Hacker Busted in Sri Lanka ( Real Story )

Ethical_World

Member
Mar 15, 2009
2,036
90
0
#! /bin/sh
Read This 1st

A Hacker Called "Zonta" Busted by CID about 3 weeks ago but they didnt arrest him because he was having his A/L examz at that time . CID gave a notice to visit CID Branch after the A/L's . The Day 31th of Aug "Zonta" When to CID Branch and All CID Agents were very Kind to him .

Agent "***********" is the agent who was in in-charge on this case . He was every Impressed with the Hacker's Knowledge Eventho he hacked Sri Lakan Gov Website. After writing his statement he was produced court and everything was calmly finished without any jail time or any Bail

That's the real story

But in new today

Untitled-1_6.jpg



But In the Real, Zonta Didnt change anything on the website .. he only upload a Defacement Page and Gave Warrning That this website is Vnl To Hack ..

:dull::dull::dull::dull::dull::dull::dull::dull:




Why News Papers Lie soo much ??????????????????:no::no::no::no::no::no::no::no::no::no::no::no::no:

:angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry:
 
Last edited:

Fire_Bird

Well-known member
  • Feb 13, 2009
    8,837
    1
    1,046
    113
    Yes true ZonTa Didn't change anything on that website. He have put only the Defacement page and he told that site vnl to hacked. I don't know why these media people always lie. Why can't they tell the truth.
     

    viraj_slk

    Active member
  • Oct 1, 2007
    505
    35
    28
    Read This 1st

    A Hacker Called "Zonta" Busted by CID about 3 weeks ago but they didnt arrest him because he was having his A/L examz at that time . CID gave a notice to visit CID Branch after the A/L's . The Day 31th of Aug "Zonta" When to CID Branch and All CID Agents were very Kind to him .

    Agent "I.P Senarathna" is the agent who was in in-charge on this case . He was every Impressed with the Hacker's Knowledge Eventho he hacked Sri Lakan Gov Website. After writing his statement he was produced court and everything was calmly finished without any jail time or any Bail

    But In the Real, Zonta Didnt change anything on the website .. he only upload a Defacement Page and Gave Warrning That this website is Vnl To Hack ..

    :dull::dull::dull::dull::dull::dull::dull::dull:


    Why News Papers Lie soo much ??????????????????:no::no::no::no::no::no::no::no::no::no::no::no::no:

    :angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry::angry:


    Ya some of us including me was surprised by this sudden attack on the WPC website. Since it was at the end of war, I thought it must be done by some canadian *%@#!! LTTE supporter. But no, then I got to know about Zonta, who pretty much like ZeroThunder is a kid who is just very curious about hacking stuff. Nothing wrong there. most of us are or were at some stage.

    I posted this incident on elakiri out of interest earlier
    http://www.elakiri.com/forum/showthread.php?t=188735

    Anyway what Zonta did may have been sort of an experiment, which it seems eventually had backfired on him. I think i can guess how he did the hack attack.

    Pls bear in mind hacking innocent websites that are useful to people, especially as Sri Lankans, defacing a government website is not at all approved :dull:

    So pls do not try your script kiddie activities on our national sites.

    Okay so here's what I think Zonta got up to
    :P

    Zonta used Shell Upload attack to gain access to the WPC site. You don't need to be so clever for this.
    The attacker uses a google dork to find potentially vulnerable websites:
    so he/she goes to Google and types:
    inurl:upload.php

    Or go to Advanced Search, select 'Date, usage rights, numeric range, and more' and set 'Region:' to Sri Lanka and then use the Google dork

    you will get a list of SL sites that will probably let you upload files. not all of them are vulnerable. some are. what's common about these sites is that they provide file upload services to users. some of them already got hacked by our curious SL hacking enthusiasts!

    so you go to such a site, check the way it lets you upload files and if you know what you are doing you can guess whether it's vulnerable. You simple find an r57, c99, c100 etc.. shell and upload it. and that's all!

    in Zonta's case, he seems to have uploaded a c100 shell. When uploaded to a site and then when accessed, the php script in those uploaded files gets executed and you get a shell prompt into the server where you can manipulate the website. for example you can replace the index file with your hack sigi.

    you don't always have to upload this malicious file (shell script) in php format. there are some other formats that servers still identify the php code in. not jpg, no that rarely works.

    you have to check the file type if you are offering file uploading services. and make the file go through proper validations to see through disguises (malicious scripts in the file etc..). i am still learning about building a proper file upload function and how to make it more secure. a colleague of mine told me that file mime type check alone is not enough as it's set by the client side, therefore can be forged. anyway this para was only for those interested web app developers. read on..

    although WPC have now taken off that mistake of its site, which was their website's file upload section (upload.php), i was still able to find it in google cache until recently. so my doubt was a bit more confirmed. you can't see that cache anymore...

    anyway here's what you can see now on a google search:
    e5idc5.jpg


    surprised why Zonta didnt use any proxies. but then again maybe he did...

    Proud of our skilled investigators!
    ;)
     
    Last edited:

    digitaldjs

    Member
    Aug 11, 2007
    926
    36
    0
    uu niyama hacker keneknam gedara internet line eka pavicchi karala web sites hack karanna tharam modayek nemeine?