Description: Found a way to abuse old unused code to login as any user with just his passhash and userid. Proof of concept gave him to get full administrator access on the site.
# 2
Description: A major SQL injection was found in the IRC stats page!
# 3
Description: StenoPlasma found a SQL injection in the search feature of the rankings page which potentially allowed him to read arbitrary data from the database.
# 4
Description: StenoPlasma found a vulnerability in the source viewing script which allowed him to view any file on the server. He also found the same flaw in another script shortly after.
# 5
Description: Nines9 and StenoPlasma found a CSRF vulnerability in the Forum BBCode that allowed them to make themselves site administrators, log out users, flag comments, accept and delete IRC linked Nicknames, etc.
Cheers for the congrats :D It needs updating since it was in Realistic 11 (and there's no info) and evinyatar should be added for it too since we both found it. :)
By: hack4urlife - 10:54 pm Saturday April 19th, 2008
BUSINESS OPPORTUNITY! I have a mission for you, should you choose to accept it. I need elite hackers, e-mail me on nines9@hts.org for briefing. Good luck private.
that is some heavy stuff hacking HTS so you could do anything lol, if i can become have the hacker you are i would be pleased!
keep up the good work :D
By: Desalator - 07:56 pm Thursday August 14th, 2008
I know that everyone on this sight nows sql injections how do i use to get a password
By: zcrxsir88 - 10:26 pm Thursday August 21st, 2008
Sup doood!!!
By: c24lightning - 12:46 pm Friday August 22nd, 2008
You ought to write an article or two!
This site is the collective work of the
HackThisSite staff. Please don't reproduce in part or whole without permission.
Page Generated: Thu, 28 Aug 2008 17:46:26 -0500 Exec:
239