Jump to content
vladiii

[PHP]Hack Me

Recommended Posts

Posted


[url]http://vladiii.phpnet.us/vuln.php[/url]

Incercati sa injectati JavaScript in pagina, sa afisati un alert sau mai stiu eu ce. Astept aici printscreenurile, iar metoda pe privat.

P.S. Fara FireBug sau alte tooluri asemanatoare :P

Bafta !

Posted

Brava.

Cod php vulnerabil:


<?php
$cookie=$_COOKIE['HackMe'];
if ($cookie != "") {
$cookie=base64_decode($cookie);
$x=explode("-", $cookie);
$nr=$x[1];
if ($nr != 0) {
echo "
<center>Mai ai $nr sanse.</center>";
$nr=$nr-1;
$cookie2=$x[0]."-".$nr;
$cookie2=base64_encode($cookie2);
setcookie("HackMe", $cookie2, time()+5000);
}
else {
echo "
<center>Nu mai ai nicio sansa.</center>";
}
}
else {
$ip=$_SERVER['REMOTE_ADDR'];
$plays=10;
$cookie3=$ip."-".$plays;
$cookie3=base64_encode($cookie3);
setcookie("HackMe", $cookie3, time()+5000);
echo "
<center>Mai ai 11 sanse.</center>";
}
echo "





<center>badc0de by vladiii</center>";
?>

Practic se codeaza IPul si nr. de incercari in base64.

Linia vulnerabila este echo "

<center>Mai ai $nr sanse.</center>"; Pt. ca acele cookies pot fi modificate foarte usor cu ceva de genu:


127.0.0.1-7"><script>alert(1)</script>

Toti au facut la fel cum am zis.

Bafta !

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...