web application security lab

fthe net - The name says it all.


Archive for April, 2007

Retarded MMS

Saturday, April 21st, 2007

So I get an MMS on my phone. Although my phone is running the Windows operating system, apparently it is incapable of getting MMSs. Here’s where my troubles begin. So I get a username and password and a website to log into. The website address does not contain a www (although that is necessary for it to function). Easily figured out. Next is the username and password.

So I look at the username, and I swear to you, it is something like “a1j4ufi3j2″ and the password is something super easy like “stats8bang”. So it takes me half a dozen times typing in the username to get it right, but the password is plaintext anyway (doesn’t even use the password type on the input box). Don’t ask me why they have utterly useless security. So I finally manage to log in and it just sits there. Oh, apparently this requires JavaScript. So I turn that on, hit refresh - sorry, no worky, gotta log in again… it continues to sit there. Uhh… switch browsers… log in half a dozen times… still sitting there… uhh… oh, I guess it’s loading something. Here I sit waiting, like a frozen idiot waiting for some stupid application to start loading…

Five fucking minutes later it loads a Flash movie for a stupid 30k image my girlfriend took of a funny sign. Ugh! So I try to download the picture embedded in the Flash movie using the hand dandy little download image button they have there. No, I’m sorry, that throws a JS error. Why? Why must you do this to me? I’m going to go punch my neighbor now - just cuz.

-RSnake