Research techniques,Your Favourite DigTech Blog

digtech.org

How Pakistan google and other sites got hacked?

August 8, 2013 by hoa tran

4.7/5 - (646 votes)
How Pakistan google and other sites got hacked ? Recently, The news about the Pakistani Google hack spread like a wildfire in the Internet.  At the time, Top Level Pakistan Domains displayed the defacement page including Yahoo, MSN, HSBC, EBay,Paypal and more sites.
boolean-based-sqli-vulnerability
Today, khanisgr8, a hacker from Pakistan hacker collective called “TeamBlackHats” sent an email regarding the security breach.  He explains how those websites got hacked by Turkish Hacker group “EBoz”.

The day before yesterday we mentioned those hacked sites’ dns records points to different free hosting site. Also we report that the site might be hacked using PKNIC vulnerability.

The hackers have claimed to have discovered a Boolean-based blind SQL injection, persistent cross site scripting, sensitive directory directory disclosure vulnerabilities in the official website of PKNIC.

PKNIC is responsible for the administration of the .PK domain name space, including the operation of the DNS for the Root-Servers for .PK domains,
and registration and maintenance of all .PK domain names. PKNIC is operated as a self-supporting organization.

They provide us the vulnerable link with POC to exploit it. Also they sent some data compromised using the vulnerability which contains database details, username and hashed password.

Xss vulnerability-pknic
Xss vulnerability

He also provide the screenshot of the Cross site scripting vulnerability. When i tried to verify the XSS vulnerability, i just searched in google for the url and visit a PKNIC link.  After visiting the link, i just saw a text “<script>alert(“HACKED BY COde InjectOr”)</script>”. May be Code Injector team attempts to exploit the vulnerability.

“Apparently Google Pakistan has been defaced by a Turkish Hacker group ‘Eboz’ . It’s still quite hard to believe that Google server has been hacked. They really need to put a lot of focus on their defenses because if one website got hacked that means every other websites can be hacked. ” they said.

More:  List Of Top 5 Pentration Testing Operating System’s Based On Linux

We have sent an email to PKNIC regarding the vulnerability and waiting for their response. We are not sure whether the vulnerability is fixed or not So we are not providing the vulnerable link here.

  • Share on Facebook
  • Tweet on Twitter
  • Share on LinkedIn

Maybe You Like

Minecraft jenny mod (1.20.1, 1.19.2) – The attraction of a virtual girlfriend
Guide on Making Fire Resistance Potions
10 Minecraft Mod Ideas To Make Your World Of Gaming More Interesting
Pokemon Fan Game
5 Most Famous Pokemon Fan Game You Should Not Miss
How To Get All Eevee Evolutions InPokemon Go!
I made a mod for freely setting your first-person field of view. Download and review

Reader Interactions

Leave a Reply

You must be logged in to post a comment.

Primary Sidebar

Featured Posts

Taylor Swift hugs rumored boyfriend in restaurant

Unveiling the Phenomenal Journey: A Captivating Biography of Neymar Jr

Latest news about Taylor Swift and Travis Kelce

The Expendables 4 Disappoints with Outdated Plot, Fails to Utilize A-List Cast

The Versatile Talents of Jamie Foxx: A Closer Look at His Expansive Career

Ads

Tools Minecraft

Pokeradar 1.16.5
Orespawn 1.8.9
Copious dogs mod 1.12.2
Pixelmon radar mod 1.16.5
Loot++ 1.12.2

Footer

About

digtech logo home Research Methods News, Reviews, and Analysis. Technology News, Your Preferred DigTech Blog. Digtech.org is a blog for IT!

Helpful Links

  • Contact Us
  • Privacy Policy
  • About
  • Create Your Own Post

Site Statistics

  • 1,235 Top Trending Topics
  • 658  Popular on Digtech channel
  • 5,101,579 Submission Views
  • 38,278 Trending searches today

Copyright © 2023 - Digtech Media Private Limited.
Digtech.org is neither affiliated with nor endorsed by any brands or trademarks on this site unless explicitly stated.