ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

csgoroll.com self-xss tip victim's wallet to yourself


  • Please log in to reply
csgoroll.com self-xss tip victim's wallet to yourself

#1

SernterxErer
SernterxErer
    Offline
    4
    Rep
    16
    Likes

    Lurker

Posts: 9
Threads: 4
Joined: Dec 12, 2016
Credits: 0
Seven years registered
#1

Hey guys, I lurked around the CS:GO site 

Please Login or Register to see this Hidden Content

 and found out that they had a tip system. I sniffed the traffic to analyze the api and I realized that you just needed to do a simple post request with your authentication cookie to tip a user your desired amount of "coins".

I then created this self-xxs script that does the following:
If this script gets executed by a user, the script will first send a get request to the server to get the user's info. From that info, we extract the user's current wallet balance and use that in the post request telling the server to tip "xxxxxx"1 ( your userID or to who you want to tip them). 

  1. If you don't know how to manipulate the script to show your userID, pm me and I can help you out. ;) 

The way we can make the request valid is to get the victims authentication cookie. We easily do this by calling:

Please Login or Register to see this Hidden Content

Here is the finished script using jquery:

Hidden Content
You'll be able to see the hidden content once you reply to this topic or

Please Login or Register to see this Hidden Content

.

I tried to make it somewhat small, but I guess some here can make it even "tidyer".

EDIT: Too lazy to respond to everyone who cannot find their id;

Hidden Content
You'll be able to see the hidden content once you reply to this topic or

Please Login or Register to see this Hidden Content

.


Edited by SernterxErer, 02 August 2017 - 03:42 AM.

  • 9

dvd2Qn6.gif


#2

neomaking
neomaking
    Offline
    0
    Rep
    0
    Likes

    New Member

Posts: 10
Threads: 0
Joined: Dec 14, 2015
Credits: 0
Eight years registered
#2

Looks funny, I need to take a look myself


  • 0

#3

pruned_34697817
pruned_34697817
    Offline
    0
    Rep
    -3
    Likes

    Varaz was there :)

  • PipPipPip
Posts: 26
Threads: 3
Joined: Dec 23, 2016
Credits: 0
Seven years registered
#3

thanks for the share, getting on it


  • 0

1.jpg


#4

Drkwn
Drkwn
    Offline
    11
    Rep
    13
    Likes

    Impressive Title

Posts: 54
Threads: 10
Joined: Mar 09, 2016
Credits: 0

Eight years registered
#4

Seems interesting, worth a look i guess.


  • 0

#5

GuurBuur
GuurBuur
    Offline
    34
    Rep
    17
    Likes

    EDU Mail Provider

Posts: 605
Threads: 25
Joined: Sep 21, 2015
Credits: 0

Eight years registered
#5

tnx


  • 0

MY DISCORD IS NOT GuurBuur#3982

Please be careful when dealing on discord

And always ask for PM confirmation on Nulled

 


#6

Vezuure
Vezuure
    Offline
    2
    Rep
    -1
    Likes

    Member

Posts: 72
Threads: 4
Joined: Jun 11, 2015
Credits: 0
Eight years registered
#6

nice


  • 0

#7

pruned_67678926
pruned_67678926
    Offline
    0
    Rep
    0
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 92
Threads: 0
Joined: Jan 10, 2016
Credits: 0
Eight years registered
#7

thx for this


  • 0

It's just my butt, ok.


#8

pruned_13921652
pruned_13921652
    Offline
    0
    Rep
    0
    Likes

    Member

  • PipPipPip
Posts: 32
Threads: 0
Joined: Oct 08, 2016
Credits: 0
Seven years registered
#8

ty


  • 0

#9

venom777
venom777
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 5
Threads: 0
Joined: Jan 19, 2016
Credits: 0
Eight years registered
#9

ty


  • 0

#10

dannyaramayo
dannyaramayo
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 1
Threads: 0
Joined: Dec 27, 2016
Credits: 0
Seven years registered
#10

ty

 


  • 0


 Users browsing this thread: