Tampilkan postingan dengan label Hacking News. Tampilkan semua postingan
NullCrew Hacked Time Warner Cable For Supporting Copyright Alert System
Kamis, 07 Maret 2013
Posted by Unknown
Infamous Hacktivists Nullcrew has defaced the Time Warner's Cable for supporting Copyright Alert System (CAS) - An American cable telecommunications company.
The hackers announced that attack on their official Twitter account.
"We hacked Time Warner Cable, due to them attempting to participate in the six strikes.They defaced the site with a gorilla picture. In the defacement page, the hackers leaked the database details, username, passwords, SSL Keys file password.
The hacktivist criticize the password used by admin, they are using the very simple password "changeme".
[user_info] USERNAME = adminPASSWORD = changeme (lolfail, learn to change default passwords; we didn't know this one till we had access to all config files.)At the time of writing, the website has been taken down by the admin, you can see the mirror of the defacement here: http://www.freezepage.com/1362546977OFVSJKBYGE
What is CAS?
The Copyright Alert System (CAS) is a private system for alerting and punishing internet subscribing customers of AT&T, Cablevision, Time Warner, Verizon and Comcast in regards to accusations of bittorrent use via their home networks to access alleged copyrighted material from a list of specific entertainment corporations and their CAS registered content. It is limited to customers of those internet vendors in the United States.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: NullCrew Hacked Time Warner Cable For Supporting Copyright Alert System
Yesterday, we reported that Soneri Bank's Online Banking System official website (www.soneribankonline.com.pk) - The biggest banking network in Pakistan was Hacked and Defaced. Our security team decided to research the security hole exploited by the hackers.
After researching, we found that, Soneri Bank, The Biggest Banking Network of Pakistan is vulnerable to a very common exploit. Yes, WebDev IIS 6.0 vulnerability exists in the Soneri Bank Server with write permission on it. Details are below:
This article is completely educational purpose only. Author does not take any responsibility of any damage/harm to the site.
About WebDev Vulnerability:
WebDAV is enabled on Soneri Bank Server and it has write permissions enabled on it.The PUT HTTP Method can be used create a test file within this directory and to execute commands on the server. The PUT method is a part of the WebDAV standard for remote content editing.
A poorly configured Web server can mistakenly provide remote access to the PUT method without requiring any form of login. Even more.
How hacker managed to create a file on the server or execute code on the server? POC with picture and details are below:
We use HttpRequester Firefox Plugin to perform test. This tool is useful when doing web or REST development, or when you need to make HTTP requests that are not easily done via the browser (PUT/POST/DELETE).
We write the Test content: Test by The Hackers Post, appended test.htm and executed PUT method. We got the following response.
PUT http://soneribankonline.com.pk/test.htm
Content-Type: text/xml
Test By The Hackers Post
-- response --
201 Created
Date: Wed, 06 Mar 2013 07:26:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://soneribankonline.com.pk/test.htm
Content-Length: 0
Allow: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, COPY, MOVE, PROPFIND, PROPPATCH, SEARCH, LOCK, UNLOCK
Below is the ScreenShot of the response.
By visiting the URL,
This is how hacker manage to upload a html deface page on the server.
We try to upload a asp Shell on the server using PUT request but its refuse the request and response was 403 Forbidden. Below is the screen shot
The impact of this vulnerability
Malicious users can execute arbitrary code on this system. Possible system compromise.
How to fix this vulnerability
Remove write permissions from this directory or disable WebDAV if it's not being used.
I was shocked to see such a common and famous vulnerability exists in a Banking Software and allowed RCE (Remote Code Execution) and not properly configured. Questions arises, Where is Bank Security Team? Does the Bank have security Team? These are the questions still unanswered.
After researching, we found that, Soneri Bank, The Biggest Banking Network of Pakistan is vulnerable to a very common exploit. Yes, WebDev IIS 6.0 vulnerability exists in the Soneri Bank Server with write permission on it. Details are below:
This article is completely educational purpose only. Author does not take any responsibility of any damage/harm to the site.
About WebDev Vulnerability:
WebDAV is enabled on Soneri Bank Server and it has write permissions enabled on it.The PUT HTTP Method can be used create a test file within this directory and to execute commands on the server. The PUT method is a part of the WebDAV standard for remote content editing.
A poorly configured Web server can mistakenly provide remote access to the PUT method without requiring any form of login. Even more.
How hacker managed to create a file on the server or execute code on the server? POC with picture and details are below:
We use HttpRequester Firefox Plugin to perform test. This tool is useful when doing web or REST development, or when you need to make HTTP requests that are not easily done via the browser (PUT/POST/DELETE).
We write the Test content: Test by The Hackers Post, appended test.htm and executed PUT method. We got the following response.
PUT http://soneribankonline.com.pk/test.htm
Content-Type: text/xml
Test By The Hackers Post
-- response --
201 Created
Date: Wed, 06 Mar 2013 07:26:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://soneribankonline.com.pk/test.htm
Content-Length: 0
Allow: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, COPY, MOVE, PROPFIND, PROPPATCH, SEARCH, LOCK, UNLOCK
Below is the ScreenShot of the response.
By visiting the URL,
This is how hacker manage to upload a html deface page on the server.
We try to upload a asp Shell on the server using PUT request but its refuse the request and response was 403 Forbidden. Below is the screen shot
The impact of this vulnerability
Malicious users can execute arbitrary code on this system. Possible system compromise.
How to fix this vulnerability
Remove write permissions from this directory or disable WebDAV if it's not being used.
I was shocked to see such a common and famous vulnerability exists in a Banking Software and allowed RCE (Remote Code Execution) and not properly configured. Questions arises, Where is Bank Security Team? Does the Bank have security Team? These are the questions still unanswered.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: How Soneri Online Banking System Website was hacked?
An Indian Hacker going by name "Godzilla" today claimed to hack into one of the server belongs to unofficial ISI(Inter Services Intelligence) website (http://isi.org.pk) and hacker claimed to have access to the secret information of Pakistani Intelligence Agency.
According to the information by the hacker, he claims to have access to Remote Desktop Protocol (RDP) of the server located at 173.193.110.72.
He claimed that System installed with Windows 2008 server standard edition and having three drives i.e C,D,E with operating system in C and Hostname 'AHCORP'.
He also claimed to hack into MSSQL server containing 3 databases, with 9 users and located at http://mssql.isi.org.pk, as shown in the below screenshot.
Some partial tables of the database 'msdb' as listed below:
bakupfile
bakupmediafile
bakupmediaset
backupset
logmarkhistory
restorefile
restorehistory
suspect_pages
As its unofficial site, it has nothing to do with ISI itself and it does not contain any secret information of the intelligence agency. The above screenshot show that, its just a random site, contain ordinary information, maintained by some fan of the ISI (inter-Services Intelligence).
According to whois details of the website, nameservers are given below:
ns9.ahcorporation.com
ns10.ahcorporation.com
Website is hosted on shared hosting server. The hosting services are provided by ahcorporation.com. Its just an ordinary windows server with sites hosted on it.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Unofficial Pakistan Intelligence agency ISI site hacked by Indian Hacker Godzilla





