Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 593 Vote(s) - 3.53 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Image IP Logger - Track any image

#1
As all may know i normally make a thread using the following elements. A image of the program, some text describing what it does, a download link and a virus scan analysis. Recently i found out that is possible to track users info (IP, OS, Browser) without the forum admin consent, this can be done by using the program Image IP Logger. This little program generate a image link that can be posted anywhere and track the visitors.

This can be used into two diferent ways. The first is to check if the stats match by seeing the number of views and compare with Image IP Logger image stats. The second is to track users that read the thread and construct a list about it.

Since this is beyond the scope of the admin, this type of information isn't normally given away by the admin and some forums even mask the ip to protect users but this won't work if you are using Image IP Logger images. This information will get revealed.

Currently i only saw a forum that is aware of this and have blocked images.
Reply

#2
Quote:Recently i found out that is possible to track users info (IP

You will not obtain"user" Information via an IP address. Your ISP owns your external/public/WAN IP address hence any Information collected or any Lookups performed (geo coordinates etc) will be that of the ISP. The Browser's user agent Is easily obtained via a JavaScript code using the window.navigator object. Same with the OS, easily obtainable.

That aside, I'm quite Interested to see how Image IP Logger performs.
Reply

#3
What you can do is, put a phishing link inside an IP-Grabber and successfully works.
If you are into hacking and shit, this is very useful if the target doesn't know what hacking is but, here is the scope.

(FYI, all website based so, nothing about hosting from your own machine or etc)
The phishing link is inside the IP grabber since, for you to know that they clicked the link, you will need the IP Grabber which will alert you that, they clicked the link. From there, if you don't get the credentials, they then know it is a fake website but, you still have there IP, BROWER, OS. It's more a double attack into 1.
Reply

#4
Quote:(06-19-2018, 04:16 PM)hacxx Wrote:

[To see links please register here]

You have missed the point you cannot add JavaScript to a thread.

I didn't say It could.

My post was based on general terms, not specifics.
Reply

#5
Quote:(06-19-2018, 11:48 AM)Mimiakira Wrote:

[To see links please register here]

What you can do is, put a phishing link inside an IP-Grabber and successfully works.
If you are into hacking and shit, this is very useful if the target doesn't know what hacking is but, here is the scope.

(FYI, all website based so, nothing about hosting from your own machine or etc)
The phishing link is inside the IP grabber since, for you to know that they clicked the link, you will need the IP Grabber which will alert you that, they clicked the link. From there, if you don't get the credentials, they then know it is a fake website but, you still have there IP, BROWER, OS. It's more a double attack into 1.

No, that's not what i mean. All the OP needs is the user to view the thread and the information is logged. You don't need a IP-Grabber like

[To see links please register here]

. Just an image to show to the user and you can log the info (ip, browser, os).
Reply

#6
Quote:(06-19-2018, 11:01 AM)mothered Wrote:

[To see links please register here]

The Browser's user agent Is easily obtained via a JavaScript code using the window.navigator object. Same with the OS, easily obtainable.

That aside, I'm quite Interested to see how Image IP Logger performs.

You have missed the point you cannot add JavaScript to a thread. For example your image
is clickable and with "Image IP Logger" you can convert to another link that will log the user info and email it to you. Each time a user view the thread their info will be logged.
Reply

#7
Quote:(06-19-2018, 04:20 PM)mothered Wrote:

[To see links please register here]

Quote: (06-19-2018, 04:16 PM)hacxx Wrote:

[To see links please register here]

You have missed the point you cannot add JavaScript to a thread.

I didn't say It could.

My post was based on general terms, not specifics.

This program is a particular case, i just got the idea, tried, tested and it works. Maybe MyBB needs an update when grabbing external images...
Reply

#8
Quote:(06-20-2018, 05:57 AM)mothered Wrote:

[To see links please register here]

Quote: (06-19-2018, 04:28 PM)hacxx Wrote:

[To see links please register here]

This program is a particular case, i just got the idea, tried, tested and it works.

How do I get my hands on this tool?

You could ask Santa? haha jk :smile:

I'm sure it's on the net for sure.
Reply

#9
Quote:(06-19-2018, 04:28 PM)hacxx Wrote:

[To see links please register here]

This program is a particular case, i just got the idea, tried, tested and it works.

How do I get my hands on this tool?
Reply

#10
Quote:(06-20-2018, 06:08 AM)Mimiakira Wrote:

[To see links please register here]

I'm sure it's on the net for sure.

Probably so, I've yet to check.

If the tool performs as described, to prevent the said Information from being leaked, simply use a VPN, hard-code the DNS servers (In the event of a DNS leak), add DNS encryption both primary & secondary and change the browser's user agent. I've changed the latter (on all browsers) to Safari and the OS to the Mac OS X 10.13. Of course, I've selected a user agent that's completely different to what I'm using.

It will not change the screen resolution, but

[To see links please register here]

does the job. It's only temporary, meaning the app must be active, so too with the browser session but It does suffice when dedicatedly navigating within the same session.
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through