Written on May 13th, 2009 at 6:06 am by

22 Comments

Fool your friends claim you hacked the Search Engine Gaint

Here is a simple tricks to claim you hacked google .It will work only with Internet Explorer 6.

What it does ?

It pops up alert message 3 seconds after you visit google site via hyperlink provided by the coder.It also sets the window status of the goolge window that opens.Which is usually not allowed pages residing in a domain can control only the pages that reside in the same domain but via the exploit below its possible to overcome it.

-It is a serious Cross Site Exploit done via ZERO DAY flaw in IE6.It provides the ability to run a script loaded in one domain over another domain.Thus can very much steal cookies written by another site which is a serious flaw!

Trick:

Save this code as html file and see to that href location is same as the path of that file where you upload it.Here it is “http://whereismycabin.googlepages.com/string1.htm#

Code:

< !DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">




www.google.com

 

To see it in action visit :

IE Zero Day Exploit

Also check out:Why its recommended not to use IE?

For technical details visit:

Phantom Team

Get Free Newsletter
Cross site scripting, Hack prank, IE cross site Exploit, IE zero day flaw

22 Responses to “Fool your friends claim you hacked the Search Engine Gaint”


  1. Vaibhav Kanwal

    3 years ago

    I tried it out and I think its pretty silly.
    Its just a popup and after clicking ok, it works normally.

    Reply

  2. admin

    3 years ago

    @Vaibhav
    I agree it just a simple pop up but what be should seen is the depth of the flaw..cookies can be read..Just think of this you have opened your orkut account in another tab you click on this malicious link very well your orkut account cookie can be read and exploited.(though orkut has fixed that bug) just letting you know it..

    Check the Technical Details:
    http://translate.google.com/translate?hl=en&u=http://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x02_0x04.txt

    you can understand de depth of the flaw

    :victory:

    Reply

  3. Vaibhav Kanwal

    3 years ago

    Yeah, I agree with you here.
    Its a security flaw not for Google but IE. Infact IE fails the ACID test. Worst browser ever.

    The only problem is people are oblivious to the flaws of IE6 and continue to use it just because it serves their purpose and it came preinstalled with their copy of windows.

    I have friends you refuse to switch to Firefox saying they didn’t feel comfortable using it. I dont know what comfortable means to them. Firefox is the best browser on earth. IE should die…

    Vaibhav Kanwal’s last blog post..Google Webmasters gets a new look

    Reply

  4. admin

    3 years ago

    @vaibhav

    We are in the same boat:0)I too always wonder why so many of them still sticking on to IE when secure browser like firefox is there..

    Reply

  5. TechZoomIn

    3 years ago

    Good one dude…Simple but yet surprising to others. Good stuff you shared..

    TechZoomIn’s last blog post..Plugin To: Make your Images Auto HighSlide

    Reply

  6. admin

    3 years ago

    Thanks welcome to my blog :big_smile:

    Reply

  7. Tech @ InkAPoint

    3 years ago

    It’s interesting one.

    Tech @ InkAPoint’s last blog post..75 Top Rated Unused Domain Names

    Reply

  8. prateek

    3 years ago

    really informative..keepup..
    http://www.thetechnoclub.com :anger:

    Reply

  9. Ricky

    3 years ago

    Thanx for the share.This pop up screen will definately fool our friends if he is not a techie.But now a days people dont use IE6.

    Reply

  10. admin

    3 years ago

    @Prateek

    Thanks dude…

    @Ricky

    Thanks and welcome to my blog happy to see you over here:)I would also like to point out tat i have seen still many institutions and school’s are sticking with IE only..

    Reply

  11. Salwa

    2 years ago

    lol, nice one! thanks for the share.

    Salwa’s last blog post..Traffic Monday: How twitter can help you drive targeted traffic to your website

    Reply

    • admin

      2 years ago

      Thanks…Happy to see you over here.. :victory:

      Reply

  12. thegands

    2 years ago

    thats why i don’t like damn f*ing IE.

    Reply

    • admin

      2 years ago

      Thats de right thing to do:)

      Reply

  13. Preetam

    2 years ago

    Nevertheless, it’s nice, and I didn’t know about it earlier. :victory:

    Preetam’s last blog post..Five Alien Places On Earth

    Reply

  14. admin

    2 years ago

    Welcome dude:)

    Reply

  15. Team Nirvana

    2 years ago

    Thats a very interesting way to jot down. This post is quite informative with all the gritty details described in and out.

    Thanks for taking time and posting.

    Reply

    • admin

      2 years ago

      Thanks friends..And happy to see you here:)

      Reply

  16. yreadthisy

    2 years ago

    cool nice post let me see how this works.

    Reply

3 Trackbacks For This Post

  1. Ultimate Mobile Prank-Make Your Friends Get Call From Their Own Mobile Number! | Technobuz Says:

    [...] Fool your friends claim you hacked Google [...]

  2. Play Pranks on Friends- Crash their Web Browser | Technobuz Says:

    [...] Fool your friends claim you hacked Google [...]

  3. Speed up Internet Explorer 6 | Technobuz Says:

    [...] Cross Site Scripting Flaw in IE6 [...]

Leave a Reply



Previous Post:

Next Post: