Skip to content
Permalink
main
Switch branches/tags
Go to file
 
 
Cannot retrieve contributors at this time
<title>Security is a Myth!</title>
<body text="#000000" bgcolor="#CCCCCC" link="#0000EE" vlink="#551A8B" alink="#FF0000">
<center><font size=+3>Would You Trust Your Brick &amp; Mortar Business To This?</font>
<br><img SRC="http://freepages.bigassweb.com/freepages/webcart/webcart.jpg" height=493 width=415>
<p>Don't Be Ridicules You Say. Well, Using Mountain Network's Webcart Scripts Is About As Secure As This Toy Cash Register.
<br>Several People Have Tried To Get Mountain Networks To Take The Security Holes In Their Scripts Seriously,
<br>But Mountain Networks Only <a href="http://www.mountain-net.com/security.htm">Response</a> Has Been To Blame The Site Owners Who Have Bought WebCart.
<br>They Claim, If The Site Owners Install The Scripts Properly, They Would Be Secure.
<p>Our Response, BULLSHIT!. The Webcarts Scripts Have Some Major Security Problems PERIOD.
<br>While It Maybe Possible To Secure WebCart Via Htaccess Type Controls, It Seems Very Unlikely.
<br>You See, Webcart's Security Problem Are At The Architectural Leval.
<br>The Webcarts Scripts Have No Security Measures What So Ever And To Make Things Worst,
<br>No Input Parsing!
<br>One Of The Security Holes Is So Serious, That One Of The Scripts Can Be Easily Exploited
<br>To Reveal Your Server Password File.
<p>To The SysAdmin Of This Site, Sorry For Defacing Your Site, But It Appears This Is The Only Way
<br>To Get Mountain Networks To Take Security Seriously. We've Waited Over A Week
<br>Since Hitting A Webcart Site In Order To See If Mountain Networks Would Do Anything.
<br>It Has Become VERY Clear, Mountain Networks
<br>Won't Admit To Design Flaws And Fix The Security Holes Until It's Proven To Them.
<p>The Only File Modified Was Your Index.html. The Original Was Saved As <a href="webcart.html">Webcart.html</a>.
<br>We Did NOT Access Any Other Files.
<p>Visit:
<br><a href="http://www.hackernews.com">Hackernews.com</a>
<br><a href="http://www.attrition.org">Attrition.org</a>
<br><a href="http://www.dutchthreat.org">DutchThreat.org</a>
<br><a href="http://www.mindsec.com">MindSec.Com</a>
<p><font size=+3>Security is a Myth!</font></center>
<div align=right>Freejack/HiP</div>
<!-- www.attrition.org web hack mirror - watermark or something -->