ESET NOD32 Taiwan Full Disclosure
Posted by isrtinkode
on March 22, 2010
#NOD32 Taiwan@ TinKode - RomaniaAbout ESET:
ESET is an IT security company headquartered in Bratislava, Slovakia that was founded in 1992 by the merger of two private companies. The company is privately held and has branch offices in San Diego, California; Wexford, Ireland; London, United Kingdom; Buenos Aires, Argentina; Prague, Czech Republic and Kraków, Poland.
Vulnerable website: www.eset.com.tw to MySQL Injection.
Main Informations:
Version : 5.0.45Database: nod32twnewDatadir : /var/lib/mysql/User : censored
Databases:
information_schemamysqlnod32twnew
Tables from main database:
We have permission to access mysql.user accounts:
articlecategoryenterprise_applyestore_productestore_product_20100106estore_product_categoryestore_product_category_20100106estore_product_copyfaq_categoryfaq_category_detailgame3managernodtwflash1registerregkeyreplacetrial30updates
MySQL.user account:
Accounts from manager table:
censored :censored
The accounts are in plain-text… great!
admin :censorededitor :censorednod32@tw :censoredsoman :censored
Now some keys from “ censored key censored “:
~Verry simple!
J102- censored :J112-censoredJ102- censored :J112-censoredJ102- censored :J112-censoredJ102- censored :J112-censoredJ102- censored :J112-censoredJ102- censored :J112-censoredJ102- censored :J112-censoredJ102- censored :J112-censoredJ102- censored :J112-censored- …
Other webservers of ESET NOD32 hacked: NOD32 Hong Kong & NOD32 Romania
~Thanks, TinKode





