OWASP Mutillidae II: Web Pwn in Mass Production
Version: 2.6.48 Security Level: 5 (Server-side Security) Hints: Disabled (0 - I try harder) Not Logged In
Home | Login/Register | Show Popup Hints | Toggle Security | Enforce SSL | Reset DB | View Log | View Captured Data
 
Want to Help?
 
 
 
 
Error Message
 
Failure is always an option
MessageSorry. An error occured. Support has been notified. Not allowed to give out errors at this security level.
Click here to reset the DB
 
Capture Data
Data Capture Page
 
This page is designed to capture any parameters sent and store them in a file and a database table. It loops through the POST and GET parameters and records them to a file named captured-data.txt. On this system, the file should be found at /tmp/captured-data.txt. The page also tries to store the captured data in a database table named captured_data and logs the captured data. There is another page named captured-data.php that attempts to list the contents of this table.
 
The data captured on this request is: popUpNotificationCode = SL5 page = capture-data.php showhints = 0 PHPSESSID = kjuvjpl9rupq70j9gukk4nbc77
 
Would it be possible to hack the hacker? Assume the hacker will view the captured requests with a web browser.