Advertisement
Guest User

Oak Ridge National Lab SQLi report

a guest
May 29th, 2012
136
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.89 KB | None | 0 0
  1. @_G4mbi7_
  2.  
  3. I know I said i don't report to governmental sites. But I figured since I'll be going into the field soon as a pentester for hire I might as well add a few .govs to my resume as well. Its a funny story on how I came across this, I was watching The Big Bang Theory, it was the episode where Shelden hacks into ORNL to use their super computer to try and figure out the jews(cant remember his name) card trick. So I thought "hmm... I wonder if they would have any vulns in their site..." With a little patients I managed to located an SQLi in their Risk Assessment Information System. I reported the vulnerability to the webmaster of the subdomain, she fixed the vulnerability but sadly did not respond back to me. Here are the screenshots:
  4.  
  5. Vulnerability before patched: http://screensnapr.com/e/ao9e6g.jpg
  6.  
  7. Email: http://screensnapr.com/v/UvDSlM.jpg
  8.  
  9. Again the SQLi has been patched up.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement