Thursday, June 5. 2008PENGGODAM MENGGODAM WEB PEJABAT PERDANA MENTERITrackbacks
Trackback specific URI for this entry
No Trackbacks
Comments
Display comments as
(Linear | Threaded)
hi anonymous,
it was file inclusion. xss was another one, which i blogged and reported to them, and was never fixed.
salam tumpang lalu..
This was just a 5 minutes job, imagine if they spend another few hours they might be able to take full control of the server but that besides the point, and the intension was to deliver the message and i guess the message was heard (within few hours).
RM2.70 = Second Tsunami
http://www.nst.com.my/Current_News/NST/Friday/Frontpage/2260134/Article/index_html
"A special officer to Datuk Seri Abdullah Ahmad Badawi confirmed the incident and said it was an "unsuccessful hacking attempt". Special officer my ass. The intention was not to deface but to the delivery the message and to point out to the lazy admins that the site is vulnerable to remote file inclusion (PoC only). This action was harmless and not against the law at all. I think next time, let them just tapau the whole thing and see what excuse the "Special Officer" will have to say.
i Was wondering, why i haven't heard of that form file that being use for redirection?
How did the RFI got there in the first place. It's been there for long time? or does it really have vulnerable file? whatever it is, it sure a simple and very CLear message.. Hacking is nothing thou, simple exploit the media and mislead a video or blog by it's content and post a lot of banner also work to send the message... for example.. namwe case meta word and misleading add-url for SEO also fill the traffic..
Fixing?? Admin just closed "the shop", duh. Way to go. Well done.
Laman Web ini ditutup buat sementara waktu kerana kerja-kerja penyelenggaraan. Pejabat ini memohon maaf di atas segala kesulitan yang dihadapi. This site is currently under maintenance. Sorry for the inconvenience.
itu lah si Pak Loh ni bodo sangat... apesal dia upah budak2 wannabe programmer p buat website dia... dah tu pakai joomla lagi.. hampeh...
Add Comment
Before you post a comment, please take note of the following guidelines:
Comment policy copied and modified from Spin Hunters. |
DISCLAIMERAll data and information provided on this site is for informational purposes and on an *as-is* basis.
This weblog does not represent the thoughts, intentions, plans or strategies of our employers. It is solely our opinion and views as security professionals. Feel free to challenge us, disagree with us, or even tell us that we are a complete mindless and brainless monkeys in the comment section of the blog entry. Report Defacements of Malaysian WebsiteTagswatchlist gcert worm exploit strong password harimau outbreak how to create password cybersecurity malaysia virus dubai myhack niser security analysis apple hitbsecconf2008 kuala lumpur pink rabbit vnsecurity leopard downadup password python edu.my conficker hitbsecconf2008 cimb phishing hackinthebox comment spam ctf mycert bank wireless lubuntu network analysis hacked hitbsecconf2008 dubai conference xss personal data privacy honeynet my-honeynet cyber terrorism scam general os x cuciotak scamming hex phishing site spam news information disclosure maybank2u hacking maybank phishing impact bro-ids sql injection malware events nsm alien_005 tools stupidity hackermalaysia joomla! hitbsecconf hitb web vulnerability defaced malaysia defacement
Recent EntriesDefaced - http://www.masjidannur.com.my
March 24 2010 Defaced - http://orogenic.com.my/ - http://orogenicgroup.com/ March 24 2010 Defaced - http://www.kedairakyat.com March 24 2010 Defaced - http://andamansetipengantin.com March 24 2010 Defaced - http://klse.info/.~x/ March 24 2010 Defaced - http://{www,ict,akademik}.kedah.edu.my/ March 24 2010 www.mampu.gov.my - hacked or misconfigured? March 12 2010 UMNO spends RM300 million hiring hackers to stop PKR for the next general election March 12 2010 Defaced - http://www.politeknik.edu.my March 4 2010 Defaced - http://ncer.com.my March 4 2010 ArchivesCreative Commons |