http://dte.org.in
The chat page is the most vulnerable part of their website
Malicious Scripts can be directly sent / posted as a chat message
Script Kiddies with javascript expertise can make their site overloaded with unnecessary undesired unexpected chat traffic, even slow it down so much, that it becomes of no use.
Imagine such a situation, when students all over India are coming in to check exam results etc ...
(Important Critical Moments)
The page content can be changed to show objectionable content?
1).
Script Kiddies can wreak havoc on chat part of Website.
Please improve/include filter validation of chat messages
which should not allow running of script embedded in
messages
Implement validation in
http://dte.org.in/dtechat/message.asp
Using Client Side Javascript and also in ASP (Server Side)
To help reduce Bandwidth usage
And deliver better performance under load testing
May I help in anyway?
In redesigning that part of the website?
2).
And also
http://dte.org.in/feedback/feedback.asp
which submits data to
http://dte.org.in/feedback/feedback1.asp
doesnt accept feedbacks
It shows
Microsoft OLE DB Provider for SQL Server error
'80040e09'
INSERT permission denied on object 'Grv', database
'DEGREE', owner 'dbo'.
/feedback/feedback1.asp, line 8
It reveals database name as "DEGREE"
Hope you have performed thorough security testing of the
site to avoid SQL Injections etc ...
Why are they allowing this?
Virtual Defacing
Are they promoting this?
Height of irresponsibility & Stupidity
Plz Respond & Act
Indians cannot Accept their Technical Education (If it really stands for it) to be such a soft target.


0 comments:
Post a Comment