XSS(cross site scripting) अटैक क्या है- Ethical hacking - My Hack Support

Ethical hacking, Cyber,Security, Money making, Computer Tips, Hacking, Web development, Online paisa kaise kamaye, Android,Android app development, Android tricks and tips, Moded games, hacking techniques, Online Courses, Hacking courses, Online Money Making, Ethical Hacking Course

Search here...

शनिवार, 7 जुलाई 2018

XSS(cross site scripting) अटैक क्या है- Ethical hacking

XSS(cross site scripting) Attack kya है :-------Xss Vulnerbility












Dosto agar aapko hacking me intrest hoga to aapko pata hi hoga ki xss(cross site scripting) attack kya hai aur ek hacker is vulnerbility ka fayda utha kar kya kya kar sakta hai to agar aapko janana hai ki xss(cross site scripting) attack kya hai to aap hamari  puri post padhe jisse aap jaan sake ki cross site scripting  kya  hai kaise hota hai or kaise kiya jata hai





XSS (cross site scripting) Attack kya hota hai ) ??








Dosto kisi bhi xss vulnerable website me 
mellicious code ko inject karke website ke 
data churana ya webaite ko hack karna xss(cross site scripting) ko kahlata hai. xss ek web based vulnerbility hai. aap to jante hi honge ki puri website alag alag language se milkar bani hoti. hai Ex php,html,javascript,css....etc
 lekin agar web devoloper dwara agar website ache se nhi banaya jaye to aam tor par ye vulnerbility mil jati hai jiska use  karke hacker website hack karke cookies admin usernames,passwords,cc_details etc data chura sakta hai.





XSS      (cross site scripting) 
      Work methood)-------




Dosto aapko pata lag hi gaya hoga ki xss based web vulnerbility hai or hacker iska fayda kaise utha sakta hai aap to jante hi hai ki website me search box,comment box paye jate hai.
Dosto iss Vulnerbility me hacker ya attacker website ke search box ya comment box me aise script ya commanddalta hai jo  execute ho jata hai.






Acha hum maan lete hai ki google.com me xss vulnerbility hai to hacker kya karega hacker google.com ke search box ya comment box kahi par bhi jayega aur waha koi mellicious script dalega ye script ya command bhi ho sakti hai toye script server se execute hokar aapke samne result show kardegi 






XSS (cross site scripting examples)




yeh ek website hai jisme xss vulnerbility hai to hacker comment box me jakar script inject karega to script server par jakar execute ho jayegi or hame result show kardegi.
Mana ki ham iss website ke comment box me jakar <body bgcolor="blue"> ye wala command dalte hai to wo command execute ho jayegi or website ka background color change ho jayega



Types OF XSS ( cross site scripting )



1st --    Server xss(#server side cross site scripting)


Dosto iss xss me hacker jab mallicious code inject karta hai tab script website ke database me store ho jati hai iss type ke xss ko server side xss attack kaha jata hai




2nd-------Client side Xss(#client side xss)



isme agar client dwara website banane me jo kami hoti hai use clent side xss attack kaha jata hai isme reflected xss aata hai





Stored XSS (cross site scripting)


Ye server side scripting hoti hai ye permanently hoti hai agar koi hacker website me script inject karta hai to wo permanently website ke databased me stored ho jata hai iss vulnerbility se website ka defacement bhi kiyga jata hai




Reflected Xss( cross site scripting)


ye temperory xss hota hai iss vulnerbility me attacker script inject karta hai to website ke database me store na hokar server se reflect ho jati hai or hame popup show hota hai



Dom Based Xss(cross site scripting)

iss type ke xss me website ka pura design ko change kiya ja sakta hai  Or website ke content ko bhi change kiya ja sakta hai or agar  attacker chahe to website me dangerous javascript ya mellicious code inject karke website ko nuksan pahucha sakta hai






TO DOSTO AAPKO HAMARI POST KAISI LAGI AGAR ACHI LAGI HO TO HAMARI POST KO SHARE KARE HAME FB AUR INSTA PR FOLLOW KARE AUR AGAR KUCH BHI PROBLEM HO TO COMMENT KARNA NA BHULE



3 टिप्‍पणियां:

  1. Thanks for sharing an information to us. If someone want to know about hacking training in coimbatore. I think this is the right place for you! ceh Training

    जवाब देंहटाएं
  2. Grab the unique DevOps Training in Chennai along with the AWS or Azure Cloud services from Infycle Technologies. Along with Infycle's software training in Chennai, grab the opportunities to get placed in top MNCs such as Zoho, Google, FreshDesk, MacAppStudio as a distinctive Cloud professional. For transforming your career, call 7504633633.

    जवाब देंहटाएं