Started by Caiky

Caiky
That one girl who writes tutorials

10-22-2017, 07:14 AM

Finding a Vulnerable Website

Targeting a certain website when using XSS is tedious work. You must go to every single page of the website to be able to find just one vulnerable page. Because of that, we will just find random vulnerable websites on google!
You would put a dork into google, such as 
So, in the google URL bar, you would type inurl: insertdorkhere to find a vulnerable website. After searching google for a vulnerable page, go to it, and find some sort of input field such as a password/username, search, etc. Lets just type in "Caiky" without the quotes.

 After we press enter and wait for the response, we can see in this case that it says "Hello Caiky." Lets see if the website "sanitizes" our code that we inject into the website. Enter in <script> and press enter. Now lets go ahead and open up inspect element, and find where that "Hello <script>" is.
It can be a large amount of different things, but in our case it will look like
Now, if <script> stays the exact same, that means the website does not sanitize! If they did, it would look something like this: 

This means this page is completely vulnerable to XSS!

Exploiting the Vulnerability.

Now its time for the fun stuff! We can enter any javascript we want into the box, and it will run. For an example, if we enter the javascript from my DIY Mine on Computers Through a Website tutorial, we can mine on anyone who inputs that code. Obviously this isn't the best for mining, but this is just a non-persistent XSS attack. This still has thousands of useful malicious scripts we can inject, but mining would be useless.

Persistent or Stored XSS will stay on the page you put the script on. This is where coinhive's miner truly comes in strong.
Imagine a forum post that is vulnerable. Any person who visits that post will have their browser infected with the miner until they close it, which personally I almost always have a browser window open. If I got coinhive's miner injected into my browser, off my computer alone you would make $1-2 a day. One computer. $1-2 a day. If you target forums or websites that normally have visitors with good computers, with just 20 infections you could be making upwards of $20 a day.

Of course, if you are able to find some sort of exploit where you can just download a file onto a person's computer and run it without their knowledge somehow, you can inject that javascript into a website and get infect after infect for your botnet, RAT, or other malicious software. We can steal the identity of people visiting the website and sensitive data, such as credit card details or accounts. You can bypass restricted areas of a website, such as VIP or donor only sections. You can deface the website, mine, DOS skid xd, or even just completely hijack their computer.


I'm not responsible for whatever you do with this yadda yadda yadda made for the community of Corrupt Zone.

Hope you guys enjoyed! Leave a post if you found this useful, it motivates me to make more tutorials  Girl_pinkglassesf
Xpad
Junior Member

10-22-2017, 11:32 PM
Thank u hq boas was looking for a tut
Cremate

10-23-2017, 02:04 PM
thanks now i can css my hack accont
Dox
Cyber Security Student

10-23-2017, 06:07 PM
Pretty fucking HQ post my dude.
drillbyte
~# Contributor #~

10-24-2017, 07:45 AM
Thanks for this.
Have another idea for you.
alextheguyuwant
Junior Member

11-20-2017, 11:17 PM
Hidden? Post to reply?!?!?! ;(
skidly

11-20-2017, 11:24 PM
Thanks, lassie. I'll put this to good use.
Jax
Junior Member

12-05-2017, 02:14 AM
Cheers for this, going to try it out now! <3
