Loading....
Loading....

    Posted by unu in English News

    Posted on March 15th, 2009

    “Fast and reliable broadband and internet access, tv, plus email, sms, webspace, and top rated search”

    A huge portal with hundreds of thousands of registered users for different services. Same story. An unsanitized parameter allows an SQLi, thus access to the databases. In the first pic I concatenated the version, user, name of the db as well as the name of the tables we gain access to (you can see only a part of them).

    In the next picture you can see login data as well as personal data of the users (username, firstname, surname, company, telephone, regdate, lastlogin, email, password):

    In the last printscreen you can see some data from the customers data base:

    ————-

    RO Version

    “Fast and reliable broadband and internet access, tv, plus email, sms, webspace, and top rated search”.

    Un portal mare, cu sute de mii de inregistrati pentru diferite servicii. Un parametru prost sanitizat permite un sql injection, deci acces la bazele de date. In prima poza am concatanat versiunelea, userul, numele bazei de date si numele schemelor la care avem acces (doar o parte dintre ele se vad in poza).

    In urmatoarea poza se vad datele de logare, cat si personale (username, firstname, surname, company, telephone, regdate, lastlogin, email, password) ale clientilor:

    In ultimul print screen se vad niste date din bogata baza customers:

    Related Posts

    One Response to “Tiscali.co.uk allows acces to users info’s”

    1. TREND MICRO Countermeasures » An interview with HackersBlog Says:

      [...] A couple of days after this interview, HackersBlog released the details of their latest succesful compromise Tiscali. Once again, access to user data, including username, firstname, surname, company, telephone, [...]

    Leave a Reply

    Studio videochat bucuresti Studio videochat Bucuresti
    Download Muzica Filme
    Studio videochat Iasi videochat Iasi