Deoctor Posted September 24, 2012 Share Posted September 24, 2012 hai I am testing one of my client site for the integrity against attacks. So i have a form from which they can send the feedback to one of their predefined mail ids. This site was completely done in asp( which i dont know how to code by the way) So i am using php for this purpose. now what doubt i have is that can the form auto submit through code is possible for the asp forms. If yes could some one please help me how to do it. I have checked with the Firebug for the post parameters,it is showing some of the content which i could not able to figure out. URL http://demand2supply...2/Feedback.aspx POST CONTENTS __EVENTARGUMENT __EVENTTARGET __EVENTVALIDATION /wEWwAQCr7jQnwkCsK/0tAoCtL7JqgYCstrOnggCofjD7gIC0MSjhg0CwKuJ6AEC26v16wECyKvB6wECyKup6AEC3qvJ6wEC4OCV5QsCuOrP4Q8C372vjAwC9N2Bxg4CicGDkwsCzoienwwCo9urzA8Cjbqu3gkCt5jYywYCl/3ztA4C/om+yQwC4on6yQwCjbuqBgK3mIjIBgKJ6sS1AwKr75yLAwLK2+qyCQKqvOofAtPiobIEArqK1aEIAvO2i5YMArChyPAEArChpJ0MAoHH/PYGAvPz5coKAoHHtKMMAtLL3UICgce4owwC7bT71woCgcesowwCnPmhmAwCgcewowwCt+K/rQYCgcekowwC5qbm7QcCgceoowwCgZCEgwICgcecowwCsNSqwwMCgce07AcCgZCY8gUCgsfQ7AcCjt2PswoCgsfU7AcCqcatyAQCgsfI7AcCxK/L3Q4CgsfM7AcC35jp8ggCgsfA7AcC+oGHiAMCgsfE7AcCleuknQ0CgsecIwKj7JnlBgKCx6AjAoiD/M8MAoLHlCMCqav4uwgCgseYIwKOwtqmDgL/xrQjAoH12uUJAv/GuCMC5ou90A8C/8asIwK3x5aQDgL/xoRTAontg4gBAv/G+FICkPuY8gMC/8b8UgKr5LaHDgL/xvBSAtqo3ccPAv/G9FIC9ZH73AkC/8boUgL8n5DHDAL/xuxSApeJrtwGAoDHjOgDAtyQ8JYJApD1t7cJApLH6tANAr/42NQJApK80LIGAoLT+twKAp/Tjt8KAsPYyqIMAvSyivwEApjTit8KAofv0L0CAruS3YgNAorT2twKApvTtt8KAujVsssPApjTjt8KAv7x7JcCAorTst8KAoXT+twKAtmZ7IsOApvTjt8KAp7Tut8KApvTut8KAorTnt8KApjTgt8KAqKAzpYIApnTht8KAofv1L0CAtmZkIsOAv7x6JcCAp/Tht8KAtar9/0DAp7Tnt8KAp3T1twKAs28ldYJAorTgt8KAoPFqaEOAsadhfMMAsud3p4NAqrnsLgLAv6bsOgNAvON/d8JApPhiIQNAt6P4oEFAuStlJQKAsTIv+sCAq288hYCsby2FgLejubZDALkrcSXCgLa34jqDwL42tDUDwKZ7qbtBQL5iabADAKA1+3tCALpv5n+BALCmNOVCwKBj5DzAwKBj/yeCwLWrNnpBgLWrNn0DgLWrMWZBgLWrLG+DQLWrJ3jBALWrImIDALWrPWsAwLWrOHRCgLWrIHzAwK7w5eSCAK7w4O3DwK7w+/bBgK7w9uADgK7w8elBQK7w7PKDAK7w5PJAwK7w//tCgK7w+uSAgK7w9e3CQKg2u3WDQKg2tn7BAKg2sWgDAKg2uWnAgKg2tHMCQKg2r1xAqDaqZYIAqDalbsPAqDageAGAqDa7YQOAoXx1/0BAo3l2NgPAt/o7fcNApfTjCwC/Jme7gMC/Zme7gMC/pme7gMC/5me7gMC+Jme7gMC+Zme7gMC+pme7gMC65me7gMC5Jme7gMC/Jne7QMC5pyCnQwC55yCnQwC5JyCnQwC64jG/QkC9IjG/QkC9YjG/QkC/YexnA8C/Pq22gwCg6b4lAMC5+GTpgQCkq6c4wECkdqqwQgCtrzAwAoC//OJ0AECtYn40gECu6SWoAoCnvXrwwUCvdK6jgkC7pH/pQcC+tzR7gMC6dXtiQMCrp7+kgcCuMPGvA0CusOSrwoCzL3Hhw4Chdu93QwCmp+jtwkCzMig6goCpu+2tgcC3v3UlwcChOu55A4C/Obs0wMCwuWngg8CyqCvywICksjL4Q0C3KDdogEClYjJ1gIC/76gxQoCpIGxzQQCqYCklgcC0IXYuAoCpqGqgQcC2eyNxg4CzcqQXQLGr9z5AQK8ie2uBwLz99DlBAKzv8qxCgKvu6TWDQLHk9z/BwL6vq+iAgL8mO+iBAL33/rlCQLuvrOSDQKw1p59AvWIhd0IAuPzi6ENAufz1ZULAtG63wsCjY/Tug0Cn6aLtwYCnIP69Q4CmoL1+AoCp8brogsCptv5gQgCg8i33Q4Cv9nEiw0Cy5O84wgCqOzH2Q8C4sXa+g4CqZW0zQoCnoqZmAcCh4bJwg0Ch4bJwg0C2rDogAICr+G54AoCqLfehwoC0dDU6QQCz87HsgYCntSzpQ0CnsK1MwL0h72yCQK+pJOuCgK0pPrtDALo57AtAsnGyqwDAqCFvMUIAriFgOgIAsXP7osBAoj1t6gDAsulm8AOAsLY/fUPApb6yvAOApif+qkIArLmifUDAqj0/PsEAuyFqb0MAsSJ9tUCAoeL5MoEApmH3boBApiH3boBApuH3boBApqH3boBAurX4coBAuvX4coBAujX4coBAunX4coBApHP1poKAo7P1poKAo/P1poKAozP1poKArmbjooHAribjooHArubjooHArqbjooHAsK0/9oJAt20/9oJAty0/9oJAt+0/9oJApTkraENApXkraENApbkraENApfkraENAqednfEHAridnfEHArmdnfEHArqdnfEHApuS24oCApqS24oCApmS24oCApiS24oCApjBu7EFAofBu7EFAobBu7EFAoXBu7EFAs2I7qsDAt6IoqgDAsGIoqgDAsCIoqgDAsOIoqgDAsKIoqgDAsWIoqgDAsSIoqgDAseIoqgDAtaIoqgDAtmIoqgDAsGI4qsDAsGI7qsDAsGI6qsDAsGI1qsDAsGI0qsDAsGI3qsDAsGI2qsDAsGIxqsDAsGIgqgDAuq/wLYFAvm/jLUFAua/jLUFAue/jLUFAuS/jLUFAuW/jLUFAuK/jLUFAuO/jLUFAuC/jLUFAvG/jLUFAv6/jLUFAua/zLYFAua/wLYFAua/xLYFAua/+LYFAua//LYFAua/8LYFAua/9LYFAua/6LYFAua/rLUFAofVop0PApTV7p4PAovV7p4PAorV7p4PAonV7p4PAojV7p4PAo/V7p4PAo7V7p4PAo3V7p4PApzV7p4PApPV7p4PAovVrp0PAovVop0PAovVpp0PAovVmp0PAovVnp0PAovVkp0PAovVlp0PAovVip0PAovVzp4PAsqYhu8DAtmYyuwDAsaYyuwDAseYyuwDAsSYyuwDAsWYyuwDAsKYyuwDAsOYyuwDAsCYyuwDAtGYyuwDAt6YyuwDAsaYiu8DAsaYhu8DAsaYgu8DAsaYvu8DAsaYuu8DAsaYtu8DAsaYsu8DAsaYru8DAsaY6uwDAq3hpYAIAr7h6YMIAqHh6YMIAqDh6YMIAqPh6YMIAqLh6YMIAqXh6YMIAqTh6YMIAqfh6YMIArbh6YMIArnh6YMIAqHhqYAIAqHhpYAIAqHhoYAIAqHhnYAIAqHhmYAIAqHhlYAIAqHhkYAIAqHhjYAIAqHhyYMIApDKw7UGAoPKj7YGApzKj7YGAp3Kj7YGAp7Kj7YGAp/Kj7YGApjKj7YGApnKj7YGAprKj7YGAovKj7YGAoTKj7YGApzKz7UGApzKw7UGApzKx7UGApzK+7UGApzK/7UGApzK87UGApzK97UGApzK67UGApzKr7YGAsfo39ICAtTok9ECAsvok9ECAsrok9ECAsnok9ECAsjok9ECAs/ok9ECAs7ok9ECAs3ok9ECAtzok9ECAtPok9ECAsvo09ICAsvo39ICAsvo29ICAsvo59ICAsvo49ICAsvo79ICAsvo69ICAsvo99ICAsvos9ECAvCkuZIDAuOk9ZEDAvyk9ZEDAv2k9ZEDAv6k9ZEDAv+k9ZEDAvik9ZEDAvmk9ZEDAvqk9ZEDAuuk9ZEDAuSk9ZEDAvyktZIDAvykuZIDAvykvZIDAvykgZIDAvykhZIDAvykiZIDAvykjZIDAvykkZIDAvyk1ZEDAo3am/kGAp7a1/oGAoHa1/oGAoDa1/oGAoPa1/oGAoLa1/oGAoXa1/oGAoTa1/oGAofa1/oGApba1/oGApna1/oGAoHal/kGAoHam/kGAoHan/kGAoHao/kGAoHap/kGAoHaq/kGAoHar/kGAoHas/kGAoHa9/oGAtyfsLkEAs+f/LoEAtCf/LoEAtGf/LoEAtKf/LoEAtOf/LoEAtSf/LoEAtWf/LoEAtaf/LoEAsef/LoEAsif/LoEAtCfvLkEAtCfsLkEAtCftLkEAtCfiLkEAtCfjLkEAtCfgLkEAtCfhLkEAtCfmLkEAtCf3LoEArPD1vkLAqDDmvoLAr/DmvoLAr7DmvoLAr3DmvoLArzDmvoLArvDmvoLArrDmvoLArnDmvoLAqjDmvoLAqfDmvoLAr/D2vkLAr/D1vkLAr/D0vkLAr/D7vkLAr/D6vkLAr/D5vkLAr/D4vkLAr/D/vkLAr/DuvoLApas9BIChay4EQKarLgRApusuBECmKy4EQKZrLgRAp6suBECn6y4EQKcrLgRAo2suBECgqy4EQKarPgSApqs9BICmqzwEgKarMwSApqsyBICmqzEEgKarMASApqs3BICmqyYEQK7wYfPDAK5gco+AtHsltIMArGFitkJAv/3gcwMAoXOuvwBHrJV5h+nkqGwomKGigE8y3SB5TI= __LASTFOCUS __SCROLLPOSITIONX 0 __SCROLLPOSITIONY 342 btnSend.x 49 btnSend.y 18 hiddenInputToUpdateATBuff... 1 international -2 txtComments jhf,mdsnfhkldsnfm,lhdslknhf,dsakf txtFeedEmail test@yd.com txtFullName kjgkjkjh txtMobile 09374093809 ucHeader$domestic -1 ucQuickSearch$UCHotelinIn... 1 ucQuickSearch$UCHotelinIn... 1 ucQuickSearch$UCHotelinIn... 1 ucQuickSearch$UCHotelinIn... 1 ucQuickSearch$UCHotelinIn... 0 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... 0 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... 0 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... 0 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... -1 ucQuickSearch$UCHotelinIn... 0 ucQuickSearch$UCHotelinIn... 1 ucQuickSearch$UCHotelinIn... ucQuickSearch$UCHotelinIn... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... Sep ucQuickSearch$UcFixedTour... 0 ucQuickSearch$UcFixedTour... 2012 ucQuickSearch$UcFixedTour... 0 ucQuickSearch$UcFixedTour... 09/01/2012 ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... 09/02/2012 ucQuickSearch$UcFixedTour... 09/03/2012 ucQuickSearch$UcFixedTour... 09/04/2012 ucQuickSearch$UcFixedTour... 09/05/2012 ucQuickSearch$UcFixedTour... 09/06/2012 ucQuickSearch$UcFixedTour... 09/07/2012 ucQuickSearch$UcFixedTour... 09/08/2012 ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... 09/09/2012 ucQuickSearch$UcFixedTour... 09/10/2012 ucQuickSearch$UcFixedTour... 09/11/2012 ucQuickSearch$UcFixedTour... 09/12/2012 ucQuickSearch$UcFixedTour... 09/13/2012 ucQuickSearch$UcFixedTour... 09/14/2012 ucQuickSearch$UcFixedTour... 09/15/2012 ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... 09/16/2012 ucQuickSearch$UcFixedTour... 09/17/2012 ucQuickSearch$UcFixedTour... 09/18/2012 ucQuickSearch$UcFixedTour... 09/19/2012 ucQuickSearch$UcFixedTour... 09/20/2012 ucQuickSearch$UcFixedTour... 09/21/2012 ucQuickSearch$UcFixedTour... 09/22/2012 ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... 09/23/2012 ucQuickSearch$UcFixedTour... 09/24/2012 ucQuickSearch$UcFixedTour... 09/25/2012 ucQuickSearch$UcFixedTour... 09/26/2012 ucQuickSearch$UcFixedTour... 09/27/2012 ucQuickSearch$UcFixedTour... 09/28/2012 ucQuickSearch$UcFixedTour... 09/29/2012 ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... 09/30/2012 ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... 9/24/2012 5:32:49 PM ucQuickSearch$UcFixedTour... 9/25/2012 5:32:49 PM ucQuickSearch$UcFixedTour... 0 ucQuickSearch$UcFixedTour... September 2012 ucQuickSearch$UcFixedTour... ucQuickSearch$UcFixedTour... ucQuickSearch$UcHotelInSo... 1 ucQuickSearch$UcHotelInSo... 0 ucQuickSearch$UcHotelInSo... 1 ucQuickSearch$UcHotelInSo... ucQuickSearch$UcHotelInSo... ucQuickSearch$UcSpecialTo... ucQuickSearch$UcSpecialTo... Sep ucQuickSearch$UcSpecialTo... 0 ucQuickSearch$UcSpecialTo... 2012 ucQuickSearch$UcSpecialTo... 0 ucQuickSearch$UcSpecialTo... 09/01/2012 ucQuickSearch$UcSpecialTo... 09/02/2012 ucQuickSearch$UcSpecialTo... 09/03/2012 ucQuickSearch$UcSpecialTo... 09/04/2012 ucQuickSearch$UcSpecialTo... 09/05/2012 ucQuickSearch$UcSpecialTo... 09/06/2012 ucQuickSearch$UcSpecialTo... 09/07/2012 ucQuickSearch$UcSpecialTo... 09/08/2012 ucQuickSearch$UcSpecialTo... 09/09/2012 ucQuickSearch$UcSpecialTo... 09/10/2012 ucQuickSearch$UcSpecialTo... 09/11/2012 ucQuickSearch$UcSpecialTo... 09/12/2012 ucQuickSearch$UcSpecialTo... 09/13/2012 ucQuickSearch$UcSpecialTo... 09/14/2012 ucQuickSearch$UcSpecialTo... 09/15/2012 ucQuickSearch$UcSpecialTo... 09/16/2012 ucQuickSearch$UcSpecialTo... 09/17/2012 ucQuickSearch$UcSpecialTo... 09/18/2012 ucQuickSearch$UcSpecialTo... 09/19/2012 ucQuickSearch$UcSpecialTo... 09/20/2012 ucQuickSearch$UcSpecialTo... 09/21/2012 ucQuickSearch$UcSpecialTo... 09/22/2012 ucQuickSearch$UcSpecialTo... 09/23/2012 ucQuickSearch$UcSpecialTo... 09/24/2012 ucQuickSearch$UcSpecialTo... 09/25/2012 ucQuickSearch$UcSpecialTo... 09/26/2012 ucQuickSearch$UcSpecialTo... 09/27/2012 ucQuickSearch$UcSpecialTo... 09/28/2012 ucQuickSearch$UcSpecialTo... 09/29/2012 ucQuickSearch$UcSpecialTo... 09/30/2012 ucQuickSearch$UcSpecialTo... 9/24/2012 5:32:49 PM ucQuickSearch$UcSpecialTo... 9/25/2012 5:32:49 PM ucQuickSearch$UcSpecialTo... 0 ucQuickSearch$UcSpecialTo... September 2012 ucQuickSearch$UcSpecialTo... ucQuickSearch$UcSpecialTo... ucQuickSearch$hdMenuSubTa... Quote Link to comment Share on other sites More sharing options...
KevinM1 Posted September 24, 2012 Share Posted September 24, 2012 You'll have to figure out: 1. How ASP encoded the values so you can decode them 2. Whether those values are used for ASP-specific things, or if PHP can use them Since this is primarily an ASP question, I'm not sure if any of us will be of any help. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.