Loading....
Loading....

    Posted by 2fingers in English News

    Posted on May 28th, 2009

    After my initial post where I was asking the staff of orange.co.uk for their contact details one of the vulns was already found by someone else and posted on RST forum. I am sorry they could not wait at least one day but nobody can stop people from making full disclosure at their own perusal. This could be a lesson for those site owners who do not think that having an email address where they could receive such as “your website has be breached” is important. We often wait 2 days sometimes just to find out who we should talk to and then wait another 2 for them to solve it. I dont find this very professional especially when we talk about a company of this size. We are talking about protecting their private data… But who are we to judge them?

    You can find the screenshot from RST here (only romanian ips can acces this page so you can use a romanian proxy if you want to see the discussions) and here.

    Initially this article was like this:

    daemien reported a new vuln in a page that belongs to Orange. This time it is Orange.co.uk.

    Here would follow some images and tables extracted from their data base but the image already posted on RST is pretty self descriptive.

    We would like to thank daemien for this report.

    PS: we hope the other vuln newly found will be fixed before any such issue would rise again.

    Versiunea in limba romana o puteti gasi aici.

    Related Posts

    One Response to “SQL Injection – Orange.co.uk”

    1. Kabron Says:

      E inca acolo ..

    Leave a Reply