http://tweedge32j4ib2hrj57l676twj2rwedkkkbr57xcz5z73vpkolws6vid.onion/2021/disclosing-wsdot-sqli
While it was active, this vulnerability granted substantial but non-administrative access to a database, which is used for the WSDOT website, permit registration and management using eSNOOPI, internal material management and test logs, ferry bulletins and schedules, some things to do with MATLAB, and more. The database itself ran Microsoft SQL Server 2016 (SP3) (KB5003279) on Windows Server 2016 standard, and its hostname was “HQOLYMSQLHA01P” which seems to imply that it’s...