|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 141
Members: 0
Total: 141
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Adult Webcam site |
|
Posted: Wed Mar 22, 2006 3:44 am |
|
|
Lain |
Beginner |
|
|
Joined: Mar 22, 2006 |
Posts: 2 |
Location: Canada |
|
|
|
|
|
|
Hi there. I work on a webcam site that is pay by the minute for customers, but I noticed that all new accounts are generated randomly, i.e. you in fact do not need to log in to access the site or your account. You think the job sounded sketchy, just think about the security holes.
So, each account has a defined, randomly generated access point. As in, www.thewebsiteinquestion/i4ertjvhgrkejtdvgbkjerhngbknerhgb/verthvbekrjbhverv/lewrvblkerjghb=true
etc etc. So, every time you access that url you will enter your account. Sounds insanely low security, and it is. I would like to know if there is a way to access a list of these randomly generated urls in order to access client accounts and thus view my own webcam show from their login, and earn some extra cash.
I never got paid well as a computer tech, hence the job. I've never been good at site cracks either, so don't yell! |
|
|
|
|
|
www.waraxe.us Forum Index -> All other security holes
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|