Shouts to all the people who tell me, directory traversal / listing is NOT important.
Additional shouts to people who tell me, how their website "security" budget is cramped, but they can do endless scans of their intranet, internal network and desktops for compliance, year on year! :)
################################################
# Website: www.mmasuperstore.com.au
# Date: 18.01.12
# Bug: Database PWNage
###############################################
If only you guys had invested a portion of the money you spent on design towards security, this day would not have arrived!
But, Enjoy while it lasts... Consider this to be more publicity :))
Directory Traversal Vuln - MMA Super Store
WP Config File - MMA Super Store
What you have to learn from this incident is invest in security... as much or a portion of your design budget. Test the website with QA & Security instead of designing eye candy and flashing banners for "affiliate" dollars in mind!
When you run an online store and sell merchandise, please provide the "level of security" promised in your privacy statement instead of keeping things adhoc and designing a flashy website. The Internet is not a secure place, the Internet was not designed with adequate security.
Directory traversal is often overlooked and Websites don't get the attention they deserve, in 2012, that's a bad statistic !
Cheers,
Kish
Showing posts with label Google Hacking. Show all posts
Showing posts with label Google Hacking. Show all posts
Tuesday, January 17, 2012
Monday, July 11, 2011
New Google Dork (Thanks AXN!)
Presenting our own google dork, which stemmed from the AXN site goodies... To check whether a particular site uses jQuery extensively...
You can use this query...
You can check a specific website using the site operator...
Cheers,
Kish
You can use this query...
intext: * jQuery 1.2.6 - New Wave Javascript * * Copyright (c)
You can check a specific website using the site operator...
Cheers,
Kish
Labels:
Crimemachine,
Google Dork,
Google Hacking,
Insecure,
Insecure Times,
Web Hacking
AXN India - Exposed to the Internet
A simple google query did the trick... :D



This is not a great flaw by itself... the site's administration should not be enabled for all internet users (to play with and break the authentication)...We did not poke with the authentication scheme, hehe ;)

Update: We also found cron.php, install.php, xmlrpc.php, half a dozen email addresses, directory traversal (scripts, modules, profiles, themes, sites) and lots more...

Stopped playing for we didn't want to end up accidentally hacking the website :))
Bottom line: Functionally sound, security wise - bad idea?
Shouts to Jaymee ong... (marry me please !) and the eBuzz Team who's programme was being featured on AXN before I found the goodies :D



This is not a great flaw by itself... the site's administration should not be enabled for all internet users (to play with and break the authentication)...We did not poke with the authentication scheme, hehe ;)

Update: We also found cron.php, install.php, xmlrpc.php, half a dozen email addresses, directory traversal (scripts, modules, profiles, themes, sites) and lots more...

Stopped playing for we didn't want to end up accidentally hacking the website :))
Bottom line: Functionally sound, security wise - bad idea?
Shouts to Jaymee ong... (marry me please !) and the eBuzz Team who's programme was being featured on AXN before I found the goodies :D
Labels:
AXN,
AXN India,
Crimemachine,
eBuzz,
Google,
Google Hacking,
Insecure,
Insecure Times,
Web Hacking
Subscribe to:
Posts (Atom)


