Author Topic: XSS worm results - umd.net  (Read 890 times)

0 Members and 1 Guest are viewing this topic.

Offline Undefined

  • NULL
  • Posts: 4
  • Cookies: 2
    • View Profile
XSS worm results - umd.net
« on: July 22, 2014, 05:22:35 am »
Dear fellow users,

Recently a xss worm was uploaded onto a "wet and messy" fetish website named "umd.net".
Users submit clips and sell them to each other, so there is money involved (this just got interesting)
Approx. 1000 login credentials were stolen.

Since i do this for the fucking lulz and have no intention of making money i'm leaving the L00T to you guys.
Have fun!

Pastebin link: http://justpaste.it/umd_net-passlist

- Undefined

Offline Undefined

  • NULL
  • Posts: 4
  • Cookies: 2
    • View Profile
Re: XSS worm results - umd.net
« Reply #1 on: July 22, 2014, 06:19:00 pm »
Sure no problem.
Also the website is still packed with vulnerabilities, fire at will.

New link: http://0bin.net/paste/Kt2YHDWJaNWt4NA5#Hoc0Q8dqG-gp2KF2zvyCtDOtAgK/qregdrKHMcIi/M4

Offline shimomura

  • Peasant
  • *
  • Posts: 57
  • Cookies: 0
    • View Profile
    • Shanaynay
Re: XSS worm results - umd.net
« Reply #2 on: July 25, 2014, 02:01:11 am »
They provided their users with new passwords, "for security reasons" lol They failed to mention that some one pwned the shit out of their weird and fucked up fetish site. I wish whoever accessed it in the first place would of just wiped the whole DB clean. 
Who gives a fuck what color the dress is...

Offline Undefined

  • NULL
  • Posts: 4
  • Cookies: 2
    • View Profile
Re: XSS worm results - umd.net
« Reply #3 on: July 25, 2014, 12:20:51 pm »
They provided their users with new passwords, "for security reasons" lol They failed to mention that some one pwned the shit out of their weird and fucked up fetish site. I wish whoever accessed it in the first place would of just wiped the whole DB clean.

Doesn't mean 99% of the users use the same passwords everywhere else haha, also the way these guys 'embed' videos onto their forum post is by allowing to add script tags so they can use their own little video player.