Security Analysis phish from Google Gmail Part 2
Posted by Dave Yadallee on
--00000000000011393506552de15d
Content-Type: multipart/alternative; boundary="00000000000011393306552de15b"
--00000000000011393306552de15b
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Hello NetKnow Security Team,
I am Ahmed Saifi, an independent security researcher specializing in
responsible disclosure.
Since 1995 you've proudly offered "strong security" =E2=80=94 however, I fo=
und the
following issues today:
Issue 1: Public Visitor Statistics Page (No Authentication)
..
https://www.nk.ca/visitors/?env=3D%2Fbestbuy.com%2F%2F..%60+WHERE+8449%3D84=
49AND%2F%2A%2A%2FGTID_SUBSET%28CONCAT%28%27~%27%2C%28SELECT%2F%2A%2A%2F%28E=
LT%289379%3D9379%2C1%29%29%29%2C%27~%27%29%2C9379%29--+-#Requested%20images=
%20and%20CSS
..
This page exposes:
Complete server traffic logs (1,199,783 unique visitors)
All 404 errors including active SQL Injection attempts
Sensitive file path requests (.env requested 41,716 times, /.git/config
29,856 times)
Full referrer data and user agent strings
Issue 2: Active SQL Injection Attempt Logged Publicly
Attacker payloads are visible in your public logs:
/visitors/?env=3D/bestbuy.com//.. + GTID_SUBSET MySQL injection
Issue 3: Auto-Generated Public Reports
Daily reports generated automatically and published publicly (last: Jun 26
2026 14:06:47), exposing 14,771,529 log entries with zero authentication.
Recommendations:
Restrict /visitors/ behind authentication immediately
Review logs for successful injection attempts
Audit .env and .git exposure
I have not accessed, modified, or extracted any data.
Regards,
Ahmed Saifi
Independent Security Researcher
syfyahmd54@gmail.com
--00000000000011393306552de15b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
auto">Complete server traffic logs (1,199,783 unique visitors)
Content-Type: multipart/alternative; boundary="00000000000011393306552de15b"
--00000000000011393306552de15b
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Hello NetKnow Security Team,
I am Ahmed Saifi, an independent security researcher specializing in
responsible disclosure.
Since 1995 you've proudly offered "strong security" =E2=80=94 however, I fo=
und the
following issues today:
Issue 1: Public Visitor Statistics Page (No Authentication)
..
https://www.nk.ca/visitors/?env=3D%2Fbestbuy.com%2F%2F..%60+WHERE+8449%3D84=
49AND%2F%2A%2A%2FGTID_SUBSET%28CONCAT%28%27~%27%2C%28SELECT%2F%2A%2A%2F%28E=
LT%289379%3D9379%2C1%29%29%29%2C%27~%27%29%2C9379%29--+-#Requested%20images=
%20and%20CSS
..
This page exposes:
Complete server traffic logs (1,199,783 unique visitors)
All 404 errors including active SQL Injection attempts
Sensitive file path requests (.env requested 41,716 times, /.git/config
29,856 times)
Full referrer data and user agent strings
Issue 2: Active SQL Injection Attempt Logged Publicly
Attacker payloads are visible in your public logs:
/visitors/?env=3D/bestbuy.com//.. + GTID_SUBSET MySQL injection
Issue 3: Auto-Generated Public Reports
Daily reports generated automatically and published publicly (last: Jun 26
2026 14:06:47), exposing 14,771,529 log entries with zero authentication.
Recommendations:
Restrict /visitors/ behind authentication immediately
Review logs for successful injection attempts
Audit .env and .git exposure
I have not accessed, modified, or extracted any data.
Regards,
Ahmed Saifi
Independent Security Researcher
syfyahmd54@gmail.com
--00000000000011393306552de15b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Hello NetKnow Security Team,
https://www.nk.ca/visitors/?env=3D%2Fbestbuy.com%2F%2F..%60+WHERE+8449%3D84=
49AND%2F%2A%2A%2FGTID_SUBSET%28CONCAT%28%27~%27%2C%28SELECT%2F%2A%2A%2F%28E=
LT%289379%3D9379%2C1%29%29%29%2C%27~%27%29%2C9379%29--+-#Requested%20images=
%20and%20CSS">https://www.nk.ca/visitors/?env=3D%2Fbestbuy.com%2F%2F..%60+W=
HERE+8449%3D8449AND%2F%2A%2A%2FGTID_SUBSET%28CONCAT%28%27~%27%2C%28SELECT%2=
F%2A%2A%2F%28ELT%289379%3D9379%2C1%29%29%29%2C%27~%27%29%2C9379%29--+-#Requ=
ested%20images%20and%20CSS
r=3D"auto">
I am Ahmed =
Saifi, an independent security researcher specializing in responsible discl=
osure.
Saifi, an independent security researcher specializing in responsible discl=
osure.
Since 1995 you've proudly offered "s=
trong security" =E2=80=94 however, I found the following issues today:=
trong security" =E2=80=94 however, I found the following issues today:=
Issue 1: Public Visitor Statistics Page (No Authent=
ication)
ication)
..=C2=A0
https://www.nk.ca/visitors/?env=3D%2Fbestbuy.com%2F%2F..%60+WHERE+8449%3D84=
49AND%2F%2A%2A%2FGTID_SUBSET%28CONCAT%28%27~%27%2C%28SELECT%2F%2A%2A%2F%28E=
LT%289379%3D9379%2C1%29%29%29%2C%27~%27%29%2C9379%29--+-#Requested%20images=
%20and%20CSS">https://www.nk.ca/visitors/?env=3D%2Fbestbuy.com%2F%2F..%60+W=
HERE+8449%3D8449AND%2F%2A%2A%2FGTID_SUBSET%28CONCAT%28%27~%27%2C%28SELECT%2=
F%2A%2A%2F%28ELT%289379%3D9379%2C1%29%29%29%2C%27~%27%29%2C9379%29--+-#Requ=
ested%20images%20and%20CSS
..=C2=A0
r=3D"auto">
This page exposes:
auto">Complete server traffic logs (1,199,783 unique visitors)
r=3D"auto">All 404 errors including active SQL Injection attempts
dir=3D"auto">Sensitive file path requests (.env requested 41,716 times, /.=
git/config 29,856 times)
Full referrer data and user=
agent strings
agent strings
Issue 2: Active SQL Injection Attempt=
Logged Publicly
Logged Publicly
Attacker payloads are visible in yo=
ur public logs:
ur public logs:
dir=3D"auto">Issue 3: Auto-Generated Public Reports
=
Daily reports generated automatically and published publicly (last: Jun 26 =
2026 14:06:47), exposing 14,771,529 log entries with zero authentication.=
div>
=3D"auto">syfyahmd54@gmail.com<=
/div>
Daily reports generated automatically and published publicly (last: Jun 26 =
2026 14:06:47), exposing 14,771,529 log entries with zero authentication.=
div>
Recommendations:
Restrict /vis=
itors/ behind authentication immediately
itors/ behind authentication immediately
Review logs=
for successful injection attempts
for successful injection attempts
Audit .env and .g=
it exposure
it exposure
I have not accessed, modified, or extrac=
ted any data.
ted any data.
Regards,
Ahmed =
Saifi
Saifi
Independent Security Researcher
=3D"auto">syfyahmd54@gmail.com<=
/div>
--00000000000011393306552de15b--
--00000000000011393506552de15d
Content-Type: image/jpeg; name="1000059256.jpg"
Content-Disposition: attachment; filename="1000059256.jpg"
X-Mozilla-External-Attachment-URL: file:///home/dsy/Downloads/1000059256.jpg
X-Mozilla-Altered: AttachmentDetached; date="Sat Jun 27 15:39:43 2026"
You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: image/jpeg; name="1000059256.jpg"
Content-Disposition: attachment; filename="1000059256.jpg"
Content-Transfer-Encoding: base64
Content-ID: <19f059986fba3c06a114>
X-Attachment-Id: 19f059986fba3c06a114
--00000000000011393506552de15d
Content-Type: image/jpeg; name="1000059254.jpg"
Content-Disposition: attachment; filename="1000059254.jpg"
X-Mozilla-External-Attachment-URL: file:///home/dsy/Downloads/1000059254.jpg
X-Mozilla-Altered: AttachmentDetached; date="Sat Jun 27 15:39:43 2026"
You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: image/jpeg; name="1000059254.jpg"
Content-Disposition: attachment; filename="1000059254.jpg"
Content-Transfer-Encoding: base64
Content-ID: <19f059986fba3a43b0f6>
X-Attachment-Id: 19f059986fba3a43b0f6
--00000000000011393506552de15d
Content-Type: image/jpeg; name="1000059255.jpg"
Content-Disposition: attachment; filename="1000059255.jpg"
X-Mozilla-External-Attachment-URL: file:///home/dsy/Downloads/1000059255.jpg
X-Mozilla-Altered: AttachmentDetached; date="Sat Jun 27 15:39:43 2026"
You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: image/jpeg; name="1000059255.jpg"
Content-Disposition: attachment; filename="1000059255.jpg"
Content-Transfer-Encoding: base64
Content-ID: <19f059986fba3b252905>
X-Attachment-Id: 19f059986fba3b252905
--00000000000011393506552de15d
Content-Type: image/jpeg; name="1000059257.jpg"
Content-Disposition: attachment; filename="1000059257.jpg"
X-Mozilla-External-Attachment-URL: file:///home/dsy/Downloads/1000059257.jpg
X-Mozilla-Altered: AttachmentDetached; date="Sat Jun 27 15:39:43 2026"
You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: image/jpeg; name="1000059257.jpg"
Content-Disposition: attachment; filename="1000059257.jpg"
Content-Transfer-Encoding: base64
Content-ID: <19f059986fba3ce81923>
X-Attachment-Id: 19f059986fba3ce81923
--00000000000011393506552de15d
Content-Type: image/jpeg; name="1000059258.jpg"
Content-Disposition: attachment; filename="1000059258.jpg"
X-Mozilla-External-Attachment-URL: file:///home/dsy/Downloads/1000059258.jpg
X-Mozilla-Altered: AttachmentDetached; date="Sat Jun 27 15:39:43 2026"
You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: image/jpeg; name="1000059258.jpg"
Content-Disposition: attachment; filename="1000059258.jpg"
Content-Transfer-Encoding: base64
Content-ID: <19f059986fba3dc99132>
X-Attachment-Id: 19f059986fba3dc99132
--00000000000011393506552de15d
Content-Type: image/jpeg; name="1000059259.jpg"
Content-Disposition: attachment; filename="1000059259.jpg"
X-Mozilla-External-Attachment-URL: file:///home/dsy/Downloads/1000059259.jpg
X-Mozilla-Altered: AttachmentDetached; date="Sat Jun 27 15:39:43 2026"
You deleted an attachment from this message. The original MIME headers for the attachment were:
Content-Type: image/jpeg; name="1000059259.jpg"
Content-Disposition: attachment; filename="1000059259.jpg"
Content-Transfer-Encoding: base64
Content-ID: <19f059986fba3eab0941>
X-Attachment-Id: 19f059986fba3eab0941
--00000000000011393506552de15d--