Loading....
Loading....

    Posted by 2fingers in English News

    Posted on May 29th, 2009

    After orange.co.uk it looks like Sugababes website is another victim of daemien curiosity.

    A post on RST (if you are outside of Romania click here) show us some info’s to prove that intrusion is real:
    LINK:http://sugababes.com/show-detail.php?id=27
    Server = Apache/2.2.0 (Fedora)
    Version = 4.1.12
    Powered by = PHP/5.1.2
    Current User = sugababes@vv44web01
    Current Database = sugababes
    Supports Union = yes
    Union Columns = 8

    Tables:phpbb_users

    phpbb_users
    diary
    news

    Columns: Table phpbb_users

    username
    user_email
    user_icq
    user_id
    user_level
    user_password

    You can see some users and passwords hashes too and the vulnerable parameter posted by benny_loppa.
    The Net is a new playground for the new generations.

    Related Posts

    2 Responses to “Sugababes.com – SQL Injection”

    1. dblackshell Says:

      eh, nu chiar asa de dulci precum ar parea… :)

    2. David Says:

      So simple to prevent SQLi attacks and so many vulnerabilities out there, even on critical websites (not talking about this one of course) :-)

    Leave a Reply

    Studio videochat bucuresti Studio videochat Bucuresti
    Download Muzica Filme
    Studio videochat Iasi videochat Iasi