+ Reply to Thread
Page 1 of 3 123 LastLast
Results 1 to 10 of 21

Thread: HowStuffWorks.com Gets Owned

  1. #1
    Spartan Erik's Avatar
    Spartan Erik is offline Retired Spartan Erik is an unknown quantity at this point
    Join Date
    Aug 2005
    Posts
    3,382

    HowStuffWorks.com Gets Owned

    http://sentient.us.to/images/owned.jpg

    Pretty humiliating if you ask me :naughty:
    Last edited by Spartan Erik; 02-24-2007 at 11:33 PM.

  2. #2
    Brandon's Avatar
    Brandon is offline Former Senior Account Rep Brandon is on a distinguished road
    Join Date
    Jun 2006
    Location
    Tewksbury, MA
    Posts
    9,589

    Re: HowStuffWorks.com Gets Owned

    LMFAO...WTF how did they get owned:thefinger

    j/k nice find
    Thanks,
    Brandon Long

  3. #3
    Livewire's Avatar
    Livewire is offline Abuse Compliance Officer Livewire is a glorious beacon of lightLivewire is a glorious beacon of light
    Join Date
    Jun 2005
    Location
    Behind a keyboard.
    Posts
    8,998

    Re: HowStuffWorks.com Gets Owned

    Huh. Guess they need to learn security.

    And unless I'm mistaken doesn't howstuffworks have guides on security (http://computer.howstuffworks.com/security-channel.htm )? Insult to injury ^_^


    Edit: Actually I think I can see how they basically faked it out - it's using radio buttons to identify what the selected answer is, and it's using post to retrieve it. But unless I'm wrong, POST can still be faked if someone knows what they're doing - what they need to do is actually check to make sure the answer submitted is a valid response XD

    At least it wasn't anything vulgar/explicit that they submitted, right?
    Last edited by Livewire; 02-25-2007 at 01:13 AM.


    TOS breakers will be suspended regardless of race, creed, national origin, hair color, or favorite food. Thanks for your understanding!

  4. #4
    Derek is offline Community Support Force Derek is a splendid one to beholdDerek is a splendid one to behold
    Join Date
    May 2005
    Location
    cossacks
    Posts
    6,354

    Re: HowStuffWorks.com Gets Owned

    LOl nice!

  5. #5
    Cubeform is offline x10 Lieutenant Cubeform is an unknown quantity at this point
    Join Date
    Aug 2006
    Location
    127.0.0.1
    Posts
    339

    Re: HowStuffWorks.com Gets Owned

    Hmm. It appears to be some sort of SQL injection attack. Maybe the folks at Howstuffworks.com should post an article on it.

    And right now, the ownage is still there. Go answer the survey on http://howstuffworks.com and see!
    Last edited by Cubeform; 02-25-2007 at 01:18 PM.
    CUBEFORM
    XHTML | CSS | PHP | JavaScript
    THIS WEEK


  6. #6
    Derek is offline Community Support Force Derek is a splendid one to beholdDerek is a splendid one to behold
    Join Date
    May 2005
    Location
    cossacks
    Posts
    6,354

    Re: HowStuffWorks.com Gets Owned

    Lol its stil there...

  7. #7
    dest581 is offline x10 Lieutenant dest581 is an unknown quantity at this point
    Join Date
    Sep 2006
    Posts
    348

    Re: HowStuffWorks.com Gets Owned

    Anyone want to advertise x10? :P

    I hope the programmer learns how to properly make surveys. It shouldn't be as easy to hack as modifying HTML.

  8. #8
    Spartan Erik's Avatar
    Spartan Erik is offline Retired Spartan Erik is an unknown quantity at this point
    Join Date
    Aug 2005
    Posts
    3,382

    Re: HowStuffWorks.com Gets Owned

    Quote Originally Posted by Spartan Erik View Post
    http://sentient.us.to/images/owned.jpg

    Pretty humiliating if you ask me :naughty:

    Wow, since that screenshot, many more people have hacked it.. some people even managed to put a vote for their own choice!

    The people at HSW ought to get that fixed.. 10 bucks says it's going to happen to every new poll they make unless otherwise
    Last edited by Spartan Erik; 02-25-2007 at 03:31 PM.

  9. #9
    dest581 is offline x10 Lieutenant dest581 is an unknown quantity at this point
    Join Date
    Sep 2006
    Posts
    348

    Re: HowStuffWorks.com Gets Owned

    Once you set up the modified page, voting is pretty simple. You just keep submitting. This is like basic HackThisSite levels :P

  10. #10
    Cubeform is offline x10 Lieutenant Cubeform is an unknown quantity at this point
    Join Date
    Aug 2006
    Location
    127.0.0.1
    Posts
    339

    Re: HowStuffWorks.com Gets Owned

    Oh my god. That is really insecure. You just have to modify ONE value and... it's really easy to hack. WOW. Suits them for having text as a value. None of that fancy injection stuff, you just have to use FireBug/Web Developer/Opera's Source editor! I put a value on there: "Is it this easy?" Yes. Yes it is.

    Yeah, they need a better polling system.
    Last edited by Cubeform; 02-25-2007 at 04:38 PM.
    CUBEFORM
    XHTML | CSS | PHP | JavaScript
    THIS WEEK


+ Reply to Thread
Page 1 of 3 123 LastLast

Similar Threads

  1. What was the first system you owned?
    By Kurther Reich in forum Gamer's Lounge
    Replies: 127
    Last Post: 11-04-2007, 12:12 PM
  2. Problema con dominio .uni.cc, owned by another user
    By sourcedominate in forum Soporte
    Replies: 2
    Last Post: 11-18-2006, 07:36 PM
  3. If you owned google for one day...
    By Brandon in forum Off Topic
    Replies: 11
    Last Post: 02-02-2006, 11:48 PM
  4. Domain owned by another user...
    By mserougi in forum Free Hosting
    Replies: 4
    Last Post: 11-17-2005, 02:25 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
x10hosting free hosting for the masses
dedicated servers