1
Hacking and Security / Re: Most embarrasing hack you've ever done?
« on: June 10, 2013, 04:54:25 pm »
Lame defaces + registered at zone-h

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
I really don't understand how can you infect someone by giving the link that contains localhost's address. There should be an advanced configuration I think. It's not that easy
.
ok, since this topic is here, i always have a question about it.
I made a page like this before ( 4 testing ) and was wondering how to change the PHP code to make it take the users input and pass it to the real website to log in and redirect the user after that to the website "after logging in" ?
I think we will need to make him has a cookies with that credential, but how ?
That will make him a lot less suspicious after the redirection .
No you dont do it automatically with scanners/tools.
No tool exists that can find an 0day for you. ¿
0-days in web apps are easy, but usually not really interesting. A CSRF vulnerability in a WordPress plugin is not interesting at all. An arbitrary code execution in the base WordPress system is interesting