Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-19 Thread webDEViL
Let's trust software from Microsoft or Apple. On Thu, May 19, 2011 at 12:33 PM, David Blanc davidblanc1...@gmail.comwrote: On Sat, May 7, 2011 at 6:53 PM, Xa Buri xab...@yahoo.com wrote: So who finally did it and when? ispy or d3hydr8? and I still don't buy the whole SQL Injection

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-19 Thread Vipul Agarwal
And let's trust HBGary. On Thu, May 19, 2011 at 7:03 AM, David Blanc davidblanc1...@gmail.comwrote: On Sat, May 7, 2011 at 6:53 PM, Xa Buri xab...@yahoo.com wrote: So who finally did it and when? ispy or d3hydr8? and I still don't buy the whole SQL Injection theory. There is no proof.

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-19 Thread Jeffrey Walton
On Thu, May 19, 2011 at 3:30 AM, Vipul Agarwal vi...@nuttygeeks.com wrote: And let's trust HBGary. :) On Thu, May 19, 2011 at 7:03 AM, David Blanc davidblanc1...@gmail.com wrote: On Sat, May 7, 2011 at 6:53 PM, Xa Buri xab...@yahoo.com wrote: So who finally did it and when? ispy or

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-19 Thread gold flake
Never trust an Indian software company. Sure, go ahead and trust the Pakis instead ;-) ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-19 Thread nix
Never trust an Indian software company. Sure, go ahead and trust the Pakis instead ;-) What's wrong with those countries? I've seen users from the both countries advertising services with words such as leading, professional and when we look at their contact emails, we'll find

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-07 Thread CnCxzSec衰仔
[ TABLES: 119 ] : jiaozhu table `jiaozhu` was made by the auto sql inject tool HDSI for a temp use... aparently this sql injection point have been f*cked by a chinese hacker before(maybe long long time ago)..:) On Sat, May 7, 2011 at 12:33 AM, d3hydr8 D d3hy...@hotmail.com wrote:

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-07 Thread w0lf
Hi The company CEO denies the attack claims that the images posted are fake :) http://packetstormsecurity.org/news/view/19110/CCAvenue-Denies-Hacking-Attack.html ~w0lf On Sat, May 7, 2011 at 11:36 AM, CnCxzSec衰仔 cncxzh...@gmail.com wrote: [ TABLES: 119 ] : jiaozhu table `jiaozhu` was

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-07 Thread Maciej Gojny
The same thing as the CCbill, CEO has denied that their portal has been hacked/ had SQL injection vulnerabilities. - MG Wiadomość napisana przez w0lf w dniu 2011-05-07, o godz. 11:53: Hi The company CEO denies the attack claims that the images posted are fake :)

[Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-06 Thread d3hydr8 D
** (+) Authors : d3hydr8 (+) WebSite : darkode.com (+) Date : 06.05.2011 (+) Hour : 08:21 AM (+) Targets : CCAvenue.com (Payment Gateway) (+) Document: ESA.int Full Disclosure (UPDATED) (+) Method : Hidden SQL Injection

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-06 Thread Chris M
But the encrypted everything right? On Fri, May 6, 2011 at 5:33 PM, d3hydr8 D d3hy...@hotmail.com wrote: ** (+) Authors : d3hydr8 (+) WebSite : darkode.com (+) Date : 06.05.2011 (+) Hour : 08:21 AM (+) Targets :

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-06 Thread Kai
adu_id adu_user adu_pwd adu_status dept_id remote_access mobile_number . . . Acc1041 Risk Risk A Acc lol, definitely a risky guy -- Cheers, Kai ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-06 Thread Xa Buri
[ + ] Date: Wed May 3 04:47:33 2011 ... -- Kindly disregard the previous report. I got the date all mixed up. hah! You must be joking right! Also where exactly was the *hidden SQL injection you said?? Cmon!

[Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-06 Thread d3hydr8 D
** (+) Authors : d3hydr8 (+) WebSite : darkode.com (+) Date : 06.05.2011 (+) Hour : 08:21 AM (+) Targets : CCAvenue.com (Payment Gateway) (+) Document: ESA.int Full Disclosure (UPDATED) (+) Method : Hidden SQL Injection