Print Page | Close Window

Can Asp Do This????

Printed From: Web Wiz Forums
Category: General Discussion
Forum Name: Classic ASP Discussion
Forum Description: Discussion on Active Server Pages (Classic ASP).
URL: https://forums.webwiz.net/forum_posts.asp?TID=7715
Printed Date: 29 March 2026 at 4:41am
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: Can Asp Do This????
Posted By: neotrix
Subject: Can Asp Do This????
Date Posted: 29 November 2003 at 9:46am
...access a user's favorites list, make my site their home page, delete their cache, delete their history, remove one item from their cache, remove one item from their history, write to a text file on their hard drive, figure out their home page, determine their custom settings, put a shortcut to my home page on their start menu, force them to download a file without a prompt, change their default download folder, adjust their page margins for printing, automatically print a page without a prompt, change their default printer, disable the edit button, disable view source, disable the back/forward buttons, change their default browser/e-mail client/newsreader, "borrow" their e-mail address, read a key from their registry, change their security settings, force them to save my web page to their hard disk, change their "browse in a new process" setting, change their screen size/resolution/color depth, force them to download an ActiveX control/plugin, automatically run an EXE on the client, force them to enable cookies, grab or delete files from their machine without asking, or force them to view my Java applets even though they have disabled Java? 

?????



Replies:
Posted By: ultramods
Date Posted: 29 November 2003 at 9:52am
Yes it can do all that, plus it can let you withdraw money from the users bank account.


Posted By: neotrix
Date Posted: 29 November 2003 at 10:29am
can you tell me how can i make my site their home page without prompting?


Posted By: Mart
Date Posted: 29 November 2003 at 10:39am
No you can't do any of that obviously! Or nobody would have any privacy, you can do some of the in javascript. http://www.w3schools.com/asp - you need to learn the differance between client side and server side


Posted By: Mart
Date Posted: 29 November 2003 at 10:40am
P.s. You cant set your site as their homepage without a prompt and you can only do it in javascript.


Posted By: neotrix
Date Posted: 29 November 2003 at 11:24am
but how?


Posted By: Mart
Date Posted: 29 November 2003 at 11:49am
www.dynamicdrive.com www.jsmadeeasy.com www.javascriptkit.com take your pick


Posted By: theSCIENTIST
Date Posted: 30 November 2003 at 5:59am

You could also make a hand coming out of the guy's monitor, grab him by his balls, turn him upside down, shake him, all his pocket coins will then fall into a pre-set recepient sliding all the way to the front door straight in to your waiting hands, here's the code for that:

<%
Set myHand = Server.CreateObject("Punch.Grabber")

Set myAction = myHand.WideOpen(FromMonitor.SqueezeBalls("Tight"))

Set Turn = myAction.UpSideDown

For Each Coin in Turn
    onClient.Action = KeepShaking
   
    'If End Of Coins
    If myAction.EOC Then
        'Send SMS to yourself so you know when to go and collect coins
        Send.SMS("YourPhoneNumber", "SMS Msg", 1)
        'Drop the guy after 30 mins
        onClient.Action = DropGuy.Delay(30)
        Else
             onClient.Action = KeepShaking("Harder")
    End If
Next

myHand.Close
Set myHand = Nothing
myAction.Stop
Turn.Stop
%>

See? Easy...



Posted By: Gullanian
Date Posted: 30 November 2003 at 7:29am
Hmmm I get a cannot create object error on line 2, whats wrong with it?


Posted By: michael
Date Posted: 30 November 2003 at 9:09am
That is hillarious.

-------------
http://baumannphoto.com" rel="nofollow - Blog | http://mpgtracker.com" rel="nofollow - MPG Tracker


Posted By: pmormr
Date Posted: 30 November 2003 at 9:15am


-------------
Paul A Morgan

http://www.pmorganphoto.com/" rel="nofollow - http://www.pmorganphoto.com/


Posted By: Mart
Date Posted: 30 November 2003 at 9:16am

Ok i found totureclient.DLL on aspin.com and the first part works.

But now im getting this error:

error 'ASP 0113'
Script timed out

/tortureclient.asp

The maximum amount of time for a script to execute was exceeded. You can change this limit by specifying a new value for the property Server.ScriptTimeOut or by changing the value in the IIS administration tools.

on this line:

'Drop the guy after 30 mins
        onClient.Action = DropGuy.Delay(30)

How do i change the timeout settings?



Posted By: pmormr
Date Posted: 30 November 2003 at 9:43am

go Start>run and type cmd.

then type "format c: -s" and wait for that program to complete... volaa!!



-------------
Paul A Morgan

http://www.pmorganphoto.com/" rel="nofollow - http://www.pmorganphoto.com/


Posted By: pmormr
Date Posted: 30 November 2003 at 9:44am
this is getting interesting!

-------------
Paul A Morgan

http://www.pmorganphoto.com/" rel="nofollow - http://www.pmorganphoto.com/


Posted By: God_Struth
Date Posted: 30 November 2003 at 11:39am
Originally posted by Gullanian Gullanian wrote:

Hmmm I get a cannot create object error on line 2, whats wrong with it?


Change this:

Set myAction = myHand.WideOpen(FromMonitor.SqueezeBalls("Tight"))



To this:

Set myAction = myHand.WideOpen(FromMonitor.SqueezeBalls("65psi"))


In this example you have to say how hard you want it to squeeze, so set it to something like 65 pounds per square inch (psi) to achieve the desired 'squeeling' effect.


Works a treat!!






-------------
"I'm only trying to help......"


Posted By: neotrix
Date Posted: 02 December 2003 at 4:56am


Posted By: neotrix
Date Posted: 02 December 2003 at 5:14am

Originally posted by Mart Mart wrote:

No you can't do any of that obviously! Or nobody would have any privacy, you can do some of the in javascript. http://www.w3schools.com/asp - you need to learn the differance between client side and server side


Well, not all of them, but most of them are really possible... and I also think that setting home page must be javascript, and i can do that by the prompt, but i have seen who really make them selves my home page without prompting, for example, http://www.oska.com - www.oska.com & http://www.bonzibuddy.com - www.bonzibuddy.com they will make them selves your home page without prompting if you wome around the site for a while?!? any body knows how can we do it,

and well privacy, what can we say, privacy issues are really important these days, cuz privacy is really really decreasing... I dont know what is gona happen in near future...

I'm sorry if any of the above sounds hard :)



Posted By: neotrix
Date Posted: 02 December 2003 at 5:18am
i think its http://www.bonzi.com - www.bonzi.com


Posted By: Mart
Date Posted: 02 December 2003 at 9:22am
He asked how to do it in asp. Which none are possible because asp is a serverside language not a clientside.< ="">


Posted By: michael
Date Posted: 02 December 2003 at 9:31am
Plus even if I knew how to do all that, including flushing my toilet, I wouldn't tell because I cannot think of any other use than abuse. Sites that force me on something are just a waste of time.

-------------
http://baumannphoto.com" rel="nofollow - Blog | http://mpgtracker.com" rel="nofollow - MPG Tracker


Posted By: theSCIENTIST
Date Posted: 03 December 2003 at 1:28am

I still believe web sites can't just set the homepage without any prompt, I have explored the sites mentioned and my homepage was not reset, the reason it might do it automatically is if you have very weak settings in your browser (ie. allow all to run/install without prompts) which is not very safe.

Like Michael said, even if knew of any way to do some of the things you asked, I wouldn't be giving it way to contribute to even more exploitation and invasion of privacy.

The masters on this kind of thing, are XXX sites, they are always looking on ways to exploit, hide true intentions, fake, steal, lure, you name it, have a look at the code of some of them and you'll see the extent at which these people go to achieve their dirty goal.



Posted By: neotrix
Date Posted: 03 December 2003 at 1:45am

And they also make so many unbeliveable things, like adding a folder in the favourites, making short cut, setting home page... i mean, if we really want to stop it, or if we think its bad, we still gota learn the code you know?? Like as they say in face off

"In Order to Trap Him, He Must Become Him"

Any how, i just wanted to learn it, and ofcoruce, the more you learn the more you gain, who know, tommorow you need any of these things for some good?!? I just wanted to say if any one knows, he must share it, like as you all people are experts, how can you make use of such things for spam & abuse ?!? you can't ? right?



Posted By: God_Struth
Date Posted: 03 December 2003 at 5:20am
Originally posted by neotrix neotrix wrote:


Any how, i just wanted to learn it, and ofcoruce, the more you learn the more you gain,




Take the time to learn javascript and you can write your own scripts to do whatever you wish.

Star here: http://javascript.internet.com/

-------------
"I'm only trying to help......"


Posted By: Bluefrog
Date Posted: 03 December 2003 at 6:27am

Best solution for hacking clients is to use both server side and client side.

On the server you determine what the client is - IE4, 5, 5.5, etc., Win98, 2k, etc. You then serve up different exploits and try to run executable code. Voila. You've got a zombie. However, you really need to know what you are doing to run exploits on a client.

If there is an HTTP header exploit for a browser, then you can use ASP to control a client.

The best exploits are always the ones that you never hear about. There is one IIS FTP exploit that still doesn't have a patch. I don't know really how it works (I'm too busy to bother with it), but I've seen it twice. It lets a hacker write data to your server.

You know you're a cheap b@$+@rd and you've got too much time when you need to steal disk space...

 



-------------
http://renegademinds.com/" rel="nofollow - Renegade Minds - Guitar Software http://renegademinds.com/Default.aspx?tabid=65" rel="nofollow - Slow Down Music


Posted By: Nathan
Date Posted: 03 December 2003 at 7:18am

People - thanks you have brightened up my day - haven't laughed so much in ages!

Nathan



Posted By: theSCIENTIST
Date Posted: 04 December 2003 at 6:14am

Let me guess .. my squeeze routine ;) or, neotrix willingness to learn/use exploits? No offence neotrix I used to be in that sort of mind frame a few years ago, you will eventually get out of it.

Bluefrog: that exploit works only on the IIS FTP, or in any Windows FTP? I don't have IIS FTP, but run another solution.

neotrix: you said they can add a folder to the favourites? Humm, and I though Javascript didn't have access to the filesystem. Are you sure of this?



Posted By: ctscott
Date Posted: 04 December 2003 at 10:58am
i've found it more efficient to just break into their house and steal their box.

-------------
______________________
http://www.cfbtrivia.com" rel="nofollow - College Football Trivia


Posted By: pmormr
Date Posted: 04 December 2003 at 3:03pm
if you get the client to download some software and execute it on their machine you can totally fu*k up their computer... but yes, it's a lot easier just to chuck a brick through their window and steal their box

-------------
Paul A Morgan

http://www.pmorganphoto.com/" rel="nofollow - http://www.pmorganphoto.com/


Posted By: Bluefrog
Date Posted: 04 December 2003 at 3:21pm
Originally posted by theSCIENTIST theSCIENTIST wrote:

...

Bluefrog: that exploit works only on the IIS FTP, or in any Windows FTP? I don't have IIS FTP, but run another solution.

...

On IIS. I doubt it works on other FTP servers. From looking at it a bit closer, I'd guess that it probably works on PWS, but I don't know.

 



-------------
http://renegademinds.com/" rel="nofollow - Renegade Minds - Guitar Software http://renegademinds.com/Default.aspx?tabid=65" rel="nofollow - Slow Down Music


Posted By: fernan82
Date Posted: 06 December 2003 at 3:39pm
Each and every thing you mentioned neotrix is possible but not with ASP nor JavaScript.

Most of it can be done with client side vbScript, the rest with ActiveX controls. vbScript only affects Windows with WSH enabled and ActiveX control affect IE. It's not even hard to do but I don't have time to waste with that so don't ask me for code.


-------------
FeRnAN
http://www.danasoft.com/">



Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net