Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Basic 26


ghost's Avatar
0 0

I think i am doing it right. I write the "code" and then a window pops out , but i am not getting any points. I will be very happy if i can pm someone with what i am doing.


Uber0n's Avatar
Member
0 0

Sure, you can PM me :)


ghost's Avatar
0 0

do you mind me pm'ing you too :P?


ghost's Avatar
0 0

Same here, the alert pops up, but no points received.


ghost's Avatar
0 0

i dont even know anything about this window :S


ghost's Avatar
0 0

I have to simplify my injection somehow….:(


ghost's Avatar
0 0

you can pm me if u like


ghost's Avatar
0 0

I don't know if you were talking to me or djdotti, but i pm'ed Uber and he told me i need to find a way to simplify it. I'm just trying to think how i can do this.


ghost's Avatar
0 0

to anyone who needs help lol.


ghost's Avatar
0 0

I could you some.


ghost's Avatar
0 0

Yes nights_shadow think on what Uber has said to you. I think you are making the same mistake like i was doing because he said me the same thing ;)


ghost's Avatar
0 0

Okay ,, i need help i couldn't get whatever you guys are talking about :angry:

i read about xss and bbcode exploits/injection

i got some sample codes but it doesn't work the BBcode that "doesn't work":right:

what exactly should i learn here .. (xss/css) , JS ?!

and could you point me to articles or websites that would teach me how the exploit work

Oh and another thing to be sure about .. is IE7 blocking this kind of (exploit/code) :right:

thanks


ghost's Avatar
0 0

flame_1221 wrote: This will greatly help you;): http://www.hellboundhackers.org/articles/748-CSS-XSS.html

uhh ,, what if i have no experience at all in css-xss

i don't seem to get it !

i did something that viewed the right list of HBH where it says:

you have xxx points -My Profile-

avatar

Edit Profile Private Messages Logout

i viewed all that list in the test thread table ..

honestly i have no idea what i am doing :whoa:

But i want to B)

Thanks


flame_1221's Avatar
nobody
0 0

You can PM me:)


ghost's Avatar
0 0

flame_1221 wrote: You can PM me:)

PM Sent :happy:


ghost's Avatar
0 0

Hi! i was able to display a centered, red, bold 'TEST' string on the table with a pop-up alert containing the session cookie on load but after closing it, nothing happens… any tips on what step i'm still missing? Thanks.


ghost's Avatar
0 0

I found one that worked on FF too. Why the hell only the IE one is accepted?


flame_1221's Avatar
nobody
0 0

I do it in ff and had found several that makes pop up in IE but did not accepted in the challenge:p


ghost's Avatar
0 0

quangntenemy wrote: I found one that worked on FF too. Why the hell only the IE one is accepted? Because this challenge isn't focused on ALL the known XSS vectors but just on one that works only on MS IE


ghost's Avatar
0 0

There is an article on HBH that basicly gives you the challenge. This artile is also posted in another thread on this same mission.