![]() |
|
Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: Hacking (https://sinister.ly/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.ly/Forum-Website-Server-Hacking) +--- Thread: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website (/Thread-Threaded-Mode-Linear-Mode-open-redirect-vulnerability-In-Cristiano-Ronaldo-website) Pages:
1
2
|
Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - Snow_mybb_import12418 - 07-05-2014 Hi all
![]() I found a bug on the official website localhost Enj0y ![]() PHP Code: http://www.localhost.com/out.php?out=http://www.hackcommunity.com&utm_campaign=downloads-links&utm_content=downloads-vivaronaldo&utm_medium=gamebyronaldo&utm_source=downloads&utm_term=downloads-gamebyronaldo
RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - Netero_mybb_import16981 - 07-05-2014 I don't think sharing these kind of things is allowed in the forum. We are ethical hacking forum ![]() @maxx have a look if you can. RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - Snow_mybb_import12418 - 07-05-2014 (07-05-2014, 01:38 AM)Netero Wrote: I don't think sharing these kind of things is allowed in the forum. I know, but I find this bug myself
RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - Netero_mybb_import16981 - 07-05-2014 (07-05-2014, 01:44 AM)Snow Wrote:(07-05-2014, 01:38 AM)Netero Wrote: I don't think sharing these kind of things is allowed in the forum. Brother it's not about finding it yourself or not. There have been incidents which a one of the forum members found a hack or vulnerability and decided to share it Mods said don't do that again. So in that regards I find what you are doing same as what he did. //Edit: best thing I suggest you to do is contact the website and tell them that. RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - chmod - 07-05-2014 We don't mind the discussion of vulnerabilities here, in fact we encourage it, but we don't want the vulnerable website/server etc posted. Proof of concept is allowed but the actual website used should not be mentioned. I have edited the post to remove all identifying information to avoid other people using this for bad things. Just a suggestion but maybe you could go into a little more depth about how this works and what the impact of the vuln is. And as a bonus a way to fix it would be much appreciated. As @"Netero" mentioned you should report this to the site owners and help them make their site more secure. RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - Netero_mybb_import16981 - 07-05-2014 Thanks for better explanation @chmod didn't know that part
RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - Isaac - 07-05-2014 That's quite a find mate, nice work! Have you decided to report it yet? Personally, I'd use this to break into their website and completely destroy it in order for them to realize the intensity of this threat, since nowadays people don't give any rewards or even a simple email saying "thanks" for your efforts. This is the reason why I don't report vulns anymore. If you do decide to report it, then I hope they acknowledge your work. Edit : Just to clear things up, this is only my opinion. If you disagree then that's fine, but please, don't start flaming me for having an unpopular opinion. RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - The Real Slim Shady - 07-05-2014 (07-05-2014, 12:38 PM)XrpmX13 Wrote: Personally, I'd use this to break into their website and completely destroy it in order for them to realize the intensity of this threat, since nowadays people don't give any rewards or even a simple email saying "thanks" for your efforts. This bugs me. You're suggesting you/he/people should be a fucking prick because you assume the person isnt going to be appreciative or reward you. and even if they arent appreciative, or do not reward you - why does this necessitate being an asshole in return? If you want to get paid to pen test, find a job in that field. This concept of ethics you have is akin to robbing someones house if they left the window open - suggesting you did it to prove the the intensity of the issue because they probably wouldnt be appreciative of you sneaking around their house trying to break in. Your just using poor logic to justify an unethical action. RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - BroZix - 07-06-2014 (07-05-2014, 02:37 PM)Geoff Wrote:(07-05-2014, 12:38 PM)XrpmX13 Wrote: Personally, I'd use this to break into their website and completely destroy it in order for them to realize the intensity of this threat, since nowadays people don't give any rewards or even a simple email saying "thanks" for your efforts. Don't want to get into the middle of so called war but I will say few words regarding that problem. Some day I found vulnerable device which was just "out there" on the internet of course I have investigated it and it appeard that some company could lose their money because of it. I had reported this right away to them but well ... After like 3 or 5 months after the report they didn't even care to respond to me and this still works... ![]() I also in the message described what's the problem is and how to resolve it but they simply don't care .... Anyway I don't defend or approve XrpmX13 behaviour in any way and just speak about my experience which I had when I was playing around some weekend for fun. Tho I must agree on some parts with XrpmX13 because some companies don't care even if you report it to them and spoonfed them how to repair it which is very sad in my opinion ┐('~`;)┌ RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website - The Real Slim Shady - 07-06-2014 (07-06-2014, 02:15 AM)BroZix Wrote:(07-05-2014, 02:37 PM)Geoff Wrote:(07-05-2014, 12:38 PM)XrpmX13 Wrote: Personally, I'd use this to break into their website and completely destroy it in order for them to realize the intensity of this threat, since nowadays people don't give any rewards or even a simple email saying "thanks" for your efforts. I think you missed my point. I am well aware that some companies dont care, dont react quickly, and/or are not appreciative. That doesnt excuse being a cunt though, especially if you havent even attempted to address the vulnerability with the vendor/company. |