Imagination is more valuable than knowledge - Albert Einstein
Friday, November 21, 2008
Navigation
Donate
Has this website helped you?
px
If so, please donate a little to help out with hosting costs.
Members Online
Total Online: 51
Web Spiders: 7
Guests Online: 36
Members Online: 15

Registered Members: 36814
Newest Member: DHAYOR
Most Users online: 523
Latest Articles

Guestbook Hacking


advertisement



website security How to take control of Guestbooks, most commonly guestbook.html



Hacking Guestbooks

Guestbooks are one of the most easly and most common begginer hacks. Because Guestbooks allow users to submit their information onto the website.

So if a guestbook was to not filter html commands, then that information is submitted to the website!!! See where im going with this....

So if you were to input html into your guestbook entry, that will be uploaded to the website, thus giving you control of that page.

So, steps to take when hacking a guestbook:

see if its vunerable! You can do this by inputing tags like:

<plaintext> or <img src="javascblockedript:alert('noob')">

If you get a whole page of code (plaintext) or a message box saying "noob", then the page is vunerable.


So now you can attack the guestbook!

to make a message pop up on the screen, you inject javascblockedript into a <img> tag or a <scblockedript>, but sometimes [scblockedript] is disabled.

so a img tag would be like:
<img src="javascblockedript:alert('noob')">

or if you wanted to redirect the page, you can use another <img> tag:
<img src="javascblockedript:void(window.location=('http://www.google.com'))">
WoW, now that page redirects to your page! simpe huh!!

Be creative, any html command can work!

Happy Hacking.

HellBound Hackers is not responsible for any blackhat hacks you may do.

~ Mr_Cheese ~

Edit by Mr_Cheese: STOP TRYING TO HACK GUESTBOOKS IN MY NAME.
Guest
Username

Password

Remember Me


Bookmark This Page
Affiliates
Adverts

 


By using, viewing or obtaining any information contained on this site, you agree to the disclaimer.

© HellBound Hackers 2007- 2008. Since 3rd December 2004.