Showing posts with label Hacking !. Show all posts
Showing posts with label Hacking !. Show all posts

Tuesday, May 17, 2016

SQL VULNERABLE WEBSITES List 2016

SQL VULNERABLE WEBSITES List 2016
SQL VULNERABLE WEBSITES List 2016








##################################################################################
http://www.mygoodact.com/collectiondetailperson.php?id=212
http://www.medix.com.hr/aboutbook.php?id=33
http://vacationet.com/resort.php?id=2


http://www.orascomci.com/index.php?id=home
http://www.orascomci.com/index.php?id=talentprogram
http://www.bible-history.com/subcat.php?id=22
http://www.oiwsba.com/oiwsba/memberinfo.php?id=54
http://www.ci.bremerton.wa.us/display.php?id=221
http://www.pangeaday.org/filmDetail.php?id=74
http://www.vst4free.com/free_vst.php?id=187
http://www.cideko.com/pro_con.php?id=3




http://www.aradergalleries.com/catgallery.php?id=2
http://www.catholiccemeterieschicago.org/locations.php?id=11
http://www.orillia.com/index.php?id=22
http://www.medix.com.hr/aboutbook.php?id=30
http://hebron.com/english/gallery.php?id=170
http://www.carkitinc.com/carkit2.php?id=12
http://www.heavymetal.com/index.php?id=1520
http://www.sherrihill.com/content.php?id=registration
http://www.hebron.com/english/article.php?id=282
http://www.nickhawkexplicit.com/gallery.php?id=77
http://www.suagacollection.com/photo-gallery.php?id=1
http://www.daphne-emu.com/site3/faq_entry.php?id=59
http://overcomingapartheid.msu.edu/sidebar.php?id=5
http://www.myvegancookbook.com/recipes/recipe.php?id=16
http://orascomci.com/index.php?id=careers
http://www.thekenkirchoffteam.com/local_detail.php?id=166338
http://www.heavymetal.com/index.php?id=1946
http://www.bia2.com/video/player.php?id=17
http://www.bia2.com/video/player.php?id=37
http://jokusoftware.cz/file.php?id=icqj
http://www.nichegardens.com/catalog/item.php?id=1911
http://pokemon.supercheats.com/team.php?id=4059
http://www.uselitewine.com/index.php?id=1
http://www.ellafitzgerald.com/viewheadline.php?id=3418
http://www.bvfonts.com/fonts/details.php?id=45
http://mathman.dreamhosters.com/MathMan/Organization.php?id=7
http://www.vf-venieri.com/prodotto.php?id=2
http://www.teenmodeling.tv/join.php?id=5
http://www.magicwings.com/index.php?id=140
http://www.cochraneventilation.com/articledetails.php?id=9
http://remewing.118696.com/article.php?id=115
http://www.ladirectmodels.com/talent.php?id=829
http://www.sherylblais.com/index.php?id=5
http://www.southernpowerlifting.com/form.php?id=5
http://www.carkitinc.com/carkit2.php?id=5
http://cathedralhillpress.com/book.php?id=
http://gazetaonline.globo.com/noticias/radios/litoral/index.php?id=/fale_conosco/faleconosco.php
http://tf2mods.net/mod.php?id=20
http://www.bia2.com/video/player.php?id=13
http://www.bvfonts.com/fonts/details.php?id=76
http://www.bitaraf.com/showlink.php?id=1244923
http://www.carbodydesign.com/goto.php?id=27
http://www.type-o-tones.com/fonts.php?id=29
http://www.killfromtheheart.com/bands.php?id=7
http://www.orascomci.com/index.php?id=aboutus
http://www.bmepainolympics2.com/comments/showmore.php?id=358
http://www.malcolmx.com/about/viewheadline.php?id=546
http://www.kaza-deluxe.com/category.php?id=45
http://bostonhigashi.org/about.php?id=1
http://www.simplytobago.com/gallery.php?id=47
http://www.interplay.com/games/support.php?id=42
http://www.mircscripts.org/ramblings.php?id=151
http://www.facingthegiants.com/news.php?id=2
http://www.nypdangels.com/cop/cop.php?id=90
http://www.vf-venieri.com/prodotto.php?id=3
http://www.pixheaven.net/galerie_us.php?id=22
http://www.ever.be/c_page.php?id=277
http://www.irishsanghatrust.ie/news.php?id=33
http://ditto3d.com/gallery.php?id=7
http://www.goodingproductions.com/shop.php?id=6
http://cathedralhillpress.com/book.php?id=1
http://www.romanianwriters.ro/s.php?id=1
http://www.benayoun.com/projet.php?id=16
http://www.karnaticlabrecords.com/cart.php?id=88
http://countryfest.ca/page.php?id=72
http://www.ath-elite.com.au/trainers.php?id=25
http://tjff.com/film-info.php?id=1471
http://www.rupri.org/dataresearchviewer.php?id=6
http://www.snowdonia-society.org.uk/index2.php?id=5
http://www.sfu.ac.at/english/index.php?id=66
http://www.raahauges.com/view-news.php?id=8
http://www.clanwilliam.info/index.php?id=1
http://www.cjsf.ca/pguide/grid/description.php?ID=38
http://www.kitefestpasirgudang.com/Content.php?id=2
http://www.kyygames.com/games.php?id=2
http://www.sciencedomain.org/page.php?id=general-guideline-for-authors
http://www.simplytobago.co.uk/gallery.php?id=47
http://www.backstagecommerce.ca/services.php?id=4
http://en.swfplay.net/game.php?id=104
http://www.imaginenative.org/program.php?id=91
http://www.jelco.ca/en/product_detail.php?id=2
http://www.bitaraf.com/showlink.php?id=1689155
http://www.sarilocker.com/advice/qa.php?id=1167
http://lm.inlinkz.com/ar.php?id=69722
http://www.gamedogped.com/details.php?id=47469
http://www.bvfonts.com/fonts/details.php?id=79
http://www.orascomci.com/index.php?id=media
http://www.twitney.co.uk/theme.php?id=7
http://www.atavistic.com/albums.php?id=8
http://www.drumheadmag.com/web/education.php?id=4
http://www.sisterstates.com/statetaxforms.php?id=43
http://house.legis.state.ak.us/rep.php?id=leu
http://www.everyway-medical.com/products.php?id=2
http://www.konfor.com.tr/Product.php?id=
http://www.ameliaearhart.com/viewheadline.php?id=2950
http://www.kjworks.com.tw/productdetail.php?id=1
http://www.pixheaven.net/photo_us.php?nom=110913_5877-78
http://www.pixheaven.net/galerie_us.php?id=16
http://www.pixheaven.net/galerie_us.php?id=10
http://tjff.com/film-info.php?id=100
http://www.sciencedomain.org/page.php?id=reviewers-editors
http://learnzone.org.uk/courses/course.php?id=1
http://www.tidytowns.ie/interior.php?id=2
http://encycl.anthropology.ru/article.php?id=1
http://www.cobranet.org/about.php?id=1
http://www.trnres.com/ebookcontents.php?id=93
http://www.goldencards.com/send1.php?id=65
http://www.reklamaru.com/content.php?id=269
http://www.prworldwidelive.com/index.php?id=188
http://www.polkatheatre.com/event.php?id=6
http://www.firstgulf.com/search-details.php?id=59
http://www.urldominator.com/ro.php?id=540
http://www.colinst.com/brief.php?id=61
http://www.kidswithfoodallergies.org/resourcespre.php?id=99
http://cjsf.ca/pguide/grid/description.php?ID=116
http://www.creationcare.org/blank.php?id=39
http://www.melbournefineart.com.au/gallery.php?id=18
http://www.orillia.com/index.php?id=23
http://www.lift.org/staffdetails.php?id=36
http://www.imaginenative.org/program.php?id=99
http://www.sciencedomain.org/journal-home.php?id=9
http://www.jfuinsurance.com/insurance/index.php?id=1137
http://www.thornbridgebrewery.com/beers.php?id=2
http://www.coldexrents.com/price_list.php?id=9

Thursday, May 12, 2016

Pornhub Launches Bug Bounty Program; Offering Reward up to $25,000

With the growing number of cyber attacks and data breaches, a significant number of companies and organizations have started Bug Bounty Programs to encourage hackers and security researchers to find and responsibly report bugs in their services and get a reward.

Now, even pornography sites are starting to embrace bug bounty practices in order to safeguard its user's security.

The world's most popular pornography site PornHub has launched a bug bounty program for security researchers and bug hunters who can find and report security vulnerabilities in its website.

Partnered with HackerOne, PornHub is offering to pay independent security researchers and bug hunters between $50 and $25,000, depending upon the impact of vulnerabilities they find.

Also Read: 10-year-old Boy becomes the youngest Bug Bounty Hacker.

HackeOne is a bug bounty startup that operates bug bounty programs for companies including Yahoo, Twitter, Slack, Dropbox, Uber, General Motors – and even the United States Department of Defense for Hack the Pentagon initiative.
"Like other major tech players have been doing as of late, we’re tapping some of the most talented security researchers as a proactive and precautionary measure – in addition to our dedicated developer and security teams – to ensure not only the security of our site but that of our users, which is paramount to us," said PornHub Vice President Corey Price.

"The brand new program provides some of our developer-savvy fans a chance to earn some extra cash – upwards to $25K – and the opportunity to be included in helping to protect and enhance the site for our 60 Million daily visitors."

How to Earn $25,000 Reward


To qualify for a bounty reward, security researchers and bug hunters must meet the following requirements:
  • Be the first to report a security bug directly related to the company infrastructure.
  • Send a description of your bug report, explaining the type of vulnerability and how it works.
  • Include screenshots and proof of concept code to substantiate your claim.
  • Disclose your finding directly and exclusively with Pornhub.
The company is currently considering serious flaws that could compromise its server and entire website.

Vulnerabilities such as cross-site request forgery (CSRF), information disclosure, cross domain leakage, XSS attacks via Post requests, HTTPS related (such as HSTS), HttpOnly and Secure cookie flags, missing SPF records and session timeout will not be considered for the bounty program.

The bounty program has currently been in a beta phase, with the company extending it via invite only. You can read complete eligibility for the bounty program on HackerOne website
 source:thehackersnews.com

Hacker reports Vulnerability in Mr. Robot Season 2 Website

mr-robot-season-two
Mr. Robot was the biggest 'Hacking Drama' television show of 2015 and its second season will return to American TV screens on Wednesday 13th of July 2016.

However, the new promotional website for season two of Mr. Robot has recently patched a security flaw that could have easily allowed a hacker to target millions of fans of the show.

A White Hat hacker going by the alias Zemnmez discovered a Cross-Site Scripting (XSS) vulnerability in Mr. Robot website on Tuesday, the same day Mr. Robot launched a promo for its second series.

The second season of the television show had already received praise from both critics and viewers for its relatively accurate portrayal of cyber security and hacking, something other cyber crime movies and shows have failed at badly.

The new series also features a surprising yet welcome guest: President Barack Obama, who is giving a speech about a cyber threat faced by the nation.

The flaw Zemnmez discovered on the show's website could have given him the ability to perform many malicious tasks, but being a white hat, the hacker responsibly reported the XSS flaw to Sam Esmail, the creator of Mr. Robot series, Forbes reported.

USA Network’s owner NBC Universal confirmed that the website was patched late Tuesday night, hours after Zemnmez reported the flaw.

According to Zemnmez, the flaw could allow an attacker to inject malicious Javascript to steal user information, including Facebook data that Mr. Robot website visitors enter to participate in its quiz.
"A threat actor with XSS on whoismrrobot.com could [have used] the XSS to inject Javascript, which inherits the ability to read Facebook information from the fsociety game," Zemnmez told Forbes. "This could be done mostly silently if correctly engineered with a short popup window."
Also, the flaw could also be exploited using some simple social engineering technique like phishing to get site victims to click on a malicious link that executes the Javascript code, enabling attackers to steal Facebook user's real name, email address, photos and pictures they are tagged in, Zemnmez added.
Hacking is not always easy to explain on TV, but Mr. Robot is a smart and compelling show that accurately portrays the hacking culture and what hackers are really like. 
 source:thehackersnews.com

Saturday, May 7, 2016


Twitter Facebook

 
Powered by Blogger