Intel Website Hacked : Another SQL Injection From Unu

I know this news is petty late as the Intel website was down near 23rd of December of 2009. which you can say about 1 week ago.But when the website was hacked, it was lead down and was showing a message of “investigating the matter.”
This is a kind of pity on the Intel security engineers, but what can we do, if they don't pay to the security professionals....
Not only is the website vulnerable to sql injection but it also allows load_file to be executed making it very dangerous because with a little patience, a writable directory can be found and injection a malicious code we get command line access with which we can do virtually anything we want with the website.
Upload phpshells, redirects, infect pages with Trojan droppers, even deface the whole website.
0 comments:
Post a Comment