Search This Blog

Powered by Blogger.

Blog Archive

Labels

Showing posts with label Shad0w. Show all posts

FOX Sports website hacked and database dumped by Shad0w

One of Famous Fox sports website(foxsports.com) is hacked by a hacker "Shad0w".  He hacked the database using the SQL Injection vulnerability and leaked the data in pastebin. The leak contains the admin username and password(encrypted).





Vulnerability Details:
  • Type: SQLi(simple)
  • Vulnerable Link:http://o.qa.premium.foxsports.com/cre/fscom/index.php?site=20027
  • Database Leaked:http://pastebin.com/3f8erdKP
  • Hacker: Shad0w 

Suggestion:
The developer should fix the vulnerability immediately and change all password and id.