About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2004-12-30, 05:50
Willvon Willvon is offline
Regular
 
Default Yahoo small business password exploit

https://edit.client.yahoo.com/sbc/swh/merge_new_reg?.ea=hcRRYp.qMlS_LySDQn.VckFN.yKGazHk fLZc2v28te9iuhcM6nFSsTqGrocIiKqmBQ_WBeiq5UDiCqGDWO n.arG88U_jYB8tPwJv4.jmmSG9ZjMUqbwxKhAFQG9t IDimVTMIYLQ6e27nI58ml9NBXc9UiT9mA7cMk7sYxg4nL4WJcq N000OaLcM1YpBEANohKrhZfpxJA_CcYhEjlrVaSChYFSFRh389 v9HzjIPGoIMQD6p8qstmKUdxYj9YrvHiQt6t8czvLcFU.q_mhe 8D_T2e._xpi9ERlTZwHgZTfIyEQ_pX 39pZoEsTC9RpoJbugI.ILP7_WMo4Htuf_5ludbipBUliirY5mT nTb5fSgUi.Cu9DCVz7LMtUNr_so6tQ4l03tv1Tgium4.pKYREp dN0yrSr8UI6Apg5OzD4cy5i7Pb3lWHkQrzu2fdEiz5EOkQMFk2 yIVLd94PNeN_jd&.partner=sbc-sw h

That "link" takes you to the yahoo small business screen where you can merge your IDs. All this does is allow you to transfer your yahoo info to your new yahoo business account with out having to make a new log in.

Anyways after you type in your name and pw it takes you to a screen where you can type in your info for your new small business account, but if you look at the source code it has your yahoo account pw in plain text.

I know this can be exploited... any ideas?

If not... there is one use for it. The url at the top doesnt have a log in attempt limit so you dont have to change proxies to log in. In other words you can try to brute force a name from there and it wont lock the account.

[This message has been edited by Willvon (edited 12-30-2004).]
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics