Don't like ads? PRO users don't see any ads ;-)

PayPal.com SQL Injection Vulnerability

By: Reck on Jul 24th, 2013  |  syntax: None  |  size: 2.25 KB  |  hits: 1,497  |  expires: Never
download  |  raw  |  embed  |  report abuse  |  print
Text below is selected. Please press Ctrl+C to copy to your clipboard. (⌘+C on Mac)
  1.  /$$$$$$$                      /$$                  /$$$$$$          
  2. | $$__  $$                    | $$                 /$$$_  $$          
  3. | $$  \ $$  /$$$$$$   /$$$$$$$| $$   /$$ /$$$$$$$$| $$$$\ $$  /$$$$$$
  4. | $$$$$$$/ /$$__  $$ /$$_____/| $$  /$$/|____ /$$/| $$ $$ $$ /$$__  $$
  5. | $$__  $$| $$$$$$$$| $$      | $$$$$$/    /$$$$/ | $$\ $$$$| $$  \__/
  6. | $$  \ $$| $$_____/| $$      | $$_  $$   /$$__/  | $$ \ $$$| $$      
  7. | $$  | $$|  $$$$$$$|  $$$$$$$| $$ \  $$ /$$$$$$$$|  $$$$$$/| $$      
  8. |__/  |__/ \_______/ \_______/|__/  \__/|________/ \______/ |__/   2011-present
  9.  
  10.                                                                   twitter.com/Reckz0r
  11.  
  12.  
  13.       (                      )
  14.       |\    _,--------._    / |
  15.       | `.,'            `. /  |  xoxo
  16.       `  '              ,-'   '       xoxo
  17.        \/_         _   (     /xoxo
  18.       (,-.`.    ,',-.`. `__,'      xoxo      xoxo
  19.        |/#\ ),-','#\`= ,'.` |xoxo          xoxo
  20.        `._/)  -'.\_,'   ) ))|    xoxo
  21.        /  (_.)\     .   -'//            xoxo
  22.       (  /\____/\    ) )`'\xoxo   xoxo    xoxo
  23.        \ |V----V||  ' ,    \   xoxo       xoxo
  24.         |`- -- -'   ,'   \  \      _____
  25.  ___    |         .'    \ \  `._,-'     `-
  26.     `.__,`---^---'       \ ` -'     lil' devil is shy as fuck under em' sheets omfg
  27.  
  28.        -.______  \ . /  ______,-
  29.                `.     ,'            
  30.  
  31.  
  32.  
  33. -----
  34.  
  35. Today, I located a MSSQL injection vulnerability (yes, you heard that right) in PayPal.com (and you heard that right too), finding a vulnerability in PayPal.com is rare as fuckin' fuck. High-class security researchers from Offensive-Security and other gangwar-skiddie groups fail to locate anything in PayPal, but fear not, as I shall now jizz all over PayPal.
  36.  
  37.  
  38. Basically, their site is full of shit, like total dogshit. Running mySQL-extensions and msSQL is a bad fuckin' idea, I mean, who the fuck would make Linux & Windows cuddle eachother? that's just absolutely nonsense!
  39.  
  40. Screenshot of the Vulnerability: http://t.co/LRMLQ5wSeT
  41.  
  42.  
  43. Although, my main plan was to brutally expose PayPal infront of deh intertubez, leak all their usernames and passwords, and moar goodiez...but we're not gonna talk about it now.
  44.  
  45. I guess, this is pretty much it, folks!
  46.  
  47. regardz,
  48. your old pal
  49. reck