0x5a617461727261436f69 Posted January 1, 2014 Report Posted January 1, 2014 (edited) Target:http://www.lg.com/uk/search.lg?search=<xss>.Requirements:It must work on one of the following browsers without user interaction if your vector is going to work in standard html context:Chrome(31.x,32.x,33.x),firefox(25.x,26.x),IE(10,11).In order to solve this you need to pm me the syntax.Solvers: Edited January 1, 2014 by 0x5a617461727261436f69
Byte-ul Posted January 1, 2014 Report Posted January 1, 2014 Target:http://www.lg.com/uk/search.lg?search=<xss>.Requirements:It must work on one of the following browsers without user interaction if your vector is going to work in standard html context:Chrome(31.x,32.x,33.x),firefox(25.x,26.x),IE(10,11).In order to solve this you need to pm me the syntax.Solvers:I emailed LG about this security problem several days ago. The vector is very easy.
0x5a617461727261436f69 Posted January 1, 2014 Author Report Posted January 1, 2014 I emailed LG about this security problem several days ago. The vector is very easy.Blah blah, who gives a damn fuck man, it's just a reflected xss and i'm making a challenge out of it, it's not like some sqli/rce to pwn the site.If it's so easy, why haven't i received a solution yet?Don't post shit in my thread if you have not provided proof of having solved my challenge!.
Guest Posted January 1, 2014 Report Posted January 1, 2014 strongshit , you failed again..........................................._¸„„„„_.................................„--~*'¯.......'\.............................. („-~~--„¸_....,/ì.........................¸„-^"¯ : : : : :¸-¯"¯/'.................¸„„-^"¯ : : : : : : : '\¸„„,-"'^^~-„„„----~^*'"¯ : : : : : : : : : :¸-":.„-^" : : : : : : : : : : : : : : : : :„-".:.:.:.:.:.:.: : : : : : : : : : ¸„-^¯.:.:.:.:.:. : : : : : : : ¸„„-^¯'\ : : : : : : : ;¸„„-~"¯:"-„""***/*'ì¸'¯: : :"-„ : : :"\: : : :" : : : : \,: : : : : : : : : 'Ì: : :, / : : : : /:::_„-*__„„~`'¨'
Byte-ul Posted January 1, 2014 Report Posted January 1, 2014 Blah blah, who gives a damn fuck man, it's just a reflected xss and i'm making a challenge out of it, it's not like some sqli/rce to pwn the site.If it's so easy, why haven't i received a solution yet?Don't post shit in my thread if you have not provided proof of having solved my challenge!.You didn't post proof you did it either. Why should I make some bastard indian believe me?You can do loads of things with XSS if you use your brain.
aelius Posted January 1, 2014 Report Posted January 1, 2014 (edited) Closed. Edited January 1, 2014 by aelius