Help with variables

Discussion in 'Cracking Discussions & Help Forum' started by Lembas, Sep 20, 2015.

  1. Lembas

    Lembas Basic Member

    Messages:
    761
    Likes:
    50
    Ratio:
    0.05
    Hi there.
    I have been trying to create a config for target. I noticed, that login post data looks like this:


    csrfToken=407c380200ffffff800a08090080ffffff8001963220affffffa2002&redirectTo=&logonId=asdas%40sad.csa&logonPassword=asdasd

    Where token is shown in the login page source:


    <script type="text/javascript">var csrfTokenValue = '407c380200ffffff800a08090080ffffff8001963220affffffa2002'</script>

    I tried creating a variable for it using parse code but I'm not exactly sure how to use it. Do I put it somewhere in the additional data / custom data in master wizard (magic wand), or do I have to create variables for login, password, token and redirect and then connect them into 1 variable and mark it as post data?
     
  2. SpiffyAF

    SpiffyAF Banned

    Messages:
    147
    Likes:
    94
    Ratio:
    0.11
    You want to parse the code for the token in the post action header. Then you take the token variable and apply it to the Form redirect header
     
  3. Lembas

    Lembas Basic Member

    Messages:
    761
    Likes:
    50
    Ratio:
    0.05
    Well, it seems that my knowledge is even worse than I thought. I have watched a youtube tutorial made by someone here and it showed that the token was taken from a "token website" in which the token was parsed and used as variable, and then it redirected to login page and was used there as post data. Here, however, the token is avaiable on the login page itself, therefore there is no need for redirect. I don't understand why you want m to put it as a header if its supposed to go into post data, not header.
     

Share This Page