IT Security Team  
قدیمی 06-26-2010, 11:15 AM   #1
اعضای قدیمی
 
0xd41684c654 آواتار ها
 
تاریخ عضویت: Jun 2009
نوشته ها: 318
Thanks: 28
Thanked 168 Times in 100 Posts
پیش فرض Havij Persistent XSS (<=v1.10)



# Exploit Title: Havij Persistent XSS (<=v1.10)
# Date: 15/6/2010
# Author: hexon
# Software Link: [فقط اعضای سایت قادر به دیدن لینکها میباشند ]
# Version: 1.10 and below
# Tested on: Windows XP Service Pack 2 Professional, Windows 7
# Code : htttp://site.com/file.php?param=[XSS Code]


Havij Persistent XSS (<=v1.10)

By : Hkhexon ([فقط اعضای سایت قادر به دیدن لینکها میباشند ])


-------------
Vulnerability
-------------

Havij does not do any filtration in Target bar so XSS codes can be executed.
However , you need to find a site that is vulnerable to XSS and SQL
Injection.
The site cannot be vulnerable to just XSS only as Havij will stop working
as it cannot inject it.

Functions Affected:
-Save in Info
-Save Tables in Tables
-Save Data in Tables

------------
Exploitation
------------

Eventhough I said you need to find a site that is vulnerable to XSS and SQL
Injection,
There is also an exception to this.Instead,you can find a site vulnerable to
SQL Injection and use SiXSS to generate your desired XSS code.
You can also put the XSS code after the Vulnerable Parameter.

Of course, before that you would need to find the column count and string
column
and replace the String column with the XSS code.

For your acknowledge , String column is the column number where the data
produces
output at the site.

Example (Type it in Target and click Analyse):

------------
SiXSS Method
------------

http://localhost/sqli.php?sqli=-1337 union select
1,'',3
or you can also remove the quotes in the XSS code, it doesn't matter.
(Assume that Column count = 3 and String column = 2)

Or the simpler one without using SiXSS:
http://localhost/sqli.php?sqli=2

If magic_quotes or addslashes is on, it would make no difference as only the
quotes
are filtered and the code will still execute unless your XSS code has quotes
in it.

NOTE : You cannot use encoding like char() or hex as the html file generated
will not parse it into plain text and execute the code.

After that , you can do either the following:
-Click Save in Info and save the html file.
-Click Save Tables in Tables and save the html file.
-Extract some data by using Get Tables,then Get Columns,then Get Data,and
save the html file by using Save Data.

After html file has been generated, open it and your XSS code will execute.


This may look undangerous since the file is made inside your computer,
but almost all XSS techniques requires the attacker to trick users to go to
a
particular file of the site though. So, anything can happen , its just that
you need to be creative.

-----
Patch
-----

I had already notified the Author of Havij(r3dm0v3).

The reason why I do not have patch for this is that I do not have the
source of Havij so I'll let r3dm0v3 to do it himself.

----------
Queries ??
----------

Please email to [فقط اعضای سایت قادر به دیدن لینکها میباشند ].


0xd41684c654 آنلاین نیست.   پاسخ با نقل قول
The Following User Says Thank You to 0xd41684c654 For This Useful Post:
nader_mo2005 (07-20-2010)
قدیمی 06-26-2010, 01:23 PM   #2
مديريت بخش
 
b3hz4d آواتار ها
 
تاریخ عضویت: Feb 2010
نوشته ها: 32
Thanks: 50
Thanked 29 Times in 18 Posts
پیش فرض

خدا شفا بده بعضیارو واقعا.یه بار یادمه یه لینک دیدم که طرف اومده بود از C99 باگ ریپورت کرده بود...
b3hz4d آنلاین نیست.   پاسخ با نقل قول
قدیمی 06-26-2010, 02:55 PM   #3
اعضای قدیمی
 
0xd41684c654 آواتار ها
 
تاریخ عضویت: Jun 2009
نوشته ها: 318
Thanks: 28
Thanked 168 Times in 100 Posts
پیش فرض

نقل قول:
نوشته اصلی توسط b3hz4d نمایش پست ها
خدا شفا بده بعضیارو واقعا.ی

آمین.
0xd41684c654 آنلاین نیست.   پاسخ با نقل قول
قدیمی 06-26-2010, 10:30 PM   #4
مديريت بخش
 
r3dm0v3 آواتار ها
 
تاریخ عضویت: Dec 2009
نوشته ها: 186
Thanks: 6
Thanked 240 Times in 99 Posts
پیش فرض

این باگ (نمیدونم واقعا میشه گفت باگ یا نه؟!) بر طرف شده ولی هنوز منتشر نشده.
__________________
[فقط اعضای سایت قادر به دیدن لینکها میباشند ]
r3dm0v3 آنلاین نیست.   پاسخ با نقل قول
قدیمی 06-26-2010, 10:45 PM   #5
مديريت بخش
 
b3hz4d آواتار ها
 
تاریخ عضویت: Feb 2010
نوشته ها: 32
Thanks: 50
Thanked 29 Times in 18 Posts
پیش فرض

دقیقا به هیچ دردی نمیخوره.مگر در حالتی که با یه browser که نتونه درست cookie ها رو manage کنه باز شه و مشکل بشه باهاش ایجاد کرد که بازم اصلا تو ذهن نمی گنجه.
b3hz4d آنلاین نیست.   پاسخ با نقل قول
قدیمی 06-27-2010, 08:35 AM   #6
مديريت انجمن
 
Pejvak آواتار ها
 
تاریخ عضویت: Feb 2010
نوشته ها: 145
Thanks: 45
Thanked 264 Times in 91 Posts
Pejvak به Yahoo ارسال پیام
پیش فرض

چه حالي ميكنه با خودش D:

ویرایش توسط Pejvak : 06-27-2010 در ساعت 09:52 AM
Pejvak آنلاین نیست.   پاسخ با نقل قول
قدیمی 07-20-2010, 01:43 AM   #7
عضو جديد
 
nader_mo2005 آواتار ها
 
تاریخ عضویت: Jul 2010
نوشته ها: 2
Thanks: 1
Thanked 0 Times in 0 Posts
Yahoo1 مرسید

مرسید
nader_mo2005 آنلاین نیست.   پاسخ با نقل قول
قدیمی 07-20-2010, 01:45 AM   #8
عضو جديد
 
nader_mo2005 آواتار ها
 
تاریخ عضویت: Jul 2010
نوشته ها: 2
Thanks: 1
Thanked 0 Times in 0 Posts
پیش فرض

نقل قول:
نوشته اصلی توسط 0xd41684c654 نمایش پست ها


# Exploit Title: Havij Persistent XSS (<=v1.10)
# Date: 15/6/2010
# Author: hexon
# Software Link: [فقط اعضای سایت قادر به دیدن لینکها میباشند ]
# Version: 1.10 and below
# Tested on: Windows XP Service Pack 2 Professional, Windows 7
# Code : htttp://site.com/file.php?param=[XSS Code]


Havij Persistent XSS (<=v1.10)

By : Hkhexon ([فقط اعضای سایت قادر به دیدن لینکها میباشند ])


-------------
Vulnerability
-------------

Havij does not do any filtration in Target bar so XSS codes can be executed.
However , you need to find a site that is vulnerable to XSS and SQL
Injection.
The site cannot be vulnerable to just XSS only as Havij will stop working
as it cannot inject it.

Functions Affected:
-Save in Info
-Save Tables in Tables
-Save Data in Tables

------------
Exploitation
------------

Eventhough I said you need to find a site that is vulnerable to XSS and SQL
Injection,
There is also an exception to this.Instead,you can find a site vulnerable to
SQL Injection and use SiXSS to generate your desired XSS code.
You can also put the XSS code after the Vulnerable Parameter.

Of course, before that you would need to find the column count and string
column
and replace the String column with the XSS code.

For your acknowledge , String column is the column number where the data
produces
output at the site.

Example (Type it in Target and click Analyse):

------------
SiXSS Method
------------

http://localhost/sqli.php?sqli=-1337 union select
1,'',3
or you can also remove the quotes in the XSS code, it doesn't matter.
(Assume that Column count = 3 and String column = 2)

Or the simpler one without using SiXSS:
http://localhost/sqli.php?sqli=2

If magic_quotes or addslashes is on, it would make no difference as only the
quotes
are filtered and the code will still execute unless your XSS code has quotes
in it.

NOTE : You cannot use encoding like char() or hex as the html file generated
will not parse it into plain text and execute the code.

After that , you can do either the following:
-Click Save in Info and save the html file.
-Click Save Tables in Tables and save the html file.
-Extract some data by using Get Tables,then Get Columns,then Get Data,and
save the html file by using Save Data.

After html file has been generated, open it and your XSS code will execute.


This may look undangerous since the file is made inside your computer,
but almost all XSS techniques requires the attacker to trick users to go to
a
particular file of the site though. So, anything can happen , its just that
you need to be creative.

-----
Patch
-----

I had already notified the Author of Havij(r3dm0v3).

The reason why I do not have patch for this is that I do not have the
source of Havij so I'll let r3dm0v3 to do it himself.

----------
Queries ??
----------

Please email to [فقط اعضای سایت قادر به دیدن لینکها میباشند ].


نقل قول:
نوشته اصلی توسط b3hz4d نمایش پست ها
خدا شفا بده بعضیارو واقعا.یه بار یادمه یه لینک دیدم که طرف اومده بود از C99 باگ ریپورت کرده بود...
ای بابا
nader_mo2005 آنلاین نیست.   پاسخ با نقل قول
پاسخ

ابزارهای موضوع
نحوه نمایش

مجوز های ارسال و ویرایش
شما نمیتوانید موضوع جدیدی ارسال کنید
شما امکان ارسال پاسخ را ندارید
شما نمیتوانید فایل پیوست در پست خود ضمیمه کنید
شما نمیتوانید پست های خود را ویرایش کنید

BB code هست فعال
شکلک ها فعال است
کد [IMG] فعال است
کد HTML غیر فعال است
Trackbacks are فعال
Pingbacks are فعال
Refbacks are فعال



اکنون ساعت 06:00 AM برپایه ساعت جهانی (GMT - گرینویچ) +4.5 می باشد.


Powered by vBulletin
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd

كليه حقوق اين وب سايت براي ITSecTeam محفوظ ميباشد


Content Relevant URLs by vBSEO ©2011, Crawlability, Inc.