Форум АНТИЧАТ

Форум АНТИЧАТ (https://forum.antichat.xyz/index.php)
-   Forum for discussion of ANTICHAT (https://forum.antichat.xyz/forumdisplay.php?f=72)
-   -   SQL Injection on Yahoo (https://forum.antichat.xyz/showthread.php?t=137339)

Fugitif 25.08.2009 20:44

SQL Injection on Yahoo
 
Цитата:

greyhat hacker has discovered a critical SQL injection vulnerability in Yahoo! Local Neighbors discussion board website. The flaw can be used to read information about administrative and user accounts or upload a shell on the server.

Neighbors is a Yahoo! Local feature launched at the end of 2007 with the purpose of providing a place for people to exchange information about events happening in their local communities and other useful info. Yahoo! describes the site as a "practical discussion board for any topic - from neighborhood safety to contractor recommendations."

The hacker who discovered the vulnerability goes by the online nickname of "Unu" and had previously uncovered similar vulnerabilities in other high profile websites. He notes that despite finding SQL injection and cross-site scripting (XSS) vulnerabilities in Yahoo! websites before, this is the first time when he encountered a MySQL 5 server being used by the company.

The screenshots provided by the hacker reveal the databases available on the server, as well as the users with access to them. While connections with the "root" account can only be established from local IP addresses owned by Yahoo!, Unu points out that an account called "reply_mon" can be used to access the databases from any host.

More info and Screenshots:

http://news.softpedia.com/news/Yahoo...d-120044.shtml

mr.The 25.08.2009 21:43

OMFG! this realy works!

..::TROYAN::.. 25.08.2009 22:15

good!

.:[melkiy]:. 25.08.2009 22:20

very good!

mr.gr33n 26.08.2009 07:54

http://forum.antichat.ru/showthread.php?p=1480726
;)))

mailbrush 26.08.2009 09:40

mr.gr33n, your SQL Injection on suggestions.yahoo.com, but "hacker's" injection on local.yahoo.com :)

PS: My first post in this board:)

Oza 27.08.2009 13:08

Oe :) very good!!!

-Onotole- 28.08.2009 23:12

Nice work :)

Dinar 29.08.2009 21:32

Good!!!


Время: 03:38