Showing posts with label INDI-HEX. Show all posts
Showing posts with label INDI-HEX. Show all posts

Saturday, 14 July 2012

Pakistan Social Networking Website Database Exposed

     BOZOPARK DATABASE EXPOSED BY INDI-HEX

Database Of BozoPark Social Networking Website of Pakistan Design By DigitalDesginBox DDB was hacked by Un_N0n Antil0g,C0d3 Inj3ctor & Ash3ll.More then 400 Username and Password Along with Admin Username and password were leaked by them.

LEAKED DATABASE HERE:- pastebin.com/iRSdhGb4
SCREENSHOT:-



Saturday, 7 July 2012

Lahore University Website Hacked By INDI-HEX

HACKED BY TEAM  INDI-HEX

National University Of Modern Languages Lahore Campus Website was Hacked By Indian hacking team INDI-HEX. No data was leaked from the site only the  front page was get defaced by INDI-HEX.

Website:-   www.numllahore.edu.pk

Thursday, 28 June 2012

How to Hack a Website with XSS Vulnerability

HACKING WEBSITE WITH PERSISTENT XSS

Today I had received tutorial on  Hacking website with the persistent XSS by INDI-HEX. If you remembered this is the group who had hacked the pakistan search engine URDUMAZA yesterday by same XSS attack. Let's have a look to the tutorial submitted by INDI-HEX

  • Use Google/Bing Dorks for finding XSS vulnerability in the site.And If you are lucky then atleast one site you will get with Persistent XSS Vulnerability.
                       
    GOOGLE DORKS:-                                

          inurl:".php?cmd="
        inurl:".php?z="
        inurl:".php?q="
     inurl:".php?search="
       inurl:".php?query="
    inurl:".php?searchstring="
   inurl:".php?keyword="
      inurl:".php?file="
     inurl:".php?years="
  inurl:".php?txt="
  inurl:".php?tag="
  inurl:".php?max="
  inurl:".php?from="
  inurl:".php?author="
inurl:".php?pass="
inurl:".php?feedback="
inurl:".php?mail="
inurl:".php?cat="
inurl:".php?vote="
inurl:search.php?q=
inurl:com_feedpostold/feedpost.php?url=
inurl:scrapbook.php?id=
inurl:headersearch.php?sid=
inurl:/poll/default.asp?catid=
inurl:/search_results.php?search=

  • Let take an example take this site urdumaza.com.pk
  • Look for webpage which has XSS Vul.
  •   eg:- 
  • urdumaza.com.pk/urdu-poetry/search.php
  • You can see a Search box on Top left hand side i
  • nsert Your C0de there. 
  • Like they have used  <h1>hacked by Un_N0n Antil0g</h1> As shown in video
  • Insert the C0de in that search box , and press Submit.
  •  A Webpage will appear , showing results. blah blah xD !! , ignore it.....
  • Then Goto Link --> http://www.urdumaza.com.pk/search 
  • When Page appears  , you can see The Code entered By you . 
  •   "As it is persistent XSS , Code will remain there forever.
  •     VIDEO TUTORIAL

  •    SUBMITED BY- Un_N0n Antil0g And C0de Hijacker-TEAM INDI-HEX