OWASP Mutillidae II: Keep Calm and Pwn On
Version: 2.11.9 Security Level: 0 (Hosed) Hints: Enabled Not Logged In
Home | Login/Register | Toggle Hints | Toggle Security | Enforce TLS | Reset DB | View Log | View Captured Data
 
Want to Help?
 
Webpwnized YouTube Channel
Video Tutorials
 
Webpwnized Twitter Channel
Announcements
 
Webpwnized Twitter Channel
Getting Started
 
Capture Data
Go Back   Back Help Me! Help Me!
Expand Hints Hints and Videos
View Captured Data
Data Capture Page
 
This page is designed to capture any parameters sent and store them in a file and a database table. It loops through the POST and GET parameters and records them to a file named captured-data.txt. On this system, the file should be found at /tmp/captured-data.txt. The page also tries to store the captured data in a database table named captured_data and logs the captured data. There is another page named captured-data.php that attempts to list the contents of this table.
 
The data captured on this request is: page = capture-data.php PHPSESSID = 9j5jf7osvsgk2m8n7plga9g8u8 showhints = 1 _toffsuid = Xu0CYWiVrRk6O2V9A3HDAg==
 
Would it be possible to hack the hacker? Assume the hacker will view the captured requests with a web browser.
 
Browser: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
PHP Version: 8.3.4