Loading....
Loading....

    Posted by 2fingers in English News

    Posted on May 29th, 2009

    Finally the last reported vuln is patched, and we can post new infos about the third SQL Injection vulnerability in Orange websites.

    Now we are talking about  190 000+ exposed accounts with passwords stored in plain text.

    schema_name + version_user_database

    schema_nameversion_user_database

    User, email and pass (in plain text)

    useremailpass

    Submitted by unu.

    Patched by Orange.fr staff.

    Related Posts

    4 Responses to “Back with fresh news about Orange.fr intrusion(s)”

    1. David Says:

      I hope unu gets a good reward for doing this for orange :-)

    2. ifrim Says:

      I wonder what a online gsm shop from France would do with 190000 email addresses :) Maybe send a newsletter?

    3. David Says:

      Newsletter + SPAM :-)

    4. SQL Injections Are the Most Common Website Vulnerability Says:

      [...] I think it needs to be banged into some security professionals and developers heads. Last year HackersBlog had an interesting blog post.  This time they have angered multinational mobile phone operator and [...]

    Leave a Reply