Monday, June 14, 2010

Metasploit 101  

Metasploit 101 from PaulDotCom

Enjoy!

Wednesday, May 12, 2010

Philippine Securities and Exchange Commission website got defaced!  


Source: www.sec.gov.ph

Saturday, April 10, 2010

Is this your email password?  

The most common account password especially for email is "123456". How did I know? Two years ago, it ranks as top # 1 on whatsmypass.com's list of "Top 500 Worst Passwords of all Time" but people never learned as they still favor on using simple and easily-guessed passwords. And how do free email service providers respond on this? Let's take yahoo and gmail as examples.

I register a new yahoo account using "123456" as the password. It then displays as a "weak" password but still able to register the account (?). Definitely, Yahoo fails on this part.



How about the password "password"?



Good thing it is not accepted.

Another test account using "123456" as the password displays the strength as a "weak" one. Gmail does not accept weak or too short passwords as registration will fail. Same applies to the password "password".





Using simple passwords is not a new phenomenon. Thus experts’ advice not to use most common or easily-guessed passwords nor re-use it on other online accounts as it is vulnerable to hacking. Choose complex passwords. You may also check StaySafeOnline.org's article on Choosing Safe Passwords.

Monday, March 22, 2010

Mannyvillar.com.ph got hacked  

After an alleged rumor circulated via text messages early this month that AFP will carry out poll automation cheating dubbed as "Project Fullmoon" in favor to Senator Manny Villar with the assistance of a certain Korean hacker Martin Leebiong, the mockery towards the senator does not ends there.

Recently, the blog section of Senator Manny Villar's website (www.mannyvillar.com.ph) just got hacked. A blog post entry dated Mar 19, 2010 fictitiously coming from Kris Aquino, bash his campaign tactics and urge readers to vote her brother Noynoy Aquino instead.

Here is the complete message of the hacker before the post was taken down:

"Omigosh kalerky to the max. Imagine, may I gamit pa mga kids sa commercial to make sipsip to the poor. Pano naman kaming mga riichhh! Wala ba candidate na magpapakatotoo “For the rich, because I am rich!” Dapat ganun devah! Love it! So many eklat and whatnot. Why pa magpakahirap sa business kung mas mataas kita sa government di ba? Like I said to Boy regarding sa interview nila, “Taas ng TF, Amiiinin!”. Hay naku, vote for my brother Noynoy na lang, manang mana sa kanya si josh, ang cute di baah! Basta, for my hair magthank you na lang ako sa mga baklush sa pinoyhacking.com. Sila rin nagtina ng buhok ni MannyVillar ever! Greet ko na rin mga tga pinoygreyhat.org, makers ng gown ko, hay naku ang aarte nyo, pwede na kayo maging National Artist! Thanks din sa mga members ng ph****, ang official Kris Aquino fan club! Hug! Kisses!! muah muah muah! At sa mga samu’t saring pinoy hacker group, mga kumare asan na kayo!? Text text nyo naman me at makapag lamierda tayo! Love it!"


Monday, January 11, 2010

TESDA Website defaced  

The Technical Education and Skills Development Authority (TESDA) was the 5th victim of the continuous government website vandalism after its home page defaced by a hacker, leaving a message of sympathy to a certain "Kimay" addressed to abusive police officers and a picture of a man showing a nasty dirty finger.



This defacement follows the attack on other agencies like Department of Health (DOH), Department of Social Welfare and Development (DSWD), National Disaster Coordinating Council (NDCC), and Department of Labor and Employment (DOLE).

Wednesday, July 15, 2009

Google tagged PRC.gov.ph website as 'Harmful'  

Yesterday, I have posted that the PRC website was injected with malicious code. And now, Google has tagged the site as 'harmful' as it may hosted malicious software. I can't imagine how risky this will be on its users once the June 2009 Nursing Board Examination Results will be published. AFAIK, there are about 80,000 who took the June 2009 NLE exams.


By looking at Google Safebrowsing Diagnostic report, the malicious code is hosted on two domains -- gamemaill.com and f1y.in. Don't visit these sites.

Updates:

(7/19/2009): Site is currently offline.
(7/25/2009): Site is up and running. However, the malware warning in Google has not yet removed.
(8/27/2009): Malware warning was removed.
(9/2/2009): Site is again listed as 'suspicious'.
(9/4/2009): Malware warning was removed.

Tuesday, July 14, 2009

PRC Hacked Again and Again?  

If you tend to visit the PRC website (www.prc.gov.ph), noticed that you can never get through on the examination results page? Does it mean that it is down? No. The site is hacked again. WTF! Damn, this is the 3rd time (1, 2, 3) that the site was hacked within this year. Looking at the status bar of the screenshot, you will notice a website hosting a script containing malicious codes. This script was injected not only on the exam results page but also on some Quick Access links. See below Google Safebrowsing diagnostic page report.

(Screenshot courtesy of DEFCONPH)

Friday, May 22, 2009

Mass Defacement on .gov.ph sites  

As recorded by Zone-h, a total of 100 government sites was defaced yesterday (May 21) by 3 known foreign hackers: ISCN Team, Cyber-Hero and Black.Spook. Black.Spook rooted 91 sites, 6 sites by Cyber-Hero and 3 sites by ISCN Team. All of these defaced sites were running FreeBSD servers.

Saturday, April 18, 2009

PRC Hacked Again?  




Last April 1 (April Fools Day), it was known that the main page of the PRC website was defaced by a group of hackers known as "linuXploit_crew". This time another group of hackers known as "Fatal Error Group Br" had successfully break into the site by inserting an index page (see attached screenshot).

As of this writing, the index page is still there.

Updates:
(7/26/2009): It is more than 3 months from this post but the index page still exists and not yet removed.

(10/21/2009): This was reported in media last 08/22/2009 but still no action was done.

Hack Poll Machines = P100M  

MANILA, Philippines—Senator Alan Peter Cayetano has filed a resolution setting aside P100 million as an incentive to anyone who can convincingly demonstrate the weakness of the automated poll system.

Cayetano, at a press conference Friday, said that if any IT expert can establish that the system to be used in the 2010 polls is not secure from fraud and tampering, "Comelec should cancel the contract, save the P11 billion and sue for damages the contractor in the event of such successful hacking."

He said he would rather revert to the manual counting of votes if the computerized system would lead to wholesale cheating.

Cayetano said the resolution, which he would file on Monday, was in response to a statement by a Comelec official challenging cyber security experts to test the system for weaknesses.

"The most effective way to test if indeed a system is credible, reliable and tamper-proof or fraud-proof is to offer a sizable prize to whoever can hack and convincingly show the weaknesses of the system," Cayetano said in his draft resolution.

"To make the said incentive system work, there is a need to authorize the Commission on Elections to set aside the amount not exceeding P100 million to be utilized as a prize money for the said successful hacker," he said.

If the system is successfully hacked, the Comelec will then be authorized to cancel the contract and sue the winning bidder.

Despite repeated assurances poll automation will significantly curb cheating, Cayetano said there are fears it might actually induce a "bigger and more sophisticated method of election cheating if the system is vulnerable to manipulation."

Source: Inquirer.net

Thursday, April 2, 2009

PRC Website Defaced  



Yesterday, the official website of the Professional Regulation Commission (PRC) was defaced by a group of hackers known as "linuXploit_crew" on the afternoon of April 1, April Fools Day.

I managed to have a screenshot of the defaced site (see above) at around 9:30PM, showing a blank page (no images) with words "Hacked by linuXploit_crew =) by DeRf-, Hualdo and _serial_killer_". I checked its subpages and I found out that its still intact thus only the main page was compromised.

As of noon of April 2, the site is still unaccessible. But as I have visited the site (its 3:05PM on my PC's clock), the site has been back to normal.

This surely mean that some .gov.ph sites are vulnerable to hacking.