Skip to main content

How to hack mostly websites with HTML Injection in 3 minutes.

                          Hacking website- HTML Injection


HTML Injection
HTML Injection is a vulnerability which occurs in web applications that allows users to insert html code via a specific parameter for example or an entry point. This type of attack can be used in combination with some sort of social engineering in order to trick valid users of the application to open malicious websites or to insert their credentials in a fake login form that it will redirect the users to a page that captures cookies and credentials. In this tutorial we are going to see how we can exploit this vulnerability effectively once it is discovered. For the needs of the article the Mutillidae will be used as the vulnerable application.


Vulnerable Form
Of course in this example there is an indication that this form is accepting HTML tags as it is part of the functionality of the application. A malicious attacker will think that he can exploit the users of this application if he set up a page that is capturing their cookies and credentials in his server. If he has this page then he can trick the users to enter their credentials by injecting into the vulnerable page a fake HTML login form. Mutillidae has already a data captured page so we are going to use this page for our tutorial
.
Mutillidae – Data Capture Page
Injecting HTML Code – Fake Login
Now we can inject HTML code that it will cause the application to load a fake login form.

.
Injecting HTML Code – Fake Login
.
Fake Login Form
Every user that will enter his credentials it will redirected to another page where his credentials will stored. In this case the credentials can be found at the data capture page and we can see them below:



As we saw in this article HTML injection vulnerabilities are very easy to exploit and can have large impact as any user of the web application can be a target. System admins must take appropriate measures for their web applications in order to prevent these type of attacks.

Comments

Popular posts from this blog

How to hack anyone System in seconds and Create viruses

G et some knowledge about virus... What is Virus ?  A computer virus is a program or piece of code that is loaded onto your computer without your knowledge and runs against your wishes. All computer viruses are man-made. A simple virus that can make a copy of itself over and over again is relatively easy to produce. Even such a simple virus is dangerous because it will quickly use all available memory and bring the system to a halt. An even more dangerous type of virus is one capable of transmitting itself across networks and bypassing security systems   Create Virus on Notepad : It is very easy to create a virus on notepad   H ow to open notepad follow these steps 1. P ush win + R then new window will open then type notepad and click on OK . After that notepad will open then type or paste these command and make a virus.   1 -> Virus Creation Tricks 1 Just open the Notepad and type the paste the following Code. set ws=createobje...

hacking windows administration password

Changing Administrator Password using Command Prompt(CMD) A fter reading this post, you’ll be able to change your and anyone’s Administrator account password in windows OS(7,XP AND OLDER VERSION)  without asking him the previous one. Usually, for changing the passwords, we go to User Accounts in Control Panel and then option for changing the passwords. But windows doesn’t permit us to do so, till we enter the previous password. So, it’s clear that we can’t change the password from this method. Because, the current password is also required here, which we don’t know. But, the same thing can become possible, if perform the same task through Windows Command Prompt(CMD). In this method, we are not prompted to enter the current/old password. But for that, we first need to be logged in as an Administrator (see step 2 below), unless you will be shown an error message. So, I don’t want you to get any type of error, that’s why I was focussing on this point. ...

Difference Between TCP Vs. UDP and it's working.

                             TCP vs. UDP T his article describes how TCP and UDP work, the difference between them, and why you would choose one over the other. O verview TCP (Transmission Control Protocol) is the most commonly used protocol on the Internet. The reason for this is because TCP offers error correction . When the TCP protocol is used there is a "guaranteed delivery." This is due largely in part to a method called "flow control" . Flow control determines when data needs to be re-sent, and stops the flow of data until previous packets are successfully transferred . This works because if a packet of data is sent, a collision may occur . When this happens, the client re-requests the packet from the server until the whole packet is complete and is identical to its original. UDP (User Datagram Protocol) ...