- Hacker Uses XSS and Google Street View Data to Determine Physical Location
- CAnCAn te iubim, CA CA tine nu gasim. Superfete.cancan.ro e de rahat
- Deface (?!?) pe Cotidianul.ro
- Virusi in clipuri video [how to]
- Cyber-Bullying – palma parinteasca a noului mileniu
- Christopher “moot” Poole: The case for anonymity online
- Wtf Avira?
- Some old story about tagged.com
- Pwning cam girls for fun
- Tabloshit
- Yahoo! again - XSS in Uncategorized (357 Visits)
- Yahoo! again - bad settings? in Uncategorized (252 Visits)
- Fanii nostri in Uncategorized (183 Visits)
- Frustrant in Uncategorized (146 Visits)
- La multi ani România, la multi ani românilor in Uncategorized (137 Visits)
- Weblog.ro - Shell via Local File Inclusion in Uncategorized (119 Visits)
- Yahoo! epic fail - permanent xss unleashed in Uncategorized (50 Visits)
- ... in Uncategorized (38 Visits)
- XSS Ownage - hi5 vs. Yahoo! + video in Uncategorized (2 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/Hi5 (4) in Uncategorized (2 Visits)
- Hackersblog.org is now blog.rstcenter.com in (1800 Visits)
- O mica dar importanta precizare in (1402 Visits)
- Twitter in (846 Visits)
- This is the end in (834 Visits)
- Ce servicii de mail folositi? in (826 Visits)
- Un nou membru in (771 Visits)
- La multi ani România, la multi ani românilor in (762 Visits)
- Inca o pierdere de timp in (709 Visits)
- De reţinut in (670 Visits)
- Azi este ziua userilor hackersblog.org in (644 Visits)
- Hi5.com coders read this in (621 Visits)
- SMS scam (1) in (611 Visits)
- Dezinformare sau proasta informare? in (597 Visits)
- Phishing Raiffeisen cu atasament html in (557 Visits)
- Phishing Bancpost in (524 Visits)
- Si tentativele de phishing pot fi amuzante in (456 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/mail (2) in (2870 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/Hi5 (4) in (2833 Visits)
- Despre CSRF, hi5.com, cum sa trisezi la concursuri s.a.m.d. in (1207 Visits)
- [Utilitare] Suna gratis de pe internet sau de pe iPhone in (1187 Visits)
- Ce nu se invata la scoala - (D)DOS (5) in (1008 Visits)
- Virusi in clipuri video [how to] in (969 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam (1) in (763 Visits)
- Yahoo! redirects - a big issue (with video) in (609 Visits)
- Internet vs. privacy (1) in (503 Visits)
- Ca musca in... in (462 Visits)
- RedTube.com ... The Free Sex Video Community in (13518 Visits)
- usa.kaspersky.com hacked ... full database acces , sql injection in (5415 Visits)
- libertatea.ro vulnerabil la (blind) sql injection in (3080 Visits)
- Telegraph.co.uk hacked, sql injection in (2700 Visits)
- Pwning cam girls for fun in (2694 Visits)
- Facebook hacked - sql injection in (2579 Visits)
- Simpatie.ro, matrimoniale3x.ro, apetisant.ro, deliciu.ro , etc Sql injection in (2553 Visits)
- F-Secure.com - SQL Injection + Cross Site Scripting in (1858 Visits)
- [Hacked]Bitdefender (Portugal) exposes sensitive customer data in (1854 Visits)
- Wtf Avira? in (1803 Visits)
- Christopher "moot" Poole: The case for anonymity online in (1580 Visits)
- Digital Photocopiers Loaded With Secrets in (1491 Visits)
- Hacker Uses XSS and Google Street View Data to Determine Physical Location in (895 Visits)
- Wannabe Hackers [1] - Cum sa hack-uiesti RapidShare-ul in (648 Visits)
- Wannabe Hackers [2] - cum sa faci un virus by sppy_hacker in (631 Visits)
- Hope 2603 – Kevin Mitnick - Life a Computer Hacker – Revealed in (487 Visits)
- PRIVACY IS DEAD - GET OVER IT, Pt 01-34 (Recommended by Hackersblog ) in (419 Visits)
- Oldies but goodies - Freedom Downtime - The Story of Kevin Mitnick in (416 Visits)
- [Video] The History Of Hacking in (395 Visits)
- Email Security - Why You Should Encrypt Your Email - Part One in (389 Visits)
- Deface - tuttoaffari.lastampa.it si citymusiclab.city.corriere.it in (3545 Visits)
- RNS vs. RAI - citizenreport.rai.it hacked. in (3360 Visits)
- Hi5 email finder si sfarsitul a tot ceea ce inseamna privacy in social networking in (3282 Visits)
- Se poate sparge parola de Yahoo? in (2735 Visits)
- Planete-plus-intelligente.lemonde.fr defaced by R.N.S. in (2561 Visits)
- Free SMS time, TrimiteSMS.ro in (2532 Visits)
- Gmail uber hacking in (2475 Visits)
- Cancan.ro spart pentru a doua oara intr-o zi in (2345 Visits)
- Camera de supraveghere a universitatii Alexandru Ioan Cuza din Iasi in (2322 Visits)
- Stiri cu antena3 in (2241 Visits)
Posted on December 12th, 2008
“VREMEA in DIRECT pe calculatorul tau !” Hihi… site-ul fiind vulnerabil la blind sql injection, se pare ca nu doar vremea ci si niste date mai personale (de logare etc) pot fi aduse direct pe calculatorul nostru. Site-ul care apartine Administratiei Nationale de Meteorologie si Hidrologie (INMH) este un punct de referinta pentru multi, incepand de la presa, tv pana la persoanele fizice, interesate de vreme. Ma amuz la gandul ce ar fi ca intr-o zi, in plina iarna, datorita insecuritatii site-ului, pe harta din prima pagina sa apara temperaturi de peste +40 grade. Pentru autenticitate publicam niste tabele.
Baza de date ftp, tabelul users
+———————————————————- +———————————————-
| description | homedir | passwd | userid |
+———————————————————– +————————————+———
| Cont ftp pentru upload fluxuri | /var/www/html/inmh/txt | $1$blacOe0o$tOXXXXXXXIoGe8uhrOs.91 | caraman |
| Sorinela | /var/www/html/inmh/images | cXXXXr | ftpinmh |
| Cont ftp pentru upload poluare | /var/www/html/inmh/txt | $1$blacOe0o$4iXXXXXu7gjrUBPeMvr.o. | sandu |
+————————————————————+————————————+———-
Baza de date inmh cu 73 tabele
+—————————-+
| abs_model_prognoza |
| abs_produse |
| abs_prognoza |
| abs_tipuri_prognoza |
| abs_zone |
| avertizari_en |
| avertizari_en_bak |
| avertizari_nowcasting_ro |
| avertizari_ro |
| avertizari_symbols |
| avertizari_symbols_rel |
| banner |
| c_descriere_tabele |
| c_evid_date |
| c_evid_statii |
| c_parametri |
| content_en |
| content_en_bak |
| content_ro |
| content_ro_bak |
| date_brute |
| date_brute_20071005 |
| date_brute_test2 |
| didi |
| emails_comanda |
| europa |
| faq_en |
| faq_ro |
| fenomen |
| forums |
| forums_auth |
| forums_forum2group |
| forums_groups |
| forums_moderators |
| forums_user2group |
| glosar_en |
| glosar_ro |
| guestbook |
| iconite_fenomene |
| lucrari_publicate |
| modules |
| news |
| orase |
| p2c |
| p2l |
| pages |
| pages_en |
| pages_ro |
| phonebook |
| prima |
| proces_principal |
| prognoza |
| prognoza_fenomene_speciale |
| prognoza_nebulozitate |
| prognoza_orase |
| prognoza_precipitatii |
| prognoza_presiune |
| prognoza_procese |
| prognoza_vant |
| prognoza_zone_geografice |
| sessions |
| sinoptice |
| statii |
| statii_razvan |
| statistici |
| stiri_en |
| stiri_ro |
| symbols |
| t1 |
| t1_attachments |
| t1_bodies |
| termeni |
| users |
+—————————-+
Cat si primele conturi,din baza de date imnh, tabelul users, cu datele de logare (unele caractere au fost inlocuite intentionat cu X)
+————————–+————+———————————-+——————+————–+————-+
| email | nume | pass | prenume | tel | user |
+————————–+————+———————————-+——————+————–+————-+
| NULL | Guest user | NULL | NULL | NULL | cretzu03 |
| 13.butty@gmail.com | astral | ce9a81c1adf725c43XXXXXee26e431b7 | adita | NULL | !N I C K! |
| a.rosca@gardiner.ro | anm | 68112abab86c73e20XXXXX52536feb54 | anm | +4072XXX2801 | 0Cool |
| a.stanescu@swietelsky.ro | Mediplus | 0ec9215bf72bd1d9eXXXXXb0a9945a26 | Dragomir Liviu | +4072XXX6665 | 13 |
| a@a.com | ANM | XXXX | Caraman | +4072XXX2800 | 1961 |
| a@a.ro | unify | 6074c6aa3488f3c2dXXXXXa7ca821aab | pocora sebastian | +40722XXX153 | 200100 |
| aaaa@meteo.inmh.ro | ANM | 57ca32d682e919cb0XXXXX35fc2e7d13 | Meteorolog | +4072XXX4447 | 28daniela28 |
| aadrf@k.ro | ANM | 25ff43ff0e4a2bfe4XXXXXf2793773c2 | Elena Toma | +4072XXX2816 | 2des |
| aanciu@yahoo.com | ANM | 19180972faf9e2696XXXXX8816315a0d | Ralita | NULL | 3E_Belgium |
| aavadim@yahoo.com | ASTRAL | cabdb1014252d39acXXXXX47e7d5fbc2 | daniel dragomir | +407XXX46542 | 68adi |
+————————–+————+———————————-+——————+————–+————-+

Leave a Reply