xss

Discussion in 'Ethical hacking' started by zero963, Aug 7, 2007.

  1. zero963

    zero963 New Member

    Joined:
    Aug 7, 2007
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    0
    hello everyone, i have been googling my mind out try to figure how to use an xss (cross site scripting) exploit like this one:

    http://www-tech.mit.edu/search.html?cx=000...2><script%3
    Ealert(1)%3C/script%3E&cof=FORID%3A11#210 (courtesy of xssed.com;)


    and others that can be executed in the url. keyword being "url" cause i already figured out how to make,find,configure,and execute "hotkeys",
    but i dont know how a remote attacker uses this (lack of a better term) "url injection", where the attacker types in a exploit like this one in his browser and magically another users cookies are sent to his cookie grabber.

    or mybe i totally iam lost and the above exploit has to be executed by the victim using a hot key or the web page has to already be compermised and the above url is than injected into the page after write access to the web page has been exploited.


    or lastly, mybe this "url injection" injects code into the vulnerable script that is being exploited. dont know, but i really want to find out and dont say google it cause i have read every xss tutorial, explanation i could find and well mybe i just need to here a little more detailed answer than what ive read.
     
  2. pradeep

    pradeep Team Leader

    Joined:
    Apr 4, 2005
    Messages:
    1,645
    Likes Received:
    87
    Trophy Points:
    0
    Occupation:
    Programmer
    Location:
    Kolkata, India
    Home Page:
    http://blog.pradeep.net.in

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice