Skip to content

Instantly share code, notes, and snippets.

@securitytube
Last active August 29, 2015 14:13
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 1 You must be signed in to fork a gist
  • Save securitytube/d413d30894e70af8d66c to your computer and use it in GitHub Desktop.
Save securitytube/d413d30894e70af8d66c to your computer and use it in GitHub Desktop.
PA
param = self.request.get("ch10")
referer = self.request.referer
xreferer = self.request.headers.get('X-Referer')
valid_referer = "http://pentesteracademylab.appspot.com/lab/webapp/csrf/10"
if referer or xreferer:
if param == flag and (referer == valid_referer or str(xreferer) == valid_referer) :
cid = "success"
self.response.headers.add_header("Set-Cookie", "cid-csrf10="+cid)
self.redirect("/lab/webapp/csrf/10")
return
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment