Thursday, 25.04.2024, 07:14
Sepo's Hacking Page MainRegistrationLogin
Welcome Guest | RSS
Site menu
Section categories
Hacked by [48]
Defaced [1]
Xssed [0]
eNews (English) [6]
eNews (Russian) [0]
Vuln-Lab [0]
Gaming [0]
Other [0]
Our poll
Rate my site
Total of answers: 29
Statistics

Total online: 1
Guests: 1
Users: 0
Login form
  
Main » 2012 » May » 30 » Big Bang Theory Inspires Hacker to Find SQL Injection Flaw on ORNL Site
20:13
Big Bang Theory Inspires Hacker to Find SQL Injection Flaw on ORNL Site
Although he has previously stated that he doesn’t help governments address the issues that affect their public-facing websites, the hacker known as Gambit has changed his mind and reported an SQL Injection vulnerability to the Oak Ridge National Laboratory (ORNL.gov).

"I know I said I don't report to governmental sites. But I figured since I'll be going into the field soon as a pentester for hire I might as well add a few .govs to my resume as well,” he explained. 

He claims that a scene from The Big Bang Theory has made him focus his attention on the site of the ORNL.

"It’s a funny story on how I came across this, I was watching The Big Bang Theory, it was the episode where Sheldon hacks into ORNL to use their super computer to try and figure out the Jew’s (can’t remember his name) card trick,” he said.

That inspired him to take a look at the government organization’s website and, after some digging around, he came across an SQL Injection security hole in the Risk Assessment Information System section of the site.

According to Gambit, the facility’s webmaster failed to respond to his emails, but the vulnerability was fixed soon after he sent the notification. Since there isn’t any danger of misuse anymore, he has made available a screenshot that demonstrates the existence of the flaw, along with the email he sent to the administrator.

We will take this opportunity to remind security enthusiasts that responsible disclosure is the best way to go. Many companies refuse to give credit to white hat hackers who find security holes in their websites, but there are a lot of them that really appreciate the help.

Category: eNews (English) | Views: 838 | Added by: sepos | Tags: gambit, sqli, government site | Rating: 5.0/1
Total comments: 0
Only registered users can add comments.
[ Registration | Login ]
Search
Calendar
«  May 2012  »
SuMoTuWeThFrSa
  12345
6789101112
13141516171819
20212223242526
2728293031
Entries archive
Site friends
  • Create a free website
  • Online Desktop
  • Browser Kits
  • free counters
    Copyright MyCorp © 2024Website builderuCoz