[Full-disclosure] Google PR Mechanism Possible Vulnerability

2006-07-10 Thread cumhur onat
e, which will finally increase the PR of "Page A" with the repeat of this process with different pages that contains css flaws. All this information is theoretic, and I never had time to spend for trying this.You can find the original version of this advisory on: http://www.hoccam.

[Full-disclosure] 30gigs SQL injection vulnerability

2005-11-16 Thread cumhur onat
I found a sql injection vulnerability, which leads to password disclosure in 30gigs.com email service. The vulnerability exists in http://www.30gigs.com/getpassword/ page due to lack of validation of user submitted data. Proof of Concept: enter http://www.30gigs.com/getpassword/ and copy & paster t

[Full-disclosure] Cerberus helpdesk

2005-11-04 Thread cumhur onat
ulnerability can lead to serious issues. regards, cumhur onat ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Internet Explorer / Outlook / Microsoft Office private exploit request

2005-06-18 Thread cumhur onat
I'm looking an out-of-the-box remote root exploit for www.bankofamerica.com Payment will be transfered by my account in Bank of America. Best Regards. Cumhur Onat :D On 6/18/05, Ivaylo Zashev <[EMAIL PROTECTED]> wrote: We'll double what the others are paying and send you free lo

Re: [Full-disclosure] Another PayPal phishing scam

2005-05-03 Thread cumhur onat
how cant authorities do anything about this servers? On 5/2/05, Julio Cesar Fort <[EMAIL PROTECTED]> wrote: Today I received a fake message pretending to be from PayPal SecurityCenter. The most intersting thing is that I don't even have a PayPalaccount.The fake PayPal link points to a possibly comp