Blog Posts Tagged with "Julian Chang"

3ebd200287a032cf6d13d6b75a570c94

Full Frontal: Is it OK to Expose Weaknesses?

September 18, 2011 Added by:David Martinez

While it might be interesting and a bit exciting finding vulnerabilities in systems, keep in mind that reporting them to the appropriate people might be more hassle then it’s worth, especially when your doing it pro bono, as I discovered...

Comments  (0)

3ebd200287a032cf6d13d6b75a570c94

High Fashion, Low Security - Part Duex

August 25, 2011 Added by:David Martinez

I spy serious SQL issues… I had the hashes for the admins table, info from the customers table, as well as the full output of the transactions and users tables, which included MD5 hashes of CC numbers. The hashes were all 64-bits from a MySQL db, which means they were probably SHA256...

Comments  (0)

3ebd200287a032cf6d13d6b75a570c94

High Fashion - Low Security

August 15, 2011 Added by:David Martinez

In the end, I had the hashes for the admins table, full customer info from the customers table, as well as the full output of the transactions and users tables, which included MD5 hashes of CC numbers. The hashes were all 64-bits from a MySQL db, which means they were probably SHA256...

Comments  (0)