pridels0.blogspot.com
- UNSECURED SYSTEMS -: October 2005
http://pridels0.blogspot.com/2005_10_01_archive.html
By r0t,der4444,cembo,VietMafia. Wednesday, October 26, 2005. Forums mazliet kust uz priekshu, ta ka bloga nebija pedejas dienas neviena jauna posta tad iemetu jums softu mazliet. Foruma ir pievonojushies paris jaunu moderu, domajams ka latvijas paplashinasies vel lielaka viss ir tikai sakuma stadija. Ka tiko iemetu tur intresantu rakstu par to ka krustevm izdevas elementari inficet virs 25000 komjuteru uztaisot tos par proxy serverim. Tas laikam ari viss no jaunumiem. Sunday, October 23, 2005. Integratio...
pridels-team.blogspot.com
-UNSECURED SYSTEMS-: Open Classifieds version 1.7.0.2 XSS Vuln.
http://pridels-team.blogspot.com/2010/09/open-classifieds-version-1702-xss-vuln.html
Sunday, 12 September 2010. Open Classifieds version 1.7.0.2 XSS Vuln. Vuln discovered by : r0t. Date: 12 September 2010. Affected versions:Open Classifieds version 1.7.0.2. Open Classifieds version 1.7.0. Versions also can be affected. Open Classifieds contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "desc","price","title","place" parameter in "index.php" and "subject" parameter in "contact.htm" isn't properly sanitised before being returned to the user.
pridels0.blogspot.com
- UNSECURED SYSTEMS -: PHPChain vuln.
http://pridels0.blogspot.com/2007/05/phpchain-vuln.html
By r0t,der4444,cembo,VietMafia. Wednesday, May 02, 2007. Vuln discovered by : r0t. Date: 2 May 2007. Vendor:http:/ www.globalmegacorp.org/PHPChain/. Affected versions: 1.0 and previous. PHPChain contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "catid" parameter in "settings.php" and in "cat.php" isn't properly sanitised before being returned to the user. Edit the source code to ensure that input is properly sanitised.
pridels0.blogspot.com
- UNSECURED SYSTEMS -: Crash.
http://pridels0.blogspot.com/2007/02/crash.html
By r0t,der4444,cembo,VietMafia. Wednesday, February 21, 2007. No new entries for long time , board is down more than half year. Everthing looks dead, so it was also. Lets say somebody from us had alot of jobs behind this scene other ones take some hollydays. But now i think we can continue wht we had started. I still miss contacts to Vietmafia and cembo,but guys if you read this post let me know if we can count of you in team. Just mail me krustevs at gmail. Or via icq 476010452.
pridels0.blogspot.com
- UNSECURED SYSTEMS -: September 2005
http://pridels0.blogspot.com/2005_09_01_archive.html
By r0t,der4444,cembo,VietMafia. Saturday, September 24, 2005. Manis nebus vienu nedelu. Velejos pateikt ka man pa darba darishanam ir jaaizlido uz kanadu vienu nedelju, bushu prom , tapec paskastites un guljas uz RaZbH pleciem , kuru shodien onlaina nesastapu. der4444 ipashi palidzet nevares , jo pashlaik vel tikai macas latvieshu valodu:) Apsolito video uztaisihu kad atgriezishos no komandejuma. Bet varbut ari RaZbH, bus laiks jus ar kaut ko jaunu iepriecinat. Paslaik forums downa, bet to noversim driz.
pridels0.blogspot.com
- UNSECURED SYSTEMS -: DVDdb XSS vuln.
http://pridels0.blogspot.com/2007/05/dvddb-xss-vuln.html
By r0t,der4444,cembo,VietMafia. Wednesday, May 02, 2007. Vuln discovered by : r0t. Date: 2 May 2007. Affected versions: 0.6 and previous. DVDdb contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "movieid" parameter in "loan.php" and "s" parameter in "listmovies.php" isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
pridels0.blogspot.com
- UNSECURED SYSTEMS -: come back
http://pridels0.blogspot.com/2007/03/come-back.html
By r0t,der4444,cembo,VietMafia. Tuesday, March 27, 2007. Check ur email krustevs at gmail. I dont see you on icq. All rights of this blog content is reserved by UNSECURED-SYSTEMS.com and Pridels Sec Crew [r0t,der4444,VietMafia,cembo].
pridels0.blogspot.com
- UNSECURED SYSTEMS -: AlstraSoft Video Share Enterprise - Information disclosure & SQL injection vuln
http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html
By r0t,der4444,cembo,VietMafia. Thursday, March 29, 2007. AlstraSoft Video Share Enterprise - Information disclosure and SQL injection vuln. Discovered by : VietMafia. Developer's site: www.alstrasoft.com. Script: AlstraSoft Video Share Enterprise. This script has a vuln which can be exploited by malicious people to disclose sensitive information and access to system as administrator. After we got access as a registered user there's a sql inj vuln in msg.php file. Poc : http:/ host/path/msg.php?
pridels0.blogspot.com
- UNSECURED SYSTEMS -: January 2006
http://pridels0.blogspot.com/2006_01_01_archive.html
By r0t,der4444,cembo,VietMafia. Tuesday, January 17, 2006. I wasnt more than week in .net and i see that xaPridel had posted some 0-day exploitz without public re-publishing. So, with public stuff i hope i will be back in this blog after 1-2 weeks . Also i will give in board some good stuff . Take care and stay tuned:} with Pridels Sec Crew. Saturday, January 14, 2006. EzDatabase 2.0 and below. EzDatabase 2.0 and below. This vulnerability was first disclosed at:. Registered globals = on OR off. Hi guys i...
pridels0.blogspot.com
- UNSECURED SYSTEMS -: November 2005
http://pridels0.blogspot.com/2005_11_01_archive.html
By r0t,der4444,cembo,VietMafia. Wednesday, November 30, 2005. Instant Photo Gallery SQL inj. vuln. Instant Photo Gallery SQL inj. vuln. Vuln dicovered by : r0t. Date: 30 nov. 2005. Vendor:http:/ www.instantphotogallery.com. Affected version:v1 and prior. If you need an elegant solution that allows you to create the kind of site that most professionals need, download Instant Photo Gallery and give it a try it's FREE! Input passed to the "cat id" parameter in "portfolio.php" and "cid" parameter in "con...