Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- -=-=-=-=-=-=-=-=-=-=--=--=-= Dropped by a no named Tophat -=-=-=--=-=-=-=-=-=-=-=-=-=
- FOR #OpIndia to Anonymous India #Phile report 1 out of ./67 attempts of Pentesting
- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
- Why?
- -> I understand, what i am doing, and censorship in India, is seriously disgusting and no way any hackers or an information enthusiasts would ever allow it. I am NOT a part of any working forces, and I am NOT taking any risks of the vulnerabilities and ways to exploit them shown here, this is given to Anonymous India, as per request. But personally I think, the Indian government has to go down, NIC does NOT really fit into the rules and regulations they provide, they blocked almost many informatics sites and the Telecom department is getting worse, so I don't mind disclosing my/T.O.F (3 Tophat Hackers working frequently) pentest to this labeling document. pWnage !
- =======================================================================================
- Possibility #1 :
- http://www.cbseresults.nic.in/ctet/ctet11.asp?regno=78932658
- Use Tamper data, and inject/change the referrer value to below:
- http://www.cbseresults.nic.in/ctet/ctet11.htm
- Inject the SQLi thereafter.
- Possibility #2 :
- http://darpg.nic.in/darpgwebsite_cms/login.aspx
- the error varies with the number of tries someone tries to access that particular resource.
- This happens because after every 5 [varies] hits on this UNIQUE RESOURCE LOCATOR from the same IP.
- It is logged into a file and that is currently missing over the server. so when it tries to append data to that file, it gets 404 and a server error page is delivered to the user. Useful maybe if more research is done. Microsoft .NET Framework Version:2.0.50727.3625; ASP.NET Version:2.0.50727.3634.
- Possibility #3 :
- http://informatics.nic.in/onlinenews.php?newsid=1426
- Time based Injection is maybe possible, but won't recommend touching it, they will monitor. And I don't want even my enemy's host that I use, to get logged there, lwal, so do it yourself, Lulz.
- Possibility #4 :
- http://www.pgportal.gov.in/UControl/
- Login page is somewhere there, but have to guess out the login page, and out of 99 possible random login page tries, I gave up on thinking it and possibly I will make a random (bruteforce type guessing combinations) for this special login. But I am not guessing anymore logically, because the login page seems to be setup randomly and with Knowledge. But I really sometime mess with the extra glitches, have fun with the below, Lulz.
- http://www.pgportal.gov.in/UControl/GetImgText.ashx?CaptchaText=Tophats+WERE+HERE
- ^that was captcha fun, nothing much there, have to find moar and moar possibilities.
- I am on my research and there are many more possibilities, out of all of them I found these convenient to mention it here, if I get something more interesting, I will inform you guys. And if I exploit and get IN/or make my mind to get "IN" anyways, I will handover the information to you, I don't care about the mass media lurking around and stupid funny fat face 3rd party people, gotcha go, later !
- ===========================================================================================
Advertisement
Add Comment
Please, Sign In to add comment