Burmese Classic

PlanetCreator has reported another critical Blind SQL Injection (vulnerability) on http://www.burmeseclassic.com/

This vulnerability has been alerted to :- Webmaster of BurmeseClassic

Applications: ———— PlanetCreator’s_Universal_Advanced_Internet_Security_T00L
System Time: ———— (UTC+08:00) Yangoon, Myanmar , 07/08/2010 02:28:46 AM

Database :————- burmesec_pawtin

Tables :—————-

youth_qna
youth_news
youth_corner
video_review
video
users
thuta
tayar
sports
song
servers
sayadaw
news
mtv_thingyan
mtv
movies
movie_rate
message
left_menu
health
files
ebook_writer
ebook
dhamma_qus
dhamma_ans
comment
cartoon
buddhawin
baydin_qus
baydin_ans
banned_users
active_users
active_guests

Columns of users table

userip
timestamp
email
userlevel
userid
password
username

username    — password

bcadmin    —–  (just for vip members)

We hope that your security staff will look into this issue and fix it as soon as possible.

Explore More

Google Stuff

Querying for vulnerable sites or servers using Google’s advance syntaxes Using “Index of ” syntax to find sites enabled with Index browsing A webserver with Index browsing enabled means anyone

XSS Stealing Cookies

This method (XSS attacks) is for get the cookies users, so, for get information of users… and then, login into the account of the victim user…u will have to give

Investigate Google’s Gmail, Docs and other products: EPIC Petitions to FTC

Electronic Privacy Information Center (EPIC) a privacy group based in Washington, D.C filed a petition to Federal trade commission to investigate the Google’s cloud computing offerings. They asked FTC to