Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 447 Vote(s) - 3.43 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[♦][SHOW] XSS Finds

#1
Here is a small collection of my recent Cross Site Scripting finds. They are all
in relatively large websites or corporations and were found in the space of a
few days. The fact that they were all found so fast made me worried yet proud.
I posted these on Pastebin & HF and only there. Anyone else taking credit for
any of these is a complete failure. @M4Y (Twitter) or /u/lul (Pastebin)

1. BBC
Site:

[To see links please register here]

Image:

Ranking: 48 Globally.

2. European Parliament
Site:

[To see links please register here]

Image:

Ranking: 911 Globally.

3. Adidas
Site:

[To see links please register here]

Image:

Ranking: 4302 Globally.

4. Life's Good
Site:

[To see links please register here]

Image:

Ranking: 1905 Globally.

5. Manchester United FC
Site:

[To see links please register here]

Image:

Ranking: 2547 Globally.

6. Dollar Files
Site:

[To see links please register here]

Image:

Ranking: 2806707 Globally.

7. Mclaren
Site:

[To see links please register here]

Image:

Ranking: 91003 Globally.

8. Hyundai
Site:

[To see links please register here]

Image:

Ranking: 359378 Globally.

9. LOC Gov
Site:

[To see links please register here]

Image:

Ranking: 4116 Globally.

10. 192
Site:

[To see links please register here]

Image:

Ranking: 3405 Globally.

11. Brazzers
Site:

[To see links please register here]

Image:

Ranking: 1074 Globally.

12. Adfocus
Site:

[To see links please register here]

Image:

Ranking: 1347 Globally.

13. Adfly
Site:

[To see links please register here]

Image:

Ranking: 88 Globally.

14. Enjin (All Boards)
Site:

[To see links please register here]

Image:

Ranking: 7215 Globally.

15. Michigan University
Site:

[To see links please register here]

Image:

Ranking: 6116 Globally.

16. Duke University
Site:

[To see links please register here]

Image:

Ranking: 8517 Globally.
Reply

#2
Nice! And I think all the XSS founded should be posted here? Well I found one,but have not done xss in a while:
Site: Edmodo.com
Picture:

[To see links please register here]

<- Totally True
Reply

#3
A lot of these were found already before your post. I found a few before too. But good job nevertheless. It doesn't matter if you're the first or not. Finding them yourself is the key :wink:

Good work!
Reply

#4
Quote:(10-05-2012, 06:57 AM)Ultimatum Wrote:

[To see links please register here]

A lot of these were found already before your post. I found a few before too. But good job nevertheless. It doesn't matter if you're the first or not. Finding them yourself is the key :wink:

Good work!

This post was actually a combination of two threads I made on HF. I found
them a few weeks ago and sadly a few people have been taking credit of
new ones alike the Brazzers login XSS. Some were already found such as
the Manchester XSS but I'm not too concerned. They were quite large finds.
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through