[align=center][url=http://www.asian-central.com/][img]http://www.asian-central.com/images/shareAC.jpg[/img][/url]
[b]
www.asian-central.com
via SwishMax embed XSS[/b][/align]
[b]proof-of-concept[/b]: [url]http://www.asian-central.com/shakiro214/[/url]
[b]CREATE AN ACCOUNT THERE[/b]
click the image above to go there, then create an account the way you would any other social networking site
[b]MAKE A JAVASCRIPT FILE[/b]
create a basic javascript file on ripway and save it [b]-or-[/b] use use the following code:
[b]replace your primary photo with youtube videos:[/b]
<">[b]THE XSS PART[/b]
step 1: download swishmax w/ crack
[url=www.megaupload.com/it/?d=S8PMG12Y]SwishMax + crack 11.07MB[/url]
[b]disclaimer:[/b] I did not upload this. It isn't mine.
[quote]a. extract contents of file
b. run setupSwishMax.exe
c. memorize the folder your installing it too
d. go to folder of installment and delete swishmax.exe
e. place the extracted swishmax.exe in that folder[/quote]
step 2: open swishmax
step 3: start a new empty movie
step 4: click on the script tab
[img]http://img68.imageshack.us/img68/4585/38632192vm4.jpg[/img]
step 5: click on the add script tag
[img]http://img502.imageshack.us/img502/4053/84610399fy5.jpg[/img]
step 6: select
[b]events[/b]
[b]frame[/b]
[b]onload[/b]
[img]http://img74.imageshack.us/img74/9397/75435218wh6.jpg[/img]
step 7: when you see the onload function appear, right click it then select
Add script
Browser/Network
getURL(...)
[img]http://img214.imageshack.us/img214/7346/58355824be7.jpg[/img]
step 8: When [b]getURL()[/b] appears, click on it
you should see a box to input the value for [b]"URL"[/b] in the bottom panel
[img]http://img237.imageshack.us/img237/8606/94564496qi8.jpg[/img]
copy this code and paste it into the textbox for [b]"URL"[/b]:
<">[quote]a. Replace the [b]URL_TO_JS_FILE[/b] with the DIRECT URL to your js file
b. click the (e) button twice as to be sure that the function for [b]getURL[/b] appears like it does in the picture above, you'll find the (e) button right beside the input box for [b]URL[/b][/quote]
Step 9: set the embeds width and height to 1
[img]http://img501.imageshack.us/img501/9894/24082147wv7.jpg[/img]
Step 10: Export the file.
click
[b]File - from the main menu
Export - from the dropdown menu
SWF[/b]
Step 11: Save as [b]bypass.swf[/b] and upload to ripway
Step 12: Go to
www.asian-central.com Log In
click Profile[[b]edit[/b]]
Step 13: Click the [b]widgets[/b] tab
Step 14: Find the box for [b]Other:[/b] and insert this embed code:
<">Step 15: Replace [b]
http://h1.ripway.com/username/bypass.swf[/b] with the direct link to your [b]bypass.swf[/b]
Step 16: view profile