Showing posts with label Hacker News. Show all posts
Showing posts with label Hacker News. Show all posts
0
[postlink]https://tenderhub.blogspot.com/2011/09/indian-government-computers-are-also.html[/postlink]

One of the Indian Hacker named "nomcat" claim to hack into the Indian Prime Ministers Office Computers and install R.A.T (remote administration tool ) in them. He also Expose the Vulnerability in Income Tax website and Database Information.
Press Release By Hacker :
Our team wanted to release this information with interests of the people and to expose out to the world how corrupt the Indian Government and this is one of the best examples ... The IT department of India is vulnerable to SQL injection it allows the "attacker" to view and edit all the databases ,tables ,columns and data stored within them since there a LOT of tables we are not yet done fully exploring them and we are letting out only the data we think is the least affecting to our country's security , But what we should learn is that this is one of the simplest hacking methods and most of the work can be done by point and click applications that need no knowledge of coding .Let this be a warning , we give the concerned officials until 17/09/11 to FIX all vulnerabilities in the major government systems else we will make all data public link to .hvj file that contains database structure (can be opened by this software) our humble request is that you only use and this is not the only website that we have control over , we would also like to mention that we have a R.A.T (remote administration tool ) installed in the PM's office computers

Few months Before, The hacker group Anonymous, which was famous for their alleged hacking on Sony PlayStation Network, announced war against corruption in India by hacking one of the government websites of an IT organisation. Not long ago, the website of India's top investigation agency CBI was too hacked by Pakistan hackers and had caused embarrassment to the government. It took several weeks to the authorities to get the CBI website back on track. The repeated incidents of hacking of the government websites, perhaps most secure ones, have certainly exposed the vulnerability of websites. The Indian government then announced several measures to prevent such cyber attacks.

Anna Hazare's anti-corruption movement
Anna Hazare had started his fast earlier from 16 August, 2011 for the implementation of a Jan Lokpal bill. Finally he will end his fast on 28 August, 2011 at 10 am. With his 12 day long anshan, there were many questions raised again the Government. This 74 year aged Anna Hazare has done that thing which a normal person was unable to do. Anna Hazare has served his country and his nation fellows. Anna Hazare finally won the battle for the people from the government of India.

It is time to get off that fluffy cloud of illusion, get educated and get informed beyond such a small focus. Investigate the bigger picture, know your own power; inform others of the immediate threat of corporations and the growing take over of world governments. If you don't like it, you can oppose it. But if you ignore it and deny it; then you will remain a sitting target.
Now is the time to evolve or die

Indian Government Computers are also Corrupted like Government

0
[postlink]https://tenderhub.blogspot.com/2011/09/hdfc-bank-database-hacked-by-zsecure.html[/postlink]


zSecure team is back in news again, this time they have discovered a critical SQL injection vulnerability in HDFC Bank's Web Portal. Using this critical flaw HDFC Bank's various databases can be accessed and dumped as well. This critical flaw really affects the customer realtions of HDFC Bank's and this really questions the existing security in place within bank. HDFC Bank is the leading bank in India but they lack behind the basic security that needs to be implemented. zSecure team claimed in their blog post that even after sending them complete details about the vulnerability and even after conducting the vulnerability assessment from the third party service provider they were not able to discover this critical falw which existed in their web portal. This really raises a big question on their existing security policy.

What would have happened if somone else would have gained acceess to this critical flaw, their entire database would've been dumped, their web-site would have been defaced and much more. HDFC Bank's really needs to think on this matter again.
General Information
Website: www.hdfcbank.com
Vulnerability Type: Hidden SQL Injection Vulnerability
Database Type: MSSQL with Error
Vulnerability Discovered: 15-July-2011
Alert Level: Critical
Threats: Complete Database Access, Database Dump, Shell Uploading
Credit: zSecure Team
Proof of Vulnerability

About HDFC Bank
HDFC Bank deals with three key business segments. – Wholesale Banking Services, Retail Banking Services, Treasury. It has entered the banking consortia of over 50 corporates for providing working capital finance, trade services, corporate finance and merchant banking. It is also providing sophisticated product structures in areas of foreign exchange and derivatives, money markets and debt trading and equity research.

HDFC Bank Database Hacked by zSecure team using SQL injection vulnerability

0
[postlink]https://tenderhub.blogspot.com/2011/09/25-year-old-uk-student-hacker.html[/postlink]

A 25 year old Brit allegedly used "considerable technical expertise" to hack into Facebook's servers. The student, from York, faces five charges, including that he “made, adapted, supplied or offered to supply” a computer program to hack into a Facebook server, Westminster magistrates’ court heard.

Mangham, a resident of York, was arrested by the e-Crime Unit of the Metropolitan Police in June this year; and has been charged with five offences under the Computer Misuse Act. Mangham is currently on bail, and like all accused hackers has been prohibited from accessing anything even resembling a computer. "The court feels it will be safer if there was no access to the internet which will reduce the temptation for your son to go on to Facebook," said Judge Evans.

As per Facebook, no personal information had been compromised during the hacks attempted by Mangham. The social network also added that it had been working with Scotland Yard and the FBI since the officials “take any attempt to hack our internal systems extremely seriously.”

25 Year old UK Student hacker penetrated Facebook‎