« October 2005 | Main | December 2005 »

November 2005 Archives

November 24, 2005

Fireworks @ Post Oak, Houston, TX

Here are pictures of fireworks taken from my apartment balcony (facing Post Oak, Houston, TX) today. The fireworks were setup at a parking lot right in front of my apartment (see pictures 4 and 8) , so I had a great view:




November 23, 2005

Digg Vulnerable to XSS

While trying to use the ‘search’ feature on Digg, I realized that it is vulnerable to Cross Site Scripting (XSS). The search string is echoed back without proper output encoding. Example:

http://digg.com/search?search=%3Cscript%3Ealert%28%27vulnerable%20to%20xss%27%29%3B%3C%2F
script%3E&submit=Submit

I haven’t checked to see if the comments or new story submission modules are affected – if they are, things could get pretty messy. I have contacted the Digg team about this, lets hope they fix it soon.

Update: They fixed it this morning.

November 8, 2005

Papa John’s Pizza’s Corporate E-mails Still Exposed (thanks Google)

According to this posting on the Full Disclosure mailing list, Papa John’s Pizza’s web-based e-mail system was not password protected for a while. They have since fixed the problem, but Google currently has the information in its cache. The following Google query will let you see these e-mails (click on the ‘Cached’ links):

site:webmail02.papajohns.com PJFS

Now try the following query to find the more interesting e-mails:

site:webmail02.papajohns.com PJFS password

This brings me back to my previous article on using Google to find vulnerabilities. It isn’t enough for Papa John’s Pizza to fix the issue, for the exposed information is still available to the world via Google’s cache. I’m hoping they will contact Google and request for this information to be removed, but this may take a while to process.

Update: Google cache no longer contains the above information.

About November 2005

This page contains all entries posted to Nitesh Dhanjani in November 2005. They are listed from oldest to newest.

October 2005 is the previous archive.

December 2005 is the next archive.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type 3.35