Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

permananet xss


ghost's Avatar
0 0

i have view some pages that have been xss'ed, and the attack seems to have stayed permanent (such as someone makes a script to alert someone of a message). my question is how to make my xss injections last on a site (i hope that this wording makes sense, and if it doesnt, then please respond and i will hopefully clarify it).


ghost's Avatar
0 0

well if you posted something in a forum for example, then it will stay there until an admin deletes your code you entered.


ghost's Avatar
0 0

Otherwise you can leave xss in your signature until admin come ask you to remove it if you dont want to get ban … It happen to me and i haven't got HOF entry for my super irc link injection :( and this xss still work.


ghost's Avatar
0 0

dude insidious, t35's exploit has been around forever… just in case if you were trying to say it was your own.


Mr_Cheese's Avatar
0 1

Arto_8000 wrote: It happen to me and i haven't got HOF entry for my super irc link injection :( and this xss still work.

thats because if you want something done on HBH you need to bug me 24/7 so i actually get around to doing it. most the times im either busy or doing something else for HBH so i end up forgetting.

keep pestering me and keeping up the pressure and i'll do it ;)


ghost's Avatar
0 0

Mr_Cheese wrote: thats because if you want something done on HBH you need to bug me 24/7 so i actually get around to doing it. most the times im either busy or doing something else for HBH so i end up forgetting.

keep pestering me and keeping up the pressure and i'll do it ;)

//bug & pressure mode// cheese what about my little side-quest for hbh? Lemme guess, you don't know what I am talking about xD. Shall I just re-send that .zip file? //mode=off//


ghost's Avatar
0 0

could someone possibly show me how to exploit t35? i have googled it, but nothing worth looking at has come up


thk-geo's Avatar
Member
0 0

Arto_8000 wrote: Otherwise you can leave xss in your signature until admin come ask you to remove it if you dont want to get ban … It happen to me and i haven't got HOF entry for my super irc link injection :( and this xss still work.

You didnt find this anyway.