Jump to content
dancezar

[XSS] Challenge

Recommended Posts

  • Active Members

Target:htxp://www.getmeontop.com/search.php?query=&search=1

Dificultate:Easy

Tasks:

-Trebuie sa faceti un vector sa functioneze in acelasi timp pe IE 8 si Chrome

Reguli:

-Nu dati hinturi

-Postati o imagine cenzurata cu cu cele 2 browsere

-Trimiteti sintaxa prin PM

Proof:

Chrome:

http://s21.postimg.org/o43oqrn3b/xss_ch_ch.png

xss_ch_ch.png

Ie:

http://s8.postimg.org/6ft1coylw/xss_ch_ch2.jpg

xss_ch_ch2.jpg

Solveri:

- akkiliON

- FoxKids

-

-

-

-

-

Edited by danyweb09
Link to comment
Share on other sites

Ok, prove me wrong.

xss this get parameter:

efukt.com/?search=<xss vector goes here>.

If it works on chrome or IE, i'll take back my words and chop off my balls.

As i predicted, weird behavior in GET parameter (just received pm from danyweb), not a bypass in either of the xss filters.

It's ok ;).

Edited by snq
Link to comment
Share on other sites

  • Active Members

Este vorba despre altceva , site-ul ala are filtru pe un caracter , cu ajutorul acelui filtru poti face "bypass" la auditorul de pe chrome si IE. Plm <script>alert(1);</script> e mult prea simplu.

Link to comment
Share on other sites

  • Active Members

CLOSED

Orice pm primit nu se v-a mai lua in considerare.

Rezolvarea era foarte simpla!

Am dat hintu intr-un post mai sus

••••••>GetMeOnTop Search for organic search engine ranking

Daca bagati " este eliminat(Inlocuit cu NULL) ,va puteti folosi de el ca faceti bypass la xss auditor.

Practic daca introduceti <scri"pt> filtrul v-a elimina " si v-a deveni <script>.

••••••>GetMeOnTop Search for organic search engine ranking<scri"pt>alert(1)</script>

Si astfel v-a functiona pe ambele browsere!@

Edited by danyweb09
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...