Total Pageviews

Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Monday, 25 February 2013

India Results website hacked by Pakistan Hacker Hitcher

A Pakistani Hacker known as Hitcher has breached IndiaResults.com - No.1 Indian Portal for Boards & University Exam Results and Educational/Career.

Similar to BRBRAITT site attack, the hacker  defaced the website and published the database contents in the defacement page itself.

The database dump contains the Name, phone nunber , address and other details. There is no password leaked in the dump.

You can see the defacement page here:

http://ser1.indiaresults.com/%2C/
In an email sent to EHN, the hacker provided the database as XLSX sheet.  It seems like the compromised database is the database which stores the Feedback form data.

At the time of press time, we are still able to see the defacement page.  The mirror of the defacement can be found here: 
http://www.th3mirror.com/mirror/id/222665/

Monday, 11 February 2013

Learn Gmail Shortcuts with the KeyRocket Chrome Extension

Learn Gmail Shortcuts with the KeyRocket Chrome Extension 
A few weeks ago, I shared a great way to master your keyboard shortcuts in Windows with KeyRocket. Today, I want to share a similar way to master your keyboard shortcuts in Gmail (and Google Apps accounts), thanks to the KeyRocket  for Gmail Chrome Extension.
Since both of these tools come from the same company, they work very similarly. One is exclusively for Windows Explorer and the other is for Gmail (Chrome only – for now).

Here’s how to use it.

1. Add the KeyRocket for Gmail extension to Chrome. You’ll see a new icon on Chrome’s toolbar, which doesn’t serve much purpose except to direct you to KeyRocket’s other downloads; you’ll probably just want to hide the button (right-click on the   browser icons and select “hide button”).
Make sure Keyboard Shortcuts are on in settings.


2. Gmail will automatically open in a new tab once the extension is installed. You’ll need to make sure that you have the keyboard shortcuts options set to “on” in settings.
You'll find Keyboard Shorcuts above Button Labels in settings.

3. Now you can go about using Gmail as you normally would. KeyRocket for Gmail will teach you keyboard shortcuts while you’re performing actions with your mouse – as long as these actions have an associated keyboard shortcut.
The KeyRocket for Gmail notification shows in the top right corner of the screen.


4. You’ll see notifications for keyboard shortcuts in the top right corner of Gmail. On the Chrome extensions page the screenshots actually shows a different style of notifications, in the bottom right corner of the screen. I’m not sure how those were achieved, but I’m happy with the ones I’m seeing for now.
Alternative notification displayed on the extension page.


I’m one that always keeps the keyboard shortcuts “off” in Gmail, because I just cannot remember them. However, after using KeyRocket for Gmail for just a few minutes, I was already using keyboard shortcuts and boosting my productivity. I really wish that I had found this extremely useful extension a lot sooner.

Sunday, 10 February 2013

Bollywood Actress Divya Dutta website vulnerable to critical vulnerabilities




Ravi Kariya, a Security Analyst from Cyber Octet Pvt. Ltd (facebook.com/cyberoctet) has discovered critical vulnerabilities in the official website (divyadutta.co.in) of famous Indian Actress Divya Dutta.

There are two SQL Injection vulnerability in the website.  One of the vulnerabilities resides in the  Press Clips page of the site(divyadutta.co.in/pressclipdetail.asp?id=7).  A malicious hacker can exploit this vulnerability and extract the database .
The other one is more critical one , it allows hackers to bypass authentication of the Login .  A malicious hacker can login into the website as admin(divyadutta.co.in/admin/) . This can be done by injecting the crafted password that will modify the sql query such that it allows hacker to login.

There is also Cross site scripting vulnerability in the contact us page(divyadutta.co.in/contact.asp ) .  Injecting the follow code in the fields and clicking the submit button executes the injected code:

"><script>alert('My Love For Divya Dutta')</script>




Ravi tried to contact the Divya dutta via email and Twitter but she fails to respond for his query.  It seems like that She doesn't realize the severity level of this security flaw. A BlackHat hacker is able to deface the site with these vulnerabilities.

I think she will respond after some blackhats attack the site, what do you think guys?

*Update*
After E hacking news published news about the vulnerability, the admin pulled down the divya dutta site. Now the site displays the following error message:

"Directory Listing Denied.This Virtual Directory does not allow contents to be listed."

Related Posts Plugin for WordPress, Blogger...