Guest expl0iter Posted November 26, 2011 Report Posted November 26, 2011 (edited) Am vazut ca majoritatea cauta xss-uri in yahoo.com sau intr-un alt site.Am gasit o metoda care v-ar putea ajutaIn primul rand cautati cu niste dork-uri subdomenii:filetype:php site:.yahoo.comfiletype:xml site:.yahoo.comfiletype:cgi site:.yahoo.comfiletype:js site:.yahoo.comfiletype:jsp site:.yahoo.comfiletype:html site:.yahoo.comfiletype:pl site:yahoo.comfiletype:asp site:.yahoo.comIn loc de yahoo.com puteti pune: msn.com, paypal.com, rstcenter.com, facebook.com etcDe exemplu folositi acest dork: filetype:php site:.yahoo.com si acolo gasim hk.finance.yahoo.com/stock/index.php. Apoi luam la puricat parametrii... Codul cel mai folosit este:"><script>alert(/xss/)</script>Se pot folosi si alti vectori deoarece unele subdomenii filtreaza unele coduriLista vectoriVectors XSS - Pastebin.comEu am gasit destule xss-uri si un SQLi cu aceasta metoda si fara sa folosesc fel si fel de scannere. Daca gasiti un scanner bun, va fi mult mai usor sa gasiti, dar se poate si manual.Uitati o lista cu peste 300 de subdomenii yahoo.com:Subdomain list yahoo.com Edited November 26, 2011 by expl0iter Quote
Zatarra Posted November 26, 2011 Report Posted November 26, 2011 Pfff.. ce idee mi-ai dat sa-mi imbogatesc scriptu cu search pe google. Mersi fain Quote
Guest expl0iter Posted November 26, 2011 Report Posted November 26, 2011 Pfff.. ce idee mi-ai dat sa-mi imbogatesc scriptu cu search pe google. Mersi fainNu ne impartasesti si noua ideea ta geniala? Poate facem si noi cascaval Quote
ROFL Posted November 26, 2011 Report Posted November 26, 2011 http://rstcenter.com/forum/10721-%5Brst%5D-yahoo-security-research-cum-poti-manipula-un-sistem.rst Quote
alinu Posted November 26, 2011 Report Posted November 26, 2011 Salut Multumesc pt tutorial, nu imi vine sa cred, am gasit xss la ebay. O sa fac un post imediat Quote
alinu Posted November 26, 2011 Report Posted November 26, 2011 nu stiu unde sa postez la ce categorie.. Quote
skizZ Posted November 26, 2011 Report Posted November 26, 2011 nu stiu unde sa postez la ce categorie.. ShowOFF - ai categorie speciala XSS Quote
Church Posted November 27, 2011 Report Posted November 27, 2011 Eu am gasit destule xss-uri si un SQLi cu aceasta metoda si fara sa folosesc fel si fel de scannere. serios? tu ai gasit sqliu ? Fara scannere ? hmm Quote
Guest expl0iter Posted November 28, 2011 Report Posted November 28, 2011 serios? tu ai gasit sqliu ? Fara scannere ? hmm Care e problema ta pana la urma?nu inteleg und evrei sa ajungi... Quote
Church Posted November 28, 2011 Report Posted November 28, 2011 (edited) rst_expl0iter(11/25/2011 1:03:30 AM) : si ce e cu linku ala?rst_expl0iter(11/25/2011 1:03:34 AM) : de ce l-ai dat ?Church(11/25/2011 1:04:42 AM) : nu e cumva sqli ?rst_expl0iter(11/25/2011 1:04:49 AM) : ai vazut tu sqli?Church(11/25/2011 1:04:57 AM) : intar pe linku de mai susChurch(11/25/2011 1:05:01 AM) : si uitate in sursa sa vezi ce se intamplarst_expl0iter(11/25/2011 1:05:14 AM) : nu se incarca linku alarst_expl0iter(11/25/2011 1:05:16 AM) : a ba darst_expl0iter(11/25/2011 1:05:17 AM) : stairst_expl0iter(11/25/2011 1:06:47 AM) : stii sa faci sqli?Church(11/25/2011 1:06:53 AM) : acuma incerc sa vad Church(11/25/2011 1:08:50 AM) : ia iaiaChurch(11/25/2011 1:09:14 AM) : ia pune ?xxxxxId=2'rst_expl0iter(11/25/2011 1:09:41 AM) : aia e de la protectieChurch(11/25/2011 1:33:44 AM) : si cica mi-o gasit blind sqliChurch(11/25/2011 1:33:45 AM) : Church(11/25/2011 1:33:53 AM) : Length of 'Data Base' is 23Data Base: xxc`ngChurch(11/25/2011 1:37:29 AM) : e false alert sau chiar o fi sqli ?rst_expl0iter(11/25/2011 1:37:37 AM) : nam ideeChurch(11/25/2011 1:54:35 AM) : acu imi gaseste a 4 baza de daterst_expl0iter(11/25/2011 1:55:14 AM) : fa un ssrst_expl0iter(11/25/2011 1:55:25 AM) : ca nu credp.s. nu sterg nimic exploatere Edited November 28, 2011 by Church Quote
Armywz0r Posted February 15, 2012 Report Posted February 15, 2012 Ce este Dork?Si cum pot accesa pasul subdomeniu Dork ? Quote
darkston3e Posted February 15, 2012 Report Posted February 15, 2012 Ce este Dork?Si cum pot accesa pasul subdomeniu Dork ?a person who is stupid, socially inept, not very athletic, dumb and has weird friends/barley any friends/ no friends.Read more: What is a dorkDaca te referi la google dorks, e un tip de search pe anumite criterii .. mai diferite decat searchul obisnuit.Exemple: inurl index.php?id=Si cum pot accesa pasul subdomeniu Dork ? Aici chiar nu inteleg ce vrei sa zici.. 1 Quote
Armywz0r Posted February 15, 2012 Report Posted February 15, 2012 'Am vazut ca majoritatea cauta xss-uri in yahoo.com sau intr-un alt site.Am gasit o metoda care v-ar putea ajutaIn primul rand cautati cu niste dork-uri subdomenii:'La asta ma refer.Unde trebuie sa intru etc.Asa mai pe 'babeste'. Quote
secure Posted February 16, 2012 Report Posted February 16, 2012 'Unde trebuie sa intru etc.Asa mai pe 'babeste'.Te duci pe desktop si dai click pe imaginea sub care scrie Internet Explorer 6.Cand se deschide programul te duci cu sageata de la mouse in sus si chiar deasupra la cele 400 toolbaruri exista un camp in care poti sa scrii adrese de site. In acel camp tastezi google.ro si apesi tasta Enter.Cu placere 1 Quote
Armywz0r Posted February 16, 2012 Report Posted February 16, 2012 (edited) Multumesc + Like xDdarkston3e si secure aveti respectul meu.EDIT :Cum imi dau seama care link este bun? (XSS) Edited February 16, 2012 by Armywz0r Quote
stoicescualecs Posted February 16, 2012 Report Posted February 16, 2012 Multumesc + Like xDdarkston3e si secure aveti respectul meu.EDIT :Cum imi dau seama care link este bun? (XSS)Ti le bagi in c*r,si cand le scoti daca sunt murdare,nu-s bune,care sunt curate au XSS. Quote
Armywz0r Posted February 16, 2012 Report Posted February 16, 2012 , iti dai seama ca suferi nu? Quote
wildchild Posted February 16, 2012 Report Posted February 16, 2012 Ti le bagi in c*r,si cand le scoti daca sunt murdare,nu-s bune,care sunt curate au XSS.Ban permanent pe ambele conturi, esti complet inutil! Go troll somewhere else! Quote
bebemic Posted February 16, 2012 Report Posted February 16, 2012 iti apare o casuta mica cu alert daca are xssMultumesc + Like xDdarkston3e si secure aveti respectul meu.EDIT :Cum imi dau seama care link este bun? (XSS) 1 Quote
Armywz0r Posted February 16, 2012 Report Posted February 16, 2012 Multumesc, dar... problema e ca am tot cautat si am tot cautat, tot ce era pe acolo de cautat si nothing... la forumuri IPB exista XSS? sau Quote
secure Posted February 17, 2012 Report Posted February 17, 2012 Mai greu cu IPB, Joomla, vBulletin etc. Cauta vulnerabilitati in pluginuri, nu in cms si ai mai multe sanse de reusita Quote
Armywz0r Posted February 17, 2012 Report Posted February 17, 2012 http://www.********.ro/mt2gs/index.php?s=player&char=FuRypractic extrage, iar daca pun la char altceva nu extrage nimic.. exista o posibilitate ca sa aflu o vulnerabilitatea ? Quote