I've already injected to eykalsyamim's page before & he doesnt know anything...
only viewers can see the alert
[/quote]
LOL 
































thats so
brb,,want to LOL
Last edited by feruzz (2008-06-07 11:48:40)
cross site scripting. Powerful yet fun.
very dangerous
[/quote]
wew..
deleted??
what did u delete pakcik feruzz??
next time I will be careful
@bang July
nothing....
I just made the XSS box
easy to inject the XSS LOL
but I cant publish in this thread
here's screenshot
[spoiler][img]http://h1.ripway.com/feruzz/friendster/photo/xssbox.PNG[/img][/spoiler]
Last edited by feruzz (2008-06-07 11:59:19)
easy to inject the XSS LOL
but I cant publish in this thread
here's screenshot
[spoiler][url]http://h1.ripway.com/feruzz/friendster/photo/xssbox.PNG[/url][/spoiler][/quote]
wew..
I also have found new js linker and css linker through media box that compatible in all browsers..
But...I can't post it here..
but still no luck in Media box
but still no luck in Media box[/quote]
wew..
hahahahaaaa..
Let's start inject malicious codes in FS TEAM profile..
I just want to test if this method works...
I dont care if my test page will be suspended lol
Here is the link
[b][url]http://profiles.friendster.com/friendster[/url][/b]
easy to inject the XSS LOL
[/quote]
make life easier 
[b]>>feruzz[/b]
pakcik feruzz..where are u??
I found something
<">if you put the codes into media box it will not be filtered but it can not be read
I put the linker from ur tag image linker
I think we need to add some character in it to make it works in media box..
[b]additional[/b]
some dangerous CSRF bugs can be used to hack account..
<">Try to send the codes as comment to ur another account..
after you approve it you'll be log out automatically..
damn..it's so dangerous..
we can use it to change other usernames and passwords through [b].html form[/b]...
Just beware !!!!!
Last edited by TA Juleigtin Siahaan (2008-06-08 09:55:05)
Last edited by xavierkym (2008-06-12 18:38:30)
[/quote]
It's like the WVM. If you apply an alert code on the php or htm file. The alert of the iframe comes out externally. The problem is how can we make the content of the iframe external in general, affecting the dom and style externally as well.
Last edited by Ephemeral (2008-06-12 23:41:42)
http://profiles.friendster.com/xavetesting
3 Alerts coming from different holes.
But I'm a bit worried in the new linker I've found.. It might be filtered by Firefox 3, since most people will be downloading Firefox 3 on the release date (June 17).
I hope it won't be filtered.
Last edited by xavierkym (2008-06-15 12:11:26)
Yeah I hope it won't get filtered.
Last edited by Ephemeral (2008-06-15 02:40:28)

Oh yeah, the linker I discovered (Who I want to meet linker) is working in Firefox 3. 
Last edited by xavierkym (2008-06-15 19:30:21)
[url=http://friendster.com/feruzz]backup linker[/url]
btw only Firefox 3 implement the getElementsByClassName which would be the fastest
Last edited by feruzz (2008-06-16 05:29:14)