Google
 

Archives for: April 2008, 03

04/03/08

Warning! BidOrBuy.co.za exploit

Permalink 01:06:20 pm, Categories: Current Events and News, Geek stuff, 181 words

For all of those on the South African http://www.bidorbuy.co.za website be very careful. Due to bad coding (as reported by Bradbowlllama on MyADSL ) it is possible for users to obtain your personal email address by simply going through the code.

To give an example:

- Find a user that is selling something you wish to bid on
- Click on the "Community Watch" link
- View the source on the "Report suspicious behaviour" page

Your result should look something like this:

INPUT class="dfont" TYPE=TEXT VALUE="communitywatch@bidorbuy.co.za" NAME="from1" SIZE=55 MAXLENGTH=100 disabled
INPUT TYPE="hidden" VALUE="youraddy@address.com" NAME="from"
INPUT TYPE="hidden" VALUE="otheruser@adress.com" NAME="cc"
INPUT TYPE="hidden" VALUE="123455" NAME="abcde"

As you will see, the email address of the user is easily accessible to anyone, including the hundreds of Nigerian scammers and identity thieves.

For those of you wanting to open an account at BidOrBuy... be very careful

This vulnerability is valid as of 3/4/2008 (Lets see how long it takes them to fix this very serious issue.

pickledbushman.com

My status

Contact Me

wtf is wrong with all you people?

 << <April 2008> >>
Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30      

Search

Categories

pickledbushman.com

Archives

Linkblog

leet software

leet sites

Who's Online?

Account

Sponsor


Linkage

ANTOWAN
CARLSPIES
FMTECH
SHUTTLEWORTH
SHOPBOT.CO.NZ
IAN FRASER
JHBLIVE.COM
NEWZ
ANTITRUST
HELLKOM
TAG
LIBRE
BEENZ

Syndicate this blog

powered by
B2/Evolution

I shmaak SA Blogs, sorted with Amatomu.com

Afrigator

Static Page 1
Static Page 2

Sponsor


Valid XHTML || Valid CSS || Valid RSS || Valid Atom