blizzard.com XSS - fixed within a day menu
100% Up to 1000$
4.9/5
150% Up to 200$ & 20 Freespins
4.8/5
Up to 1 BTC
4.9/5
20% Cashback
4.8/5
Up to 5 BTC
4.8/5
100% Up to 1 BTC
4.7/5
Up to 5 BTC
4.7/5
110% Up to 1 BTC
4.6/5

User Tag List

Page 2 of 3 FirstFirst 123 LastLast
Results 16 to 30 of 36
  1. #16
    Remus's Avatar Banned

    Reputation
    402
    Join Date
    Nov 2007
    Posts
    1,697
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    blizzard.com XSS - fixed within a day
    that is the best option ^

    blizzard.com XSS - fixed within a day
  2. #17
    reduction's Avatar Member
    Reputation
    19
    Join Date
    Jan 2009
    Posts
    22
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Obama View Post
    If you think it is genuinely good. Then give it to a high ranked user such as myself and I will post it in a higher section and direct all rep to be given to you.
    Thank you for your offer. I will take you up on it if I ever find something.

  3. #18
    Y R U A NUB ?'s Avatar Banned
    Reputation
    103
    Join Date
    Nov 2007
    Posts
    436
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by TunakTun View Post
    Someone ban this troll please, every single post he has made is completely negative, ignoring all of the forums rules.
    Yes please, listen to this completely mindless child and ban me.

  4. #19
    ZombieSnail's Avatar Active Member
    Reputation
    15
    Join Date
    Sep 2008
    Posts
    23
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Please what is a XSS?

  5. #20
    Y R U A NUB ?'s Avatar Banned
    Reputation
    103
    Join Date
    Nov 2007
    Posts
    436
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by ZombieSnail View Post
    Please what is a XSS?
    Cross Site Scripting, it's a pretty common JavaScript vulnerability that can be abused for cookie stealing and such. You can also re-direct to other sites. Let's say you use this XSS exploit, you use something like where it's vulnerable, mostly in the search function. Then you can just encode the link and make it look as if it's on Blizzards real site, then it re-directs to your phisher, and the victim is ****ed.

  6. #21
    parinoia's Avatar Member
    Reputation
    27
    Join Date
    Jun 2007
    Posts
    220
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    How do you find the XSS? Do you just enter js codes until you hit something or is there an actual method to getting them?

  7. #22
    Y R U A NUB ?'s Avatar Banned
    Reputation
    103
    Join Date
    Nov 2007
    Posts
    436
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by parinoia View Post
    How do you find the XSS? Do you just enter js codes until you hit something or is there an actual method to getting them?
    Type this in the search function on the site you want to check:



    That should output a little box that says "IT WORKS!" if it works, and it's search function is vulnerable.

  8. #23
    parinoia's Avatar Member
    Reputation
    27
    Join Date
    Jun 2007
    Posts
    220
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Well I tried it on WoW Guild Rankings :: WoWProgress - World of Warcraft Rankings and History and got a normal looking search page with alert("IT WORKS!")" :: World of Warcraft Rankings and History." /> at the top, but I dont think that's what I want lol

  9. #24
    Y R U A NUB ?'s Avatar Banned
    Reputation
    103
    Join Date
    Nov 2007
    Posts
    436
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by parinoia View Post
    Well I tried it on WoW Guild Rankings :: WoWProgress - World of Warcraft Rankings and History and got a normal looking search page with alert("IT WORKS!")" :: World of Warcraft Rankings and History." /> at the top, but I dont think that's what I want lol
    Yeah, that's just a sign that it's not vulnerable. Try another site.

  10. #25
    Poiview1's Avatar Member
    Reputation
    1
    Join Date
    Mar 2009
    Posts
    64
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I don't suggest jumping into javascript and cookie jacking until you understand the language first, atleast to an extent. That was a beautiful find, a shame that it has been fixed.

    Good luck,
    -Ku

  11. #26
    ZombieSnail's Avatar Active Member
    Reputation
    15
    Join Date
    Sep 2008
    Posts
    23
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Y R U A NUB ? View Post
    Cross Site Scripting, it's a pretty common JavaScript vulnerability that can be abused for cookie stealing and such. You can also re-direct to other sites. Let's say you use this XSS exploit, you use something like where it's vulnerable, mostly in the search function. Then you can just encode the link and make it look as if it's on Blizzards real site, then it re-directs to your phisher, and the victim is ****ed.
    Thank you very much for short and good explanation +Rep

  12. #27
    Ahskrew's Avatar Member
    Reputation
    35
    Join Date
    Oct 2007
    Posts
    182
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    to bad it got fixed

  13. #28
    Y R U A NUB ?'s Avatar Banned
    Reputation
    103
    Join Date
    Nov 2007
    Posts
    436
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by ZombieSnail View Post
    Thank you very much for short and good explanation +Rep
    Oh, thanks a bunch

  14. #29
    Intu's Avatar Banned
    Reputation
    95
    Join Date
    Feb 2009
    Posts
    303
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    LoL, you guys have no idea, Blizzard uses a php script that auto changes the link, its what banks use for online banking, paypal and ebay do it to. Shoot even I use it.

  15. #30
    Kallerballer's Avatar Active Member
    Reputation
    31
    Join Date
    Sep 2007
    Posts
    112
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    sad :/ .. we got a blizz on mmo ! who it is ... o.O ?

Page 2 of 3 FirstFirst 123 LastLast
All times are GMT -5. The time now is 08:41 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search