5 ms·
if(isset($_COOKIE['4chan_auser'])&&isset($_COOKIE['4chan_apass'])){ $user = mysql_real_escape_string($_COOKIE['4chan_auser']);
by NewsReader42 12y ago
if(isset($_COOKIE['4chan_auser'])&&isset($_COOKIE['4chan_apass'])){
$user = mysql_real_escape_string($_COOKIE['4chan_auser']);
$pass = mysql_real_escape_string($_COOKIE['4chan_apass']);
}
HAHAHAHAAHAHAHAHAA
Steal a cookie, gain access.. WTF
- Kiro 12y agoHow do you "steal" a cookie?
- aidos 12y agoThe best bet is generally an xss attack. Though there are other ways, you could sniff one on a wireless network if no encryption is in use.
- exDM69 12y agoGet on the same WiFi as your target, open up Wireshark and grab their HTTP communications. To make this easier, there was/is a tool called Firesheep that can be used to hijack session cookies. The popularity of Firesheep caused many sites to enable HTTPS by default (e.g. Facebook did so).
- mandalar12 12y agoDoes it mean that the password is stored in the cookie or I am missing something ?
- spoiler 12y agoIt's probably a hashed version. It would be horrendous if it was actually stored in plain text.
- kawsper 12y agoAren't you able to hijack sessions on most webpages if you stole session cookies?
- odonnellryan 12y agoThe real problem is: "extract($_POST); extract($_GET); extract($_COOKIE);" For more information on extract: http://www.php.net/extract http://www.php.net/extract
- cyphunk 12y agoDocu on extract(): Description Import variables from an array into the current symbol table. If flags is not specified, it is assumed to be EXTR_OVERWRITE. EXTR_OVERWRITE If there is a collision, overwrite the existing variable. The danger is that any state variables set before the extract($_...)'s can be overwritten arbitrarily. This also makes it essential that any and every variable is instantiated prior to any use.