CONFIG When you found it type in server name like this Your homepage address is http://user.7host.com/HeR97 And don't forget to save it Than open this XSSShell - v0.6.2\admin\db.asp Now you need to find DATABASE to find it type this in notepad ++ <% response.Write Server.MapPath(".") %> Save it like blah.asp To upload it open FlashFXP Press F8 When you are connected upload blah.asp When you done that open your web browser and type URL of your web site It should look like http://user.7host.com/HeR97 At the end add /blah.asp It should look like http://user.7host.com/HeR97/blah.asp Press enter and we'll see where's our database It should look like D:\user\HeR97 And post that in db.asp When we done this go to FlashFXP and upload XSSShell on the host When we done this type http://user.7host.com/HeR97/admin/ The password is w00t and press login After that type in your web browser http://user.7host.com/HeR97/sample_victim/ When it's opened type ctr+u and find <!-- attacker payload, assume that you injected it by XSS vulnerability --> There type your webpage in <script src=....................... To make that open xssshell folder and go in sample_victim and open default.asp And enter your page After that with FlashFXP upload file back ![]() Here is a video tutorial if you didn't uderstood this http://www.youtube.com/watch?v=vgrxDZVApdI Enjoy
RE: XSS Shell - 1llusion - 07-24-2011 Nice tut, however, some formating would make it more readable =) RE: XSS Shell - bspro - 07-24-2011 Nice tut can u edit it so it look attractive thanks RE: XSS Shell - 1234hotmaster - 07-24-2011 nice tut but its the exact stuff in patchy's tut. even the hosting. PS: its called XSS tunnel not XSS shell
RE: XSS Shell - HeR97 - 07-25-2011 OK NOw will somenone give me reputation xDDDDDDDDDDDDDDDDDDDDDDD RE: XSS Shell - 1234hotmaster - 08-02-2011 i'll give patchy reputation its the same tut :epic: RE: XSS Shell - KaiT_AleX - 08-03-2011 I think this tut is stolen ! But it's good !
RE: XSS Shell - HeR97 - 08-03-2011 xD but it was in serbian xDDDDDD RE: XSS Shell - KaiT_AleX - 08-03-2011 YES !! lol........
RE: XSS Shell - Hbkripcrick - 08-04-2011 I dont about XSS shell.But it s a nice tutorial |