You are viewing a single comment's thread.

view the rest of the comments →

16337615? ago

I'm not l337 enough to hack this :(

16350044? ago

The security of that website is laughable. Each file can be easily downloaded:

http://www.teris.ch/download.asp?ogg=&name={filename}

Where {filename} is relative to e:/virtual/www.teris.ch/db/files/

If you want to take a look at page.asp, you just request:

http://www.teris.ch/download.asp?ogg=&name=../../www/page.asp

I haven't been able to find any exploits to enter the admin backend. I can only confirm that the username is definitely admin.

16357204? ago

The security of that website is laughable. Each file can be easily downloaded:

Oh but come on that's just…

http://www.teris.ch/download.asp?ogg=&name=../../www/page.asp

SERIOUSLY??

I for one am glad pedodevs are this fucking retarded.

open file

potential SQL injection just like that

I swear to God if I didn't have my hands full with life stuff I'd be learning web security to hack kike pedos.