Author | Post | |||
unknown user |
Recently posted about the soft hyphen in "cool hacks" thought i'd share one site i know that's vulnerable (because i just tested it) i went through some of the sites on the link page I just registered Electrica with password testtest but beware there is an \xAD character in there the username was created with echo -e "Elec\xADtrica" you could now post messages as "Electrica" or you could register Cae\xADsum .. and be all devious and/or bloody annoying Aren't vulnerabilities in fellow challenge sites all the "cool"? Do I get extra karma points for posting it first on Bright-Shadows? ps: it's nifty, you'll see that you can copy paste the username from above, and use it with the password given. but it won't work if you just type the username (without the softhyphen) |
|||
22.06.2007 23:10:50 |
|
|||
Caesum |
Hmm, I'll have to do something about that! |
|||
10.09.2007 15:33:43 |
|
|||
alt3rn4tiv3 |
Cool. Caesum still appears here? |
|||
11.09.2007 03:40:17 |
|
|||
Caesum |
should be fixed now. |
|||
21.01.2008 18:22:20 |
|
|||
quangntenemy |
Maybe too late |
|||
22.01.2008 01:29:28 |
|
|||
DigitalAcid |
Better late than never . |
|||
22.01.2008 11:08:48 |
|