dvwa-09-Weak Session IDs

这个就是讲几种cookie设定的方式
很容易猜到(除了第三个

low:每次加1
medium:时间戳
high

<?php

$html = "";

if ($_SERVER['REQUEST_METHOD'] == "POST") {
    
    
    if (!isset ($_SESSION['last_session_id_high'])) {
    
    
        $_SESSION['last_session_id_high'] = 0;
    }
    $_SESSION['last_session_id_high']++;
    $cookie_value = md5($_SESSION['last_session_id_high']);
    setcookie("dvwaSession", $cookie_value, time()+3600, "/vulnerabilities/weak_id/", $_SERVER['HTTP_HOST'], false, false);
}

?> 

。。。

猜你喜欢

转载自blog.csdn.net/qq_53755216/article/details/113747795
ids