Ninjitsu-Technique.com/NinjaForum
September 07, 2010, 02:59:05 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Spam gone - hurray!
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: important!(maybe)  (Read 78 times)
st3alth
Full Member
***

Karma: +4/-0
Posts: 139


View Profile
« on: June 23, 2010, 11:03:07 AM »

ok. i have found an xss hole in the ninja_store search engine. http://ninjitsu-technique.com/ninja_store on that page, in the search box type <script>alert("this is an xss found by stealth");</script> and take a look.

this isn't big as far as i know but it could become a bigger issue/other holes may exist.

i noticed admin left, however if you can contact him let him know. the last thing we need is some jackass ,like shayden to actually learn how to exploit these things.

btw this is an example, the string could be other javascript as well.

just thought id put it out there.

update:i forgot to mention that at this stage it means nothing, other than bad coding of the search bar. dont be too worried about this, right now your fine, unless it leads to more vulns.
« Last Edit: June 23, 2010, 11:29:41 AM by st3alth » Logged

\\\"those who have the brightest light give off the darkest shadows\\\"-idk who
Avenger
Hero Member
*****

Karma: +34/-30
Posts: 1272



View Profile
« Reply #1 on: June 27, 2010, 08:09:13 PM »

nothing happened for me.
Logged

Quote from: X Calibur
And use the goddamn search button before posting a question.
Quote from: Kagebushi
Use the goddamn PM system rather than this forum

The Order of the Crimson Lotus is watching.
ShinobiWanKenobi
Hero Member
*****

Karma: +32/-106
Posts: 626


I act like shit don't phase me. It drives me crazy


View Profile
« Reply #2 on: June 28, 2010, 01:43:25 AM »

Sorry, no exploits can be done on the site that I know of.
Logged

st3alth
Full Member
***

Karma: +4/-0
Posts: 139


View Profile
« Reply #3 on: June 28, 2010, 10:33:03 PM »

yes it can. its not on the forum, its on the store. it works,i just did it try taking out the semicolon.
Logged

\\\"those who have the brightest light give off the darkest shadows\\\"-idk who
Ninja of Shadows
Sr. Member
****

Karma: +7/-3
Posts: 465


If you want to die, call me! xD Just kidding!


View Profile
« Reply #4 on: June 29, 2010, 12:33:22 AM »

lol try typing   <script>alert("This is sooooo cool!!");</script>  it's pretty cool
Logged

When negotiation fails, get stabby!

Quote from: Unknown
When all else fails, call your monkey!

Quote from: Ninja of Shadows
If you want to die, call me! xD

Ninjitsu is a way of life.
st3alth
Full Member
***

Karma: +4/-0
Posts: 139


View Profile
« Reply #5 on: June 29, 2010, 11:28:46 AM »

this site is very badly made. ive easily found three vulns. one in the store 2 in the forum. 1 is unexploitable(meaning you cant do anything with it.) the other is very dangerous. and im sure there are more.
be careful.
Logged

\\\"those who have the brightest light give off the darkest shadows\\\"-idk who
Pandemonium
Sr. Member
****

Karma: +4/-3
Posts: 415


View Profile
« Reply #6 on: July 01, 2010, 12:43:30 AM »

What kind of vulns?
Logged
st3alth
Full Member
***

Karma: +4/-0
Posts: 139


View Profile
« Reply #7 on: July 01, 2010, 08:51:57 AM »

the one in the store is xss. the avatar upload system is flawed ive already uploaded a couple shells. the next vuln is in conjunction with the avatar system. its LFI, meaning you can go to restricted files(i have yet to find the file paths).

p.s. the unexploitable vuln is actually exploitable(the avatar upload system)
Logged

\\\"those who have the brightest light give off the darkest shadows\\\"-idk who
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC Valid XHTML 1.0! Valid CSS!