Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

Problem! - Cookie Logging


ghost's Avatar
0 0

hi, I've been reading the tutorial on xss cookie logging, and unfortunately the server is down, I am not be able to download the particular software to continue the tutorial, is there any other alternatives that may help? thnks

                           src=>down  "http://ccl.whiteacid.org/"

ghost's Avatar
0 0

crash_overide 2 wrote: hi, I've been reading the tutorial on xss cookie logging, and unfortunately the server is down, I am not be able to download the particular software to continue the tutorial, is there any other alternatives that may help? thnks

                           src=>down  "http://ccl.whiteacid.org/"

Haha its not a download its a cookie logger. If you know php code your own cookie logger. I used to use that site, it was awsome. R.I.P http://ccl.whiteacid.org/


ghost's Avatar
0 0

oh so the whole point is, to create that particular logger to be directed to the link "http://ccl.whiteacid.org/" right?


ghost's Avatar
0 0

crash_overide 2 wrote: oh so the whole point is, to create that particular logger to be directed to the link "http://ccl.whiteacid.org/" right?

No no no http://ccl.whiteacid.org/ is dead. Gone. (for now at least) The point is to log there cookies (by making someone click on a link that redirects there cookies most likely to your server ie phishing). You have to code some php to log cookies on your server. Than where ever the site is vuln to XSS put in something that will make the cookies redirect to your server. Make whom ever click that link. Than when you have successfully stolen there cookies go back to the site, change your cookies to the ones stolen and then BAM! You just stole some cookies :D.

EDIT: XSS is very powerful in the right hands ;) it's not limited to just stealing cookies. http://keepitlocked.net/archive/2008/06/17/quot-the-spy-who-hacked-me-quot-teched-2008-demo.aspx


xxSk1N_D33Pxx's Avatar
Member
0 0

Thank you skathgh420 for the link to the screencast. It was extremely informative and illustrates just how dangerous a cross site scripting exploit can be.


ghost's Avatar
0 0

xxSk1N_D33Pxx wrote: Thank you skathgh420 for the link to the screencast. It was extremely informative and illustrates just how dangerous a cross site scripting exploit can be.

No problem. Glad to share :D.


Uber0n's Avatar
Member
0 0

Does anyone know why WhiteAcid closed the CCL service? :right:


spyware's Avatar
Banned
0 0

Uber0n wrote: Does anyone know why WhiteAcid closed the CCL service? :right:

He didn't. Dreamhost killed his account because of ToShit stuff. He'll be back, though.


Uber0n's Avatar
Member
0 0

Thanks for the info spyware ^^