payment-gateway

News Roundup: 9 million 3G users in India, Payment Gateway from RIL?

by Paul Joseph May 20, 2011 Featured
0 comments Read the full article →

Payment Gateway CCAvenue Hacked (?)

by Paul Joseph May 5, 2011 Featured

Payment gateway, CCAvenue it seems was hacked by hackers via exploiting SQL injection vulnerability. As per this site , Hacker identifying himself as d3hydr8 has shared the hack report with them and it seems that ccAvenue stored the password in plain text! Below is a report belonging to this compromise —————— [ + ] USER ()                         : iusr_ccavenueiusr_ccavenue [ + ] S_USER ()                    : iusr_ccavenue [ + ] DB_NAME ()              : gateway [ + ] HOST_NAME ()         : AV-2 [ + ] SERVER_NAME ()   : AVDB-3 [ + ] SERVER_TYPE ()     : Apache/2.2.14 (Unix) mod_ssl/2.2.3 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.28 [ + ] X-POWERED-By ()    : Servlet 2.5; JBoss-5.0/JBossWeb-2.1 [ + ] IP_ADDRESS_INFO  : 124.153.83.27 ———————————————————————————————————- [ + ] Displaying list of databases on this MSSQL host ! [ DATABASE: 0 ]        : gateway [ DATABASE: 1 ]        : master [ DATABASE: 2 ]        : tempdb [ DATABASE: 3 ]        : model [ DATABASE: 4 ]        : msdb [ DATABASE: 5 ]        : Reseller – Storing password in plain text – and that too by a payment gateway?

0 comments Read the full article →