skip to main
|
skip to sidebar
Ignorance is the root of all evil ... ;-)
Exposing Digital In-security
Thursday, April 28, 2011
And you thought online booking is safe
INOX Movies features - A lesson in "designing secure web pages"
Vulnerable URL: hxxp://www.inoxmovies.com/seatlayout.aspx
Incase you don't understand what will be the bug, it will be a SQL Injection!
INOX Movies is "Safe"... Come on, it uses "http"... it's unbreakable! :D
0 comments:
Post a Comment
Newer Post
Older Post
Home
Subscribe to:
Post Comments (Atom)
Blog Archive
▼
2011
(8)
►
October
(2)
How I got back a returning customer
Wow, Goodbye Steve?
►
August
(1)
iQuit... Steve job quits apple, what again?
►
July
(1)
Love Letters...
►
June
(1)
Note: Top 5 Database Breaches in 2011
▼
April
(2)
And you thought online booking is safe
APNIC runs out of IPv4 Address
►
February
(1)
Ignorance is "THE" root of all evil
►
2010
(7)
►
December
(1)
Back... To Security Testing
►
August
(1)
UIDAI Scheme - Or - Compromising my privacy?
►
July
(3)
Xchanging URLs now ;))
Xchanging SQL Injections with you...
Linux migration SNAFU
►
May
(1)
U Socket - USB Charging directly from plug points
►
February
(1)
No pun intended
►
2009
(7)
►
October
(1)
Evil Maid - Pwnie for Overhyped bug
►
July
(1)
R.I.P - Fravia, the master
►
May
(1)
Warning: Don't be conned
►
April
(2)
Getting passwords with P2P
Recession ? Okay, but still cigarettes, gutkha, ...
►
March
(1)
How to get Examworx dumps for FREE, with a special...
►
February
(1)
My good friend and fellow hacker, Digi from Crimem...
►
2008
(4)
►
October
(2)
Worked @ _some company_ for 15 months, it was quit...
As many people think Iam dead ... I just want to r...
►
January
(2)
Just nitpicked a small xss, which could've been sp...
"Hacker Safe" Site Hacked, Data Stolen - Or not so...
►
2007
(28)
►
November
(1)
Few good links that can help you unbrick your iPho...
►
October
(3)
It's XSS snack time of the day... Paypal is secur...
Google chat can be blocked, without blocking googl...
I was invited to speak in LegionSec 07 conference,...
►
September
(2)
THE website is back, yes, the one and only CRIMEMA...
The code displayed below is from MXtreme firewall,...
►
July
(2)
A picture of the M927 warhead, containing 2.63 kg ...
Actual tests website bug ;)A specially crafted url...
►
June
(1)
A random line from my arsenal of quotes ... HE'S ...
►
May
(6)
Time for serving today's pwnsauce (morning_wood* t...
Quote from "For a few dollars more" , 1960 somethi...
We present to you ... www.usablesecurity.com !Secu...
Presenting the XSS Trio ;)Site: www.googlefont.com...
Hew Griffith, the ex-DoD council member, has been ...
Quoted from ArsTechnica, a kid got kicked outta sc...
►
March
(5)
Full headers of the phishing email ...X-Apparently...
Update from jf -at- danglingpointers -dot- net. S...
Is OWASP vulnerable ?Check this out, the code show...
Site: www.techworks.in Multiple XSS bugsRisk: Medi...
Originally posted on the 14th of Feb, Yeah, Iam s...
►
February
(6)
Site: www.tcs.com (Tata Consultancy Services)Multi...
Got a reply from them, they want to fix it now :)M...
Posted to Full-Disclosure list, copied to LegionSe...
I never expected them to reply but they did ! What...
►
January
(2)
►
2006
(40)
►
December
(5)
►
November
(2)
►
October
(3)
►
September
(2)
►
August
(1)
►
July
(1)
►
June
(2)
►
May
(3)
►
April
(4)
►
March
(5)
►
February
(8)
►
January
(4)
►
2005
(4)
►
December
(4)
About Me
Scarlet Pimpernel
Interested in RCE / Hacking / Coding ... and random things in life ;) Everybody is into computers these days. Who's into yours? ;)
View my complete profile
0 comments:
Post a Comment