Full Disclosure mailing list archives

Re: jaillords.com hacked, login/password/email list


From: Hack Talk <hacktalkblog () gmail com>
Date: Tue, 8 Feb 2011 11:17:10 -0500

Probably not but I'm pretty sure someone that knows the admin that is
security inclined would notice it and alert the admins.


Luis Santana - Security+
Administrator - http://hacktalk.net
HackTalk Security - Security From The Underground



On Tue, Feb 8, 2011 at 10:46 AM, Paul Schmehl <pschmehl_lists () tx rr com>wrote:

--On February 7, 2011 11:58:50 PM +0000 Bob Smith
<bobbyhadababyitsaboy () googlemail com> wrote:

Weak passwords, no brute force protection,  lots of sql injections,
was easy to take full control of site

Heres the password files
[snipped]
admins fix ur shit or we will be back


Do you seriously believe that admins for a site like this would be reading
FD?

--
Paul Schmehl, Senior Infosec Analyst
As if it wasn't already obvious, my opinions
are my own and not those of my employer.
*******************************************
"It is as useless to argue with those who have
renounced the use of reason as to administer
medication to the dead." Thomas Jefferson
"There are some ideas so wrong that only a very
intelligent person could believe in them." George Orwell

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: