Jump to content
Wisa

Fun stuff

Recommended Posts

N-ai ce dovada sa-mi dai. Poate ca ai gasit vreun xss, dar poza tot fake este.

Ca sa te ajut putin - variabila rstforums este definita in domeniul acela si are fix valoarea "rstforums"? Frumoasa coincidenta.

Al doilea indiciu, care este diferenta dintre

<script>alert(1)</script>
si
<script>alert(qwerty)</script>

?

Edited by TheTime
Link to comment
Share on other sites

@TheTime ti-am dat tot ceea ce ai nevoie in pm, daca e nevoie ofer si unui administrator p.o.c. :)

x2:// adevarat poza este neclara si am gresit eu legat de vector, am sa fac inca un screen.

X3:// acum fac update la poza.

Multumesc de atentionare oricum.

Edited by Aerosol
Link to comment
Share on other sites

In PM:

pai am cenzurat si probabil in timp ce am cenzurat s-a pierdut claritatea.

Nu e ok sa facem atata caz pentru o virgula....

da apare <script>alert(rstforums)</script>

in loc de<script>alerti('rstforums');</script> greseala mea...

Trebuia sa ma asigur ca am postat corect. am sa revin cu edit la poza.

Si-a dat seama ce era gresit in poza ( http://i.imgur.com/KZhqWCo.png ) deci se iarta.

Felicitari pentru XSS! Dar nu mai pune dovezi fabricate.

  • Upvote 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...