• Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
AnonyViet - English Version
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
AnonyViet - English Version
No Result
View All Result

How I hacked a school’s website

AnonyViet by AnonyViet
January 24, 2023
in Security
0

This hack is for educational purposes only, so that new bug hunters can exploit the same method and responsibly disclose security issues to the owners of the site.

Join the channel Telegram of the AnonyViet 👉 Link 👈

How I hacked a school's website

The Covid-19 pandemic has moved everything from offline to online, so schools need a website to manage data related to their students, including their activities, assignments, tuition fees. , points, etc. So I will use the website https://ugtfdxlm.com as an example.

I opened the website and started accessing the various links present on it with burp running in the background. It’s mostly a static site with .html pages so not much can be found in those pages. Eventually, I started using burp to crawl on the domain that displays many of the resources contained in the site. I found some php pages but didn’t have any interesting information.

How I hacked a school's website 12

How I hacked a school’s website

Hole 1

Then I see a subfolder that burp crawler found, such as xhjcso the URI becomes https://ugtfdxlm.com/xhjc. I opened it and there is also a php page whose function is to take the student’s unique admission number and DOB as input and display the tuition details related to that student. This seems to be a vulnerable place. I entered a random admission number and the DOB and submitted it, which throws an error because the numbers are random. But this makes a GET request, for example that request is https://ugtfdxlm.com/xhjc?stud_id=87263&dob=2011–01–23.

Seeing this type of URL, my instinct tells me to add the calculated payload of SQLi in the request i.e. https://ugtfdxlm.com/xhjc?stud_id=87263’+oR+1=1+#&dob=2011–01–23 and send it. The error is gone and this means the site has the SQLi error. I did a little more digging into it and was able to dump a database of tuition fees for the rest of the students.

How I hacked a school's website 13

How I hacked a school's website 14

The details include sensitive student information such as their admission number, name, father’s name, DOB, mobile number, tuition details, etc.

How I hacked a school's website 15

Obviously I will not exploit this vulnerability more because my ethics do not allow and will not abuse this information. But what else can I do with this vulnerability? This is a common question among newbies. With this security hole, I can now upload my own reverse shell payload to the server, execute it, and the whole server will be under my or the hacker’s control. Also, if the user has the privilege of the INSERT INTO command then he can insert new rows or even update the rows, such as making the tuition zero, but all this is unethical. The following is the CVSS score that will be assigned to this vulnerability:

How I hacked a school's website 16

Hole 2

On the same page, I think to add some HTML tags in the GET parameter like https://ugtfdxlm.com/xhjc?stud_id=

HELLO HTMLi

&dob=2011–01–23 and send it.

How I hacked a school's website 17

I was able to fake the page content and prove that I can insert HTML into the web page. The following is the CVSS score that will be assigned to this vulnerability:

How I hacked a school's website 18

Vulnerability 3

Since the URL https://ugtfdxlm.com/xhjc?stud_id=87263&dob=2011–01–23 accepts tokens, it is also vulnerable to XSS vulnerabilities. The URL will become https://ugtfdxlm.com/xhjc?stud_id=&dob=2011–01–23.

How I hacked a school's website 19

Hackers can use this vulnerability to add their own form asking for DOB and number of students for admission and upon submitting the application, the hacker can get those details in the server using javascript. The URL could be sent to the parents and they could fall victim to a scam. That’s why HTMLi and XSS are also critical vulnerabilities. A CVSS score will be assigned to this vulnerability:

How I hacked a school's website 20

Vulnerability 4

Since I have found all possible vulnerabilities related to URL GET request, there are no other holes to test on cz domain other pages are static. And since this is a basic website, so there is a chance that there will be an error/misconfiguration on the site, I tested the Click jacking feature on the site. And it actually works cz the X-frame header is missing.

How I hacked a school's website 21

After I found these vulnerabilities, I wrote them an email, which was in the contact section of the website explaining to them the severity of these vulnerabilities, but they didn’t reply back, otherwise I helped them patch these vulnerabilities. The database that I received has sensitive information, hackers can also use this information for fraudulent purposes because most parents don’t know much about cyber security.

Anyway, I just wanted to share that anything in the public domain that is vulnerable to hacking is high risk, you never know what information could be misused in what way.

In addition, schools should also be aware of the severity of this type of data that is vulnerable to hacking, and should be equipped with more knowledge about cybersecurity.

The article achieved: 5/5 – (101 votes)

Tags: hackedschoolsWebsite
Previous Post

Lesson 179: How to generate random numbers in Excel

Next Post

Use Netcat to Transfer Files in Windows and Linux

AnonyViet

AnonyViet

Related Posts

How to use hackers use Splitfus to execute PowerShell malicious code
Security

How to use hackers use Splitfus to execute PowerShell malicious code

July 20, 2025
How to implement Shellcode Injection attack technique with Autoit
Security

How to implement Shellcode Injection attack technique with Autoit

March 14, 2025
How to exploit the holy hole of Hijacking on Windows
Security

How to exploit the holy hole of Hijacking on Windows

March 8, 2025
Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery
Security

Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery

February 10, 2025
Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile
Security

Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile

December 14, 2024
Capsolver: Automatic solution solution for business
Security

Capsolver: Automatic solution solution for business

December 12, 2024
Next Post
Use Netcat to Transfer Files in Windows and Linux

Use Netcat to Transfer Files in Windows and Linux

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest

guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recent News

Instructions for receiving 80GB of free data from VinaPhone from August 15

Instructions for receiving 80GB of free data from VinaPhone from August 15

August 15, 2025
Online driving exam preparation: Support theory and practice

Online driving exam preparation: Support theory and practice

August 15, 2025
How to add application to your favorite bar

How to add application to your favorite bar

August 14, 2025
Wowhay.com – The door opens the world of modern knowledge and network culture

Wowhay.com – The door opens the world of modern knowledge and network culture

August 13, 2025
Instructions for receiving 80GB of free data from VinaPhone from August 15

Instructions for receiving 80GB of free data from VinaPhone from August 15

August 15, 2025
Online driving exam preparation: Support theory and practice

Online driving exam preparation: Support theory and practice

August 15, 2025
How to add application to your favorite bar

How to add application to your favorite bar

August 14, 2025
AnonyViet - English Version

AnonyViet

AnonyViet is a website share knowledge that you have never learned in school!

We are ready to welcome your comments, as well as your articles sent to AnonyViet.

Follow Us

Contact:

Email: anonyviet.com[@]gmail.com

Main Website: https://anonyviet.com

Recent News

Instructions for receiving 80GB of free data from VinaPhone from August 15

Instructions for receiving 80GB of free data from VinaPhone from August 15

August 15, 2025
Online driving exam preparation: Support theory and practice

Online driving exam preparation: Support theory and practice

August 15, 2025
  • Home
  • Home 2
  • Home 3
  • Home 4
  • Home 5
  • Home 6
  • Next Dest Page
  • Sample Page

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí mm88 8XBET mm88 trang chủ new88

No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí mm88 8XBET mm88 trang chủ new88

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply