HACKED: www.proton-edar.com.my prone to SQL Injection Attacks

Saturday, March 7, 2009


Website: Proton Edar Sdn Bhd
URL: http://www.proton-edar.com.my/

From Proton Edar:
Proton Edar has achieved a commendable success in building PROTON brand name as the pride of the nation. Proton's success story is testimony of its product quality and excellent service.

An hour ago I found a vulnerability on perodua's website, now, another comes in. The similarities between these two company (if u dont know) is, both are leading companies selling cars in our local country. I think the main reason why their website is lack of security is because they are too busy selling cars. hmm.. ok.. thats acceptable.. Anyway, me myself owns a Proton Savvy. =)


Here it is, screenshot showing accessible databases. With user root, think of what you can do? load_file() and into OUTFILE function maybe? =)

0 comments:

Most Recent Post

MORE ON ARCHIVE
Widget by Mad Tomato

Help Me Expose This Article in Bulk!

Bookmark & Share

- OR -

SELECT YOUR PREFERRED ONE:

Bookmark and Share