Saturday, March 29, 2014

Amadeus Vista Selling Platform – Penetration Testing

Penetration Testing - Amadeus Vista Selling Platform
Excuse moi, this one is for all Penetration Testers. You all are invited to test Amadeus Vista Selling Platform (don’t go by name, it works on all Windows XP, Vista, 7 etc; but on Windows only).
To proceed, download the file:
Start with ‘Amadeus_Selling_Platform_3.1P120_Installation_Guide.pdf’ file as it has all installation instructions, plus you would need some reverse engineering and the talentno spoon feeding please.
Message to beginners: this one is not for you. Lets hope after a few months we see Zero day security flaws in Amadeus Vista Selling platform on websites like cvedetails, packetstormsecurity, etc.
Then finally we will have a payload which our fellow testers could use using Metasploit. There is a lot of mess that can be done (a lot of potential I mean), hence we need to pull their eye open so they fix flaws.
Useful Tips:
Buffer Overflow & Remote Code Execution will top the list of flaws. FYI, its coded in Visual C++.
IP 82.150.248.28 ncewpo01-ext.dev.amadeus.net
Refer to http://api.dev.amadeus.net for their code structure, in C & messages in XML.
Could also download some PDF’s here: http://www.mirrorupload.net/file/E1KHYPYT/#!pdf.zip
And SEO (search engine optimization) people can download AWStats for api.dev.amadeus.net here: http://www.mirrorupload.net/file/1APAGLFL/#!awstats.pl.zip
In yet another review, a developer not from the best university says that Amadeus is yet using the old technology and has not upgraded:
Hacker review
References:
http://www.sca.amadeus.com/download -> click on category -> user:download, pass:gogetit
amadeusvista.com
certificates.amadeusvista.com/sgwadmin
diagnostic.amadeus.com/travelagencies
webconfig.amadeus.com/diagnostic
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Elizabeth Susan Carter – Photography
Store: http://goo.gl/kEa7ul
Facebook: http://goo.gl/mFei5t
Contact: http://goo.gl/ulA9Lm
About: http://goo.gl/pwPdiq
PortFolio:-

No comments:

Post a Comment