Archive Pages Design$type=blogging

Tutorial JavaScript Injection And Cheatcodes

JAVA SCRIPT INJECTION:- Summary: JavaScript injection is a little technique that allows you to alter a sites contents without actually ...


JAVA SCRIPT INJECTION:-

Summary:

JavaScript injection is a little technique that allows you to alter a sites contents without actually leaving the site. This can be very useful when say, you need to spoof the server by editing some form options. Examples will be explained throughout.

Using JavaScript a user can modify the current cookie settings. This can be performed with some basic JavaScript commands. To view the current contents of your current cookies, use the following JavaScript command. Put this in your browser's URL bar.

javascript:alert(document.cookie);


Contents:


  1. Injection Basics
  2. Cookie Editing
  3. Form EditingI. 

Injection Basics:
JavaScript injections are run from the URL bar of the page you are visiting. To use them, you must first completely empty the URL from the URL bar. That means no http:// or whatever.

JavaScript is run from the URL bar by using the javascript: protocol.\ but if you are a JavaScript guru, you can expand on this using plain old JavaScript.

The two commands covered in this tutorial are the alert(); and void(); commands. These are pretty much all you will need in most situations. For your first JavaScript, you will make a simple window appear, first go to any website and then type the following into your URL bar:

Code:

javascript:alert('Hello, World');


You should get a little dialog box that says "Hello, World". This will be altered later to have more practical uses. You can also have more than one command run at the same time:

Code:
javascript:alert('Hello'); alert('World');


This would pop up a box that said 'Hello' and than another that says 'World'.

2. Cookie Editing

First off, check to see if the site you are visiting has set any cookies by using this script:

Code:
javascript:alert(document.cookie);


This will pop up any information stored in the sites cookies. To edit any information, we make use of the void(); command.
Code:

javascript:void(document.cookie="Field = myValue");

This command can either alter existing information or create entirely new values. Replace "Field" with either an existing field found using the alert(document.cookie); command, or insert your very own value. Then replace "myValue" with whatever you want the field to be.

For example:
Code:
javascript:void(document.cookie="Authorized=yes");


Would either make the field "authorized" or edit it to say "yes"... now whether or not this does anything of value depends on the site you are injecting it on.

It is also useful to tack an alert(document.cookie); at the end of the same line to see what effect your altering had.

3. Form Editing


Sometimes, to edit values sent to a given website through a form, you can simply download that HTML and edit it slightly to allow you to submit what you want. However, sometimes the website checks to see if you actually submitted it from the website you were supposed to. To get around this, we can just edit the form straight from JavaScript.

Note: The changes are only temporary, so it's not use trying to deface a site through JavaScript injection like this.

Every form on a given webpage (unless named otherwise) is stored in the forms[x] array. where "x" is the number, in order from top to bottom, of all the forms in a page. Note that the forms start at 0, so the first form on the page would actually be 0, and the second would be 1 and so on.

Lets take this example:
Code:
<form action="http://www.website.com/submit.php" method="post">
<input type="hidden" name="to" value="admin@website.com">


Note: Since this is the first form on the page, it is forms[0]

Say this form was used to email, say vital server information to the admin of the website. You can't just download the script and edit it because the submit.php page looks for a referrer. You can check to see what value a certain form element has by using this script.
Code:

javascript:alert(document.forms[0].to.value)


This is similar to the alert(document.cookie); discussed previously. In this case, It would pop up an alert that says "admin@website.com"

So here's how to Inject your email into it. You can use pretty much the same technique as the cookies editing shown earlier:
Code:
javascript:void(document.forms[0].to.value="xyz@xyz.com")


This would change the email of the form to be "xyz@xyz.com". Then you could use the alert(); script shown above to check your work. Or you can couple both of these commands on one line.

Other codes:


javascript:alert("XSS By Priyanshu");

javascript:alert(0);

javascript:alert(document.forms[0].to.value="something")

document.body.contentEditable='true';document.designMode='on';void0

To move things around on the webpage

Source: http://blog.hackersonlineclub.com/

COMMENTS

BLOGGER : 1
Loading...
Tên

.htaccess #OPISIS 000WebHost HACKED 18+ 4rum Addons Affliates AIO Sofware Android Anti AV Anti DDos Anti Dos Anti SQLi Anti Virus App ASCII Art ASP Attack Auto AutoGame AutoIT backdoor BackTrack Bin Checker Bind Bitcoin Blog Tricks Boot Botnet Brute Bug Bypass C C# C++ Carder Cash Out CCN CCV CD CEH CF Charset check Check PayPal Checker Tools CHMOD Clone Scripts Cloudflare Code Code Web Codecanyon Coding Collation UTF-8 Command Cookie Cpanel cPanel Tools Crack Crack Tools Cracker Cracking Credit Card Cross site CSRF CSS Data DDos Decode Decrypter DeepWeb Deface DNS DNS Hijacking Domain Dork Dork SQL Dork Vulnerability Dos Dos-Deflate Drop DropBox Ebook Ebooks Email Email Spam Emal Encode Encryption error Exploit Exploit - Vulnerability Facebook Fake Page File Inclusion File Injections Filter Firewall Fix lỗi Flash Flood Footprinting Freezer FTP Funny Game Games Gift Card Girls Giveaway Gmail Google Hack Google Proxy Grabber Hack Facebook Hack Game Hack password Hack Shop Hack Wifi Hacker Hackig Hacking HackNet Hash Hijacking Hosting HTML HTML5 ICANN ID Card IFrame Injection Attacks Injection iOS IP IRC IT Java Joomla JS Kali Kali Linux Kaoli Linux KAV Keylogger KIS LAN LFI Linux Local Attack Mã hoá Maintaining Access Make Money Malware Metasploit Method MITM MMO MyBB MySQL NEWBIE News NginX Nmap NNLT Operating System Operation Oracle Other PageRank Parser PayPal Pentest Perl phần mềm Phishing Phone Photoshop PHP PHP Script Ping Web Plugin Profile Program Programmer Proxy PTC pts Pumper Python RATS Remote Remote Desktop reverse engineering RFI Roboo Scam Scam Page Scan Scan Vps Scanner Tools Scource Scoure Search Security Sell SEO Serial Key Sever Share Code Shell Shipper Shipping Shipping TUT Skype Sniff Social Networking Socks Socks Proxy Source Spam Spaw Spoofer Spy SQL SQL ASPX SQL Basic SQLi SQLMap SSH SSL SSLstrip Tạo Website Test Theme - Wallpaper Thủ thuật Thủ thuật Facebook thủ thuật máy tính thủ thuật web ToolKit Tools Tools Hack Tools Pack Tricks Trojan TUT TUT UG TUTORIAL Ubuntu UG Up shell vBulletin Virus visual basic.net VPN VPS VPS Free Vulnerability WAF Warez Warning Webdav Website Website hữu ích Widget Wifi Win 7 Win 8 Win 8.1 Windows Wireless Wireshark Wordlist WordPress Worm WPA Key Xâm nhập máy tính Xenforo XHTML XSHM XSS Zipcode
false
ltr
item
Joker™ Blog: Tutorial JavaScript Injection And Cheatcodes
Tutorial JavaScript Injection And Cheatcodes
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivCe7Qpg7l6K9eUViEEmciG5YDQ3jbEEEbnw-Jms2cRNMS0SvC1Cmz2JppKdQtFYLqbohmlrEU8QzEIbtHMrA6PlE0BcK8_wzAfA2f8aqRBQBHGtfXemKtm3ysd6yy0g3_K59h77l5rPkc/s1600/JS+injection.png
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivCe7Qpg7l6K9eUViEEmciG5YDQ3jbEEEbnw-Jms2cRNMS0SvC1Cmz2JppKdQtFYLqbohmlrEU8QzEIbtHMrA6PlE0BcK8_wzAfA2f8aqRBQBHGtfXemKtm3ysd6yy0g3_K59h77l5rPkc/s72-c/JS+injection.png
Joker™ Blog
https://jdkgreyhat.blogspot.com/2014/05/tutorial-javascript-injection-and.html
https://jdkgreyhat.blogspot.com/
http://jdkgreyhat.blogspot.com/
http://jdkgreyhat.blogspot.com/2014/05/tutorial-javascript-injection-and.html
true
6952006105369371103
UTF-8
Not found any posts VIEW ALL Read More Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago