Tampilkan postingan dengan label Ethicalindians. Tampilkan semua postingan

Indian Ethical Hackers found a SQL injection flaw at Sify( sify.com). SQLi Vulnerability still exist in the site.

Ethical Hackers from India found a SQL Injection vulnerability at the high profile website sify.com. According to Ethical Hackers, they reported bug to site administration but they didnot respond to the vulnerability.

Website:
http://www.sify.com
Vulnerable link:
http://www.sify.com/imagegallery/gallery/img_view_sentcard.php?card_number=ss 
Vulnerability Type: 
SQL Injection
Status: 
Not Fixed [Critical]

About Sify:

Sify is an Internet service provider in India. Seventy five per cent of the 1.6 million visitors in 2008 to the web site sify.com hail from India. It was rated as one of "The ten top technology companies world-wide recommended for investment" by Fortune in 1999.

Sify was one of the first private sector player to offer internet access, when internet access was opened to private sector (until then the state run VSNL had a monopoly in providing internet access). It leased international bandwidth from global vendors, domestic connectivity from telecom players and set up last mile connectivity by multiple methods: wi-fi connections using roof top antennae, copper connections using phone lines or cable TV connections. Sify also started providing internet network connectivity for business enterprises in India. Sify set up a chain of franchised internet cafes (today a network of over 3,300+ cybercafes).


Description: Sify.com vulnerable to SQL Injection
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Sify.com vulnerable to SQL Injection


One of the subdomain (http://groups.adobe.com) of Abode site is vulnerable to XSS. The vulnerability is still not fixed by Adobe. Ethical hackers reported vulnerability a few days ago but they failed to respond. We got email from Ethical Indians.

Since the Bug Bounty Program started by companies, hackers are continually hunting different types of vulnerabilities of different top profile sites. Some site lists hacker on hall of fame page for the Bug Bounty and other offer reward for Bug bounty.

Web site:
http://groups.adobe.com

Vulnerability Type:
Cross Site Scripting (XSS)

Vulnerable Link:
http://groups.adobe.com/index.cfm?event=page.badpage&pageid=%3Cscript%3Ealert%28/Ethicalindians/%29%3C%2Fscript%3E

Status:
Not Fixed (No Reply)
Description: Adobe Vulnerable to XSS flaw
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Adobe Vulnerable to XSS flaw
Welcome to My Blog

Popular Post

Labels

Followers

- Copyright © 2013 shad0w-share | Designed by Johanes Djogan -