-
Notifications
You must be signed in to change notification settings - Fork 59
Description
[*] WE GOT A HIT! Printing the output:
POSSIBLE USERNAME FIELD FOUND: ------WebKitFormBoundaryK53nrQPL5G9NkDUW
Content-Disposition: form-data; name="ts"
1587971044337
------WebKitFormBoundaryK53nrQPL5G9NkDUW
Content-Disposition: form-data; name="q"
[{"app_id":"256281040558","posts":"rB3waVtbImdrMl9leHBvc3VyZSIseyJpZGVudGlmaWVyIjoiMTA3MzUwMCIsImhhc2giOiJBVDZDX0NFYWF3YlVFcU5jIn0sMTU4Nzk3MTAzNjczNy44LDAsNTBdLFsicmVxdWlyZV9jb25kX2UNYhxfbG9nZ2luZ0JqAPBWQWEyZzVXNk9FdnRwTzFLMDRuM3JhQXhWYjFIbXF0a3FpVU5oVUo3T1YzbjE1a0FTdkZsTm5IMVJnUUxPNmdBZVpfS2xGejhGZzNkV0ZMSUdaUFRUblJNNqAAIDQ0LDAsMTA0XcqfAPBjMzNld2UtQVhuZk5wV2tHN19mVnlWRWFIeXhCYVN1YnBYRG5uektSY2d6Q2h6Y0ZfMnRWNHF3cDQ4RV9ieGs5YVJ2cF9KdU5tck1iR1BNSDctMyJ9LDE1ODc5NzEwMzY3NDQuNAWeADHSngDwRGR3XzJ3ZnJPeVZ3dWRSSXl1cEV6d1hhNmlhckFqa3RpWk15NkN1QW56aUtfdDIwN3o3OUIyQkxXREVtbzZBaXZTRjA0Ij6RABQ1LDAsODjOkADwXjBGMkUwTm5nRmZwXzFSX2c1d05FaTlNTWNIN01WOTFLdFQySzc4ZDB5RWctUE0zZFF6RmVHM0VUU2ZTbWwxakxNR1lwRzZQQVlvbnNRVlpESmptTjR6aG42MnBkblMiPqkAGDcsMCwxMTMBqnLQAhQ5NDY4OTQuzwI0NzRBT2phVV9rR1dGQ1g6LwIcNS4xLDAsNDmCWAAUNjc2OTIyMlgAMEVRVFpyTmNqVUNZSURCWABBiZ5YAAAwLlgAODYzam1QeWZnLXAxYU9GIi4JARA5NDAuNqqwAAAxLlgANDRJb0ZycUkwZlBSVGgtNlgABDU3qrAACDgzNy5YADQ1NE1QMzhWQXdjZE82dTZYAAQ2MSW5ADSGYAEUMTExMzI0NlkAMDFwdjZJNkJJQ25CUUo2WQAEOTgFsQA1hYhyEQIUNzA4MjUzLrEANDZ6Q2dLRFhnczV5NWZVLlgADDkzMjRlE46xABQzOTkyMTguWQA0NU0xMjdZSzlyTWNSZk8dWRA0MDU5Nh2xAHK6OQXwUDBBNG5jYVVpUjAtVExFN2V3MlhoZHluNVY4WGZDN0hpdVJzRHAtQ25RTWtyMDFlN05hOUg4aTd1V2RkNXUtVHE3Y01PRHVCX05UX0t0aEhvTUKcAAA4YV8AMIpOAQwyOTYzMq8CNDQxZGJCZFpRUnJDSmFxOlkAYbaSTAEMODE3NjJMATQ3ZzNrNFVwVVk2UTJReD5XAAQuMtWFdv0BAa8yBgM0NVJIYTEtcDRub21oS3RCWAAAM5ZeAxgxMjgxNTA1Lv0BNDQxR05Sd3VnQktJTmdUQlkAYbeKrgIUMTI5MTAyMq8CNDc2Rkx2VWRFcHdPNkxWQlkAIbqWWQAINDE4MsEENDVfcVE1a2hEMC1UN2dSQlkAADmWYwEYMTMzNDY2OS4LATQ3QklwdEVWazhFNkNTMDpZAAA4pXKOsgAQNDAxMDY2bAIwRFN5Smxwdk9CTlBrNUJZACG9llkACDUxMTJkATQ0cmJoTEc3d0hoTUlXWkJZAKHMjlkAEDA5OTg5NlkAMFl4ZnNJTmhLX1pBa04uWQAMNDEyNR2yvhME8Ewza3RwUmlrcWc1N1M1dXYyc2thcmZqUmVYYVZTY2NrUUxIRlRydE9tZ3lRa2tmcF9uY0huYTFXOXljb2V5M2RlNTZlMTZGZDVtNkp3ItlkCZdBrQQ5NeEUwpcA8FRTU1pUT1EyMnYtQkRXMVZVM2xNd3ZqTEdDSnFubndDaDVQdW41X25EcXJDS2lBRk8xb294WHJJQTgtSllVRDdObXRZS3E2MGp1WTBjVmhqS1NCT1RyQjgBQfUEMTAFogRna2reChQ2Nzc3NjIynAIwTndWZEM0Z0p2ckZkaDZZAAQ3NSXqibFMd2ViX2RldmljZV9wZXJmX2luZm8O3AoO2ApYY3B1X2NvcmVzIjo4LCJncHVfdmVuZG8OUAsMQVJNIgkTGHJlbmRlcmUBFSBNYWxpLVQ4MzAycAAIMjQyZWUANhIQCiBjbGlja19yZWYBZSxnZXIiLFsiMmRVbCIifwskNDQyNzgsImFjdBkUDDMzMzYhrhwiZW1haWwiLAlHHQggLSIsInIiLCIvAbgQZnQiOnsJI0BfdHlwZSI6ImxlZnQifSwiZwEbIH19LDQwOSwyN6FfIDAsImRrMmk4cwE+KGxvZ2luLnBocCJdOpAADDAsMTWmwQAEODFCwQAQNjE3LDH+wQAdwRw0OSwyNjcsMJLBAAQ4MCXzssMAADI+wwAoNzMyMywyLCJwYXMhLSXK7oMBEDQzLDMxIdaOgwEEODESYwkAMYmgBXx+RgIEODM6wgAgNDI0MTcsMywiJecduwVPBCIswkYCIX0BBIZCAiw4My4xLDAsMTQ3XV0=","user":"0","webSessionId":":v5ic4k:dk2i8s","trigger":"categorized_ods","send_method":"ajax","compression":"snappy_base64","snappy_ms":16},{"app_id":"256281040558","posts":[["script_path_change",{"source_path":null,"source_token":null,"dest_path":"/login.php","dest_token":"ad976420","impression_id":"0azpnEXZltZYlBpRF","cause":"load","sid_raw":"1kg5fz:v5ic4k:dk2i8s","referrer":"","dest_ef_page":null,"dest_uri":"https://www.facebook.com/login.php"},1587971044301.9,0,255],["require_cond_exposure_logging",{"identifier":"Aa26BoGBIrz4hMsXoLrWSKBl9LjVVnoGCjWPpC04mVa77asZA3xA2We9DdKe5PBAclVOCHWbCTskZ62A9hj7BBulTNchQqzV"},1587971044302.2,0,113],["categorized_ods",{"2966":{"ms.time_spent.qa.www":{"time_spent.bits.js_initialized":[1]}}},1587971044310.9,0,72]],"user":"0","webSessionId":"1kg5fz:v5ic4k:dk2i8s","compression":""},{"webSessionId":"1kg5fz:v5ic4k:dk2i8s","posts":[["categorized_ods",{"2979":{"banzai":{"blue_messages_received":[37]}}},1587971044313.8,0,51]],"user":"0","app_id":"256281040558","compression":""},{"webSessionId":"1kg5fz:v5ic4k:dk2i8s","posts":[["categorized_ods",{"2979":{"banzai":{"blue_messages_sent":[37]}}},1587971044314.7,0,47]],"user":"0","app_id":"256281040558","compression":""}]
------WebKitFormBoundaryK53nrQPL5G9NkDUW--
Exception happened during processing of request from ('127.0.0.1', 55332)
Traceback (most recent call last):
File "/usr/lib/python3.8/socketserver.py", line 650, in process_request_thread
self.finish_request(request, client_address)
File "/usr/lib/python3.8/socketserver.py", line 360, in finish_request
self.RequestHandlerClass(request, client_address, self)
File "/usr/lib/python3.8/socketserver.py", line 720, in init
self.handle()
File "/usr/lib/python3.8/http/server.py", line 427, in handle
self.handle_one_request()
File "/usr/lib/python3.8/http/server.py", line 415, in handle_one_request
method()
File "/usr/share/set/src/webattack/harvester/harvester.py", line 334, in do_POST
filewrite.write(cgi.escape("PARAM: " + line + "\n"))
AttributeError: module 'cgi' has no attribute 'escape'
[*] WE GOT A HIT! Printing the output:
POSSIBLE USERNAME FIELD FOUND: __user=0
Exception happened during processing of request from ('127.0.0.1', 55336)
Traceback (most recent call last):
File "/usr/lib/python3.8/socketserver.py", line 650, in process_request_thread
self.finish_request(request, client_address)
File "/usr/lib/python3.8/socketserver.py", line 360, in finish_request
self.RequestHandlerClass(request, client_address, self)
File "/usr/lib/python3.8/socketserver.py", line 720, in init
self.handle()
File "/usr/lib/python3.8/http/server.py", line 427, in handle
self.handle_one_request()
File "/usr/lib/python3.8/http/server.py", line 415, in handle_one_request
method()
File "/usr/share/set/src/webattack/harvester/harvester.py", line 334, in do_POST
filewrite.write(cgi.escape("PARAM: " + line + "\n"))
AttributeError: module 'cgi' has no attribute 'escape'