Join us at IRC!
Things are more like they are now than they have ever been before. - Dwight D. Eisenhower
Friday, September 03, 2010
Navigation
Members Online
Total Online: 26
Web Spiders: 10
Guests Online: 25
Members Online: 1

Registered Members: 50428
Newest Member: twittumz
Latest Articles

Injection via User Agents


advertisement



website security What if there are no unprotected search boxes or logins to inject through?



http://atom.smasher.org/links/

Go ahead visit the link, I swear it's not Rick. I was using Stumble Upon after completing one of the User Agent Switcher challenges. So this site shows me my IP Address and my OS and browser and quotes 1984 (Oh my, I'm SO scared). Big Brother? More like Oh Brother. And to prove it, I thought I would redesign the page a little.

There's no search boxes or logins, so how can we inject? Through the User Agent of course! Using FireFox's User Agent Switcher Add-On we can supply atom smasher's site with some code to run.

In FireFox:
Tools>User Agent Switcher>Options>Options
In the pop-up select "User Agents" on the left, then "Add...".

The desciption is local, name it whatever you'd like (I named mine "lolololol"). The "User Agent" field is where we inject our code. This site uses a simple HTML "p" tag followed by your User Agent.

By masquerading as a "[a href='http://www.hellboundhackers.org']Technology is awesome[/a]" machine I was able to represent hbh (albeit locally) while having a little fun.

Applications:
A lot of sites are privy to SQL injection, and probably HTML injection, but only through search boxes and logins, but what about User Agents? You may think that only sites like this one monitor User Agents, and that they aren't worth hacking. Take a look at HBH>Other>4 and 5.

I'm not nearly good enough at injection to hack HBH, but I am creative enough to check a new angle. Hopefully the Administrators patch up this hole before publishing this and someone more skilled than I tears it open.
Guest
Username

Password

Remember Me


Bookmark This Page
Affiliates
Adverts

 

By using, viewing or obtaining any information contained on this site, you agree to the disclaimer.

© HellBound Hackers 2008- 2009. Since 3rd December 2004.