Re: [Full-disclosure] Telecom/Chat Servers = 2.0.1.1 Blind Exploitation Attack Vulnerability

2011-08-27 Thread Xianuro GL
Hey, please do not spoof my email address, thanks xD ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Telecom/Chat Servers = 2.0.1.1 Blind Exploitation Attack Vulnerability

2011-08-27 Thread GloW - XD
think u have the wrong person buddy. xd On 27 August 2011 16:26, Xianuro GL xianur0.n...@gmail.com wrote: Hey, please do not spoof my email address, thanks xD ___ Full-Disclosure - We believe in it. Charter:

[Full-disclosure] Telecom/Chat Servers = 2.0.1.1 Blind Exploitation Attack Vulnerability

2011-08-26 Thread Xianuro GL
Over the last few days,seen a number of sites getting hacked with a malware script. It is done using the WQuery injection attack. WQuery ($username) $userdata = hub#; if (isPasswordCorrect($username:Bg, $pass:M25)) { $userdata = Bf%ByLogin($F20); ... } { AS BEGIN