Jump to content

davidg80

New Members
  • Posts

    8
  • Joined

  • Last visited

    Never

Profile Information

  • Gender
    Not Telling

davidg80's Achievements

Newbie

Newbie (1/5)

0

Reputation

  1. http://www.arteinsania.net/site.php still gives paths
  2. i was able to login with: admin' OR 1='1 all personal data came up
  3. SQL Injection at: http://dreamshowstudios.net/members.php?user=Tester'%20AND%20'1'='0
  4. You should protect directory: http://dreamshowstudios.net/inc/ Better yet tell Apache/2.2.4 (Fedora) Server to handle .inc files with php. Do the same for all file extensions you use ex: .class,.php,.inc, etc.
  5. Completely bypass liveBetting verification by going to the display.php page. http://www.xpersa.com/live/display.php
  6. Full Path Disclosure: http://www.best-nights-out.com/index.php?page=place&placeid=a
  7. from: Neohapsis You can compile Apache without UserDir, you can totally disable UserDir, or you can enable UserDir only for specific users e.g. UserDir public_html UserDir disabled UserDir enable 11a But since most users only have control of their websites through something like cPanel for the "Remote Username Enumeration Vulnerability" you make a custom 403 error page by copying your 404 error page. This will only seem to generate 404 errors and will only allow users with valid index pages to be identified.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.