Advertisement
Guest User

Untitled

a guest
Aug 20th, 2019
73
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.63 KB | None | 0 0
  1. <?php
  2. session_start();
  3.  
  4. if(!isset($_SESSION['csrf_token'])) {
  5. $_SESSION['csrf_token'] = substr(base_convert(sha1(uniqid(mt_rand())), 16, 36), 0, 32);
  6. }
  7. ?>
  8. <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
  9. <html>
  10. <head>
  11. <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"/>
  12. <link rel="stylesheet" type="text/css" href="contents.php?file=style.css" media="screen"/>
  13. <title>What's up</title>
  14. </head>
  15. <body>
  16. <div class="top">
  17. <div class="header">
  18. <div class="left"></div>
  19. <div class="right">
  20. <h2>What's up</h2>
  21. <p>Deze website maakt onderdeel uit van een Certified Secure challenge en wordt beveiligd door de beste specialisten!</p>
  22. </div>
  23. </div>
  24. </div>
  25. <div class="container">
  26. <div class="main">
  27. <div class="content">
  28. <h1>This is up</h1>
  29. <?php
  30. $sql = new mysqli("localhost", "whatsupr0vCk5", "kxUnS4Ra05PElcwu", "whatsupdS2Prl");
  31. $result = $sql->query("SELECT `name`, `site`, `message`, `when` FROM `messages`");
  32. while($res = $result->fetch_array(MYSQLI_ASSOC)) {
  33. ?>
  34. <div class="descr"><?=strip_tags($res['when'])?> door <a href=<?=strip_tags($res['site'])?>><?=strip_tags($res['name'])?></a></div>
  35. <blockquote>
  36. <p><?=strip_tags($res['message'])?></p>
  37. </blockquote>
  38. <?php
  39. }
  40. ?>
  41. <h1>What's up?</h1>
  42. <form method="POST" action="add.php">
  43. <label for="name">Naam</label><input type="text" name="name" id="name"/>
  44. <div class="clearer"></div>
  45. <label for="website">Website</label><input type="text" name="website" id="website"/>
  46. <div class="clearer"></div>
  47. <label for="message">What's up</label><textarea name="message" id="message"></textarea>
  48. <div class="clearer"></div>
  49. <label for="submit"></label><input type="submit" id="submit"/>
  50. <input type="hidden" name="token" value="<?=$_SESSION['csrf_token'];?>"/>
  51. </form>
  52.  
  53. <div class="sidenav">
  54. <h2>Zoek</h2>
  55. <form method="GET" action="search.php">
  56. <input type="text" name="search" size="16"/>
  57. <input type="submit" value="zoek"/>
  58. <input type="hidden" name="token" value="<?=$_SESSION['csrf_token'];?>"/>
  59. </form>
  60. <h2>Over</h2>
  61. <p>Op deze website mag iedereen vertellen hoe het met hem of haar gaat. Heb je een slechte dag gehad omdat je site is gekraakt? Ben je ontslagen? Of heb je juist een nieuwe baan als security officer gevonden? Laat het weten!</p>
  62. </div>
  63. <div class="clearer"><span></span></div>
  64. </div>
  65. <div class="footer">&copy;2017 What's up. Template design door<a href="http://arcsin.se">Arcsin</a> </div>
  66. </div>
  67. </body>
  68. </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement