########################################
# Website: http://mexico.cnn.com
# Date: 14.09.11
# Bug: Open Redirection Page
########################################
Click here for demo
I could use a r57shell with this to make it look more scary :)
Sidenote: GoDaddy has made an effort to make us look good, by putting up their default banner...hmmm !
Cheers,
Kish
Showing posts with label Digi. Show all posts
Showing posts with label Digi. Show all posts
Wednesday, September 14, 2011
Thursday, December 30, 2010
ISS - Internet Security Systems?
I have great respect for the guys at ISS X-Force... You guys are the best, nothing personal :)
Although, I'm certain they wouldn't approve of this screenshot here...

Vuln URL: hxxp://webapp.iss.net/Search.do
On Behalf of Crimemachine, Wish You (Our Readers) a Happy New Year Guys
We are Back ! ;)
Although, I'm certain they wouldn't approve of this screenshot here...

Vuln URL: hxxp://webapp.iss.net/Search.do
On Behalf of Crimemachine, Wish You (Our Readers) a Happy New Year Guys
We are Back ! ;)
Labels:
Crimemachine,
Digi,
Experts,
HTML Injection,
IBM,
Insecure,
Insecure Times,
ISS,
Web Hacking,
Whack,
X-Force,
XSS
Wednesday, August 26, 2009
Advisory Updates: Q2 2009, and a bit more...
Even though a spectacular hack was pulled off on Imageshack, they've not fixed their bug yet.
The lazy developers behind the Indian Premier League (oh reely??) have not fixed their XSS and SQLi bugs either... In 2009 if you want to see a demo, of a site allowing "delete method" in databases please visit them :))
ZDNet that writes the special 0-day column, apart from regular security ramblings is "yet" to fix their bug, and Dancho danchev, one of the authors from their team is still replying to mail...
Adobe atleast fixed their bug even though it was late, and I applaud their security team / devs for their store.
Electronic arts and blogarama haven't fixed their bugs just like the others, no I am not surprised
Probably, I'll write the next / final advisory update for this year in 3 to 4 months from now... Keep your eyes open !
Cheers :)
Kish
The lazy developers behind the Indian Premier League (oh reely??) have not fixed their XSS and SQLi bugs either... In 2009 if you want to see a demo, of a site allowing "delete method" in databases please visit them :))
ZDNet that writes the special 0-day column, apart from regular security ramblings is "yet" to fix their bug, and Dancho danchev, one of the authors from their team is still replying to mail...
Adobe atleast fixed their bug even though it was late, and I applaud their security team / devs for their store.
Electronic arts and blogarama haven't fixed their bugs just like the others, no I am not surprised
Probably, I'll write the next / final advisory update for this year in 3 to 4 months from now... Keep your eyes open !
Cheers :)
Kish
Labels:
Adobe,
Blog,
Blogarama,
Crimemachine,
Digi,
Electronic Arts,
eShop,
Hack,
Hacking,
Indian Premier League,
Insecure,
Insecure Times,
IPL,
SQL Injection,
SQLi,
Web Hacking,
Whack,
XSS,
ZDNet
Wednesday, March 4, 2009
XSS in ESET website
#########################################
# Website: http://www.eset.com
# Bug: XSS
# Date: 04.03.09
########################################

Vulnerable URL: hxxp://kb.eset.com
Click here for the demo
Fix input validation in the page, antivirus vendors are supposed to be careful, atleast, I thought so !
This is a special advisory, Dedicated to Digi (Crimemachine,Founder), my very good friend, and fellow hacker, who is an ardent supporter of ESET products, the antivirus especially, for the heur et al.
Cheers :)
Kish
# Website: http://www.eset.com
# Bug: XSS
# Date: 04.03.09
########################################

Vulnerable URL: hxxp://kb.eset.com
Click here for the demo
Fix input validation in the page, antivirus vendors are supposed to be careful, atleast, I thought so !
This is a special advisory, Dedicated to Digi (Crimemachine,Founder), my very good friend, and fellow hacker, who is an ardent supporter of ESET products, the antivirus especially, for the heur et al.
Cheers :)
Kish
Labels:
antivirus,
Crimemachine,
Digi,
ESET,
Insecure,
Insecure Times,
Special,
Web Hacking,
Whack,
XSS
Subscribe to:
Posts (Atom)
