Thisislegal.com
:[ Offline ]:

welcome, please log-in:




 Remember Me  ?
About: Remember Me
Ticking this box will make the site remember you for 24 hours. However, each time you visit the site this time is renewed, so if you are a regular visitor you will stay logged in.


Register An Account
Forgot Password?

:[ Forums ]:
Latest Post In:
Challenge Help
Topic:
Challenge 5
By:
Tiffyish
:[ Like ]:
:[ Alexa ]:
 
:[ Forums ]:
 Thisislegal ForumsChallenge Help → Bonus Challenge 2...injection!

Topic: Bonus Challenge 2...injection!
  Author:  Message:
devolution
Offline
Forum Rank: n00b
rank
avatar
Posts: 2
Thanks: 0
Standard User

thank
Hi people,

I have completed bonus challenge 2 by downloading the webpage. However, I want to do it with a javascript injection. Here what happens:

I crack the code.
I inject javascript to change the password box value to 'hello'.
I SEE that the value has physically changed.
I press submit...

THE PAGE RELOADS!

Why doesn't that work? Do I need to do a javascript injection to change the forms action?

I know I have done the challenge and should move on but I need to know why this doesn't work!

Thanks in advance!
  #1   Back To Top
BuRNeD
Offline
Forum Rank: Active User
rankrankrankrank
avatar
Posts: 112
Thanks: 14
Moderator

thank
That's because you haven't adjusted where the action will be posted, by default on the same page. But you don't want to send this to the page you saved on your disk, but rather to the site's page. So you'll have to change the "action" in the form and instead of nothing put the link of the real page using "http://www.example.com"
  #2   Back To Top
dokyriak
Offline
Forum Rank: n00b
rank
avatar
Posts: 7
Thanks: 0
Standard User

thank
I wasn`t able to do it downloading the page so I made it at last using javascript injection.
D O K Y R I A K
  #3   Back To Top
Xssed
Offline
Forum Rank: n00b
rank
avatar
Posts: 2
Thanks: 0
Standard User

thank
all hail firebug..
  #4   Back To Top

Locked.



Online (last 15 mins): metallover

DareYourMind   WeChall.net   Thenetsend.info   Powered by CloudFlare   Download Firefox   Opera Web Browser
Valid XHTML 1.0 Transitional
Home | Challenges | Forums | Contact | About (Disclaimer)
Copyright © 2007-12 Thisislegal.com, All Rights Reserved.


:[ ShoutBox ]:
Guest - Login to post comments


shoutbox bot:
no more proxy
iS33stars:
It helps if you read the tutorials before you attempt a challenge.
howboutdemboyzz:
wheres the proxy they offer?
mejizz420:
uh... i got lucky with the first challenge... dont really get the second challenge..
Nutu2000:
man, what are you doing here if you can't look at the source code of a web page?
adapt760:
whts the pass word for the 1st challenege
zurenarrh:
Nobody really uses the forums :/
Pages: 1, 2...343
Goto:
 
0.333 sec