Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 527 Vote(s) - 3.55 Average
  • 1
  • 2
  • 3
  • 4
  • 5
<XSS> [Help Needed]

#1
Heres my understanding of the XSS Cookie Stealing.

You find an XSS Valn within that site.
You then Send them the XSS Valn With a cookie Stealing Script (Of course you need to create a site with the cookie stealing script, log, and script that gives the cookie to the cookie stealer.)

What I do not under stand is how you view the cookies after u get them, or Say if a user wasnt logged in does it send them to a login page which they then log in and then u get their login cookie?

And do you need to create a real web page for these scripts?

These are what I need to Clarify.

And then hopefully i can create these with out any kind of help.

Sorry for the Newbie Questions, I'm more of a visual learner, and then I keep doing it until I understand the complete process to where i understand every detail.
Reply

#2
Um, you use firebug and you modify your current cookie to change them to the one that is hopefully the admin's after he has logged in therefore, giving you access to AdminCP.

If the admin is not logged in receiving your email (weird), then you will still get a cookie, but will not give you access, just make you look like him accessing the page.
Reply

#3
Yeah XSS didnt help me much on my mission i set out to do.
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through