Monday, 27 February 2017

http://www.mercatinomusicale.com | system compromise, XSS, sql injection.

http://www.mercatinomusicale.com | system compromise, XSS, sql injection, data dump. XSS http://www.mercatinomusicale.com/ann/search.asp?rp=&ct=&ch=&mc=&p1=&p2=&rg=&pv=&kw=%22%3E%3Cscript%3Ealert(%27xss%27);%3C/script%3E%3C%22%20627%20r

Thursday, 23 February 2017

overlay with youtube video - simple

It's very simple but I didn't spent too much time.

you just need to add your image with x.png



paste the js or include it in an external .js file.


JS


<script>
$(document).ready(function(){


var overlay = jQuery('<div id="overlay"></div><div id="box" class="videoWrapper"><iframe src="https://www.youtube.com/embed/B-HCMfaOkL0?autoplay=1&rel=0&enable_js=1" frameborder="0" allowfullscreen></iframe></div><div id="closebox"><img src="images/x.png" /></div>');
overlay.appendTo(document.body).fadeIn('fast');

    $("#box").width($(window).width());
    $("#box").height($(window).height());
    $("#box").css('width','90%');
    $("#box").css('margin-left','5%');
    $("#box").css('margin-right','5%');
   
     $("#closebox").click(
     function(){
         $('#overlay').fadeOut('fast');
         $('.videoWrapper iframe').attr('src', '');
         $('#box').hide();
         $('#closebox').hide();
     });

     //chiusura emergenza
     $('#overlay').click(
     function(){
        $(this).fadeOut('fast');
        $('.videoWrapper iframe').attr('src', '');
        $('#box').hide();
        $('#closebox').hide();
     });
   
     $(document).on('keyup',function(evt) {
        if (evt.keyCode == 27) {
             $('#overlay').fadeOut('fast');
             $('#box').hide();
        }
    });
});

$(window).resize(function(){
    $("#box").width($(window).width());
    $("#box").height($(window).height());
    $("#box").css('width','90%');
    $("#box").css('margin-left','5%');
    $("#box").css('margin-right','5%');
});

</script>



and add a bit of css

CSS

#overlay {position: fixed;top: 0;left: 0;width: 100%;height: 100%;background-color: #000;opacity: .7; filter: alpha(opacity=70);-ms-filter:"progid:DXImageTransform.Microsoft.Alpha(Opacity=70)";z-index: 10000;}
#box{ width:90%; height:90%; display:none;position:absolute; left:0%; top:0%;z-index: 10001;}
#box iframe{width:100%;height:100%}
#closebox{ position: fixed; top: 0px;right: 0px;z-index: 10001;padding:4px;}

Thursday, 16 February 2017

webx1009.aruba.it 89.46.104.19

123prova.net
ageendawifi.com
albergovenezia.net
altremedicine.com
amid.net
angolodellesoluzioni.it
canaledisecchia.it
checcozalone.it
clpsrl.com
cospat.com
deltawear.it
elgusto.it
espisrl.com
euronomade.info
forexometro.com
fotocolizzi.com
gianmarcoventuri.net
gizia.it
globalsecurity.it
hotelquadrifoglio.com
ilnuovopicchio.org
iswatlab.eu
jollybeach.it
lacasanettarina.it
lacortedilucia.com
lemlaboratorio.com
loomenstudio.com
maestranzeartistiche.it
marchotel.it
mauriziogreco.it
mestieridarte.net
monteferrario.com
mpdistribuzione.com
reccometeo.it
rinofior.com
sanbernardoabate.it
ski-nordik.it
stefaniasperandio.com
studiograssi.it
studiosoluzioni.it
studiotravaglin.it
suonarealondra.com
taffo.com
taranta.it
ufficialidigaranisseni.it
violamassimo.com
webx1009.aruba.it

Wednesday, 15 February 2017

https://servizistudenti.unisannio.it/ - XSS





https://servizistudenti.unisannio.it/pls/self/ssiiolk0.form2



http://www.lavoraconnoi.rai.it/ | stored xss and sql injections

http://www.lavoraconnoi.rai.it/lavoraconnoi/application/initiativeList?initiativeType=all

after registering you can add stored XSS in quite any field.


Other info will be added after that they fix the problems.


Set the placeholder in the input of the Google GCSE custom search engine.

When you play with the google CSE by removing various things via CSS happens that the placeholder could be "undefined".
The timewait or onload are not working correctly and just a workaround.

After your usual script part to include GCSE
gcse.src = (document.location.protocol == 'https:' ? 'https:' : 'http:') + '//cse.google.com/cse.js?cx=' + cx;

put this part


gcse.onload = gcse.onreadystatechange = function() { $(function() { // hack to set a placeholder in google's custom search input var pollInput = window.setInterval(function() { var $input = $('.gsc-input input.gsc-input'), $div = $('.search-db'); if ($input.length) { $input.on('focus', function(e) { $div.addClass('wide').removeClass('narrow'); }); $input.on('blur', function(e) { if (!$input.val().length) { $div.addClass('narrow').removeClass('wide'); } }); $input.attr('placeholder', ""); window.clearInterval(pollInput); } }, 10); }); };


I found the script part on github.
https://github.com/mongodb/docs-tools/blob/master/themes/mms-onprem/page.html

Thank you to mongodb!

Sunday, 12 February 2017

Webcam easynote - Windows 10 - Windows 7 - Windows Vista

USB2.0 350K WebCam
USB\VID_0402&PID_5602&REV_0100
easynote_webcam_v
Download

Cardbus Texas Instruments PCI-8x12/7x12/6x12 - Windows 10

Controller Cardbus Texas Instruments PCI-8x12/7x12/6x12
Windows 10 x32
PCI\VEN_104C&DEV_8039&SUBSYS_22001558&REV_00

Download

Yuan MPC718 TV Tuner Card Drivers - Windows 10

windows 10, windows 7, windows vista - 32 bit drivers
Yuan MPC718 TV Tuner Card 2.13.10.1016
PCI\VEN_14F1&DEV_5B7A&SUBSYS_071812AB&REV_00

Download

Twitter Delicious Facebook Digg Stumbleupon Favorites More