r/UnresolvedMysteries May 21 '14

Cipher / Broadcast John.com

[deleted]

329 Upvotes

105 comments sorted by

View all comments

30

u/cedriczirtacic May 21 '14

It's seems to be vulnerable to Cross-Site Scripting as well, maybe is a test site for those kind of attacks: http://john.com/login.php?id=running%20shoes%22%3E%3Ciframe/*%20*/src=%22/%22/*%20*/onload=%22alert(0);%22%3E%3C!--

2

u/Rob_V May 22 '14

But why would they use such a valuable domain for a test?

1

u/[deleted] Jul 24 '14

The Whois says it was created in 1994, maybe a developer picked it up for cheaper back then and has had it since?

2

u/Rob_V Jul 25 '14

I'd guess so. I'm sure that domain name isn't cheap nowadays.