Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
කිතුල් තලප
Manoj Suranga Bandara
Updated:
Today at 7:04 PM
Ad icon
ව්යාපාර, Tuition පන්ති සහ Personal Portfolios සඳහා Web Setup එකක් රු. 9,099/- කට (වාර්ෂික renewal ර
thathsilura
Updated:
Thursday at 6:17 PM
AWS Certified Solutions Architect-Associate + AWS Certified Cloud Practitioner
Sanjeewani95
Updated:
Aug 19, 2026
🚀 එක පැකේජ් එකයි - මාසෙටම Unlimited Internet! 🌐
sayuru bandara
Updated:
Aug 18, 2026
🎬 CapCut Pro 1 Month Access! LKR 600
sayuru bandara
Updated:
Aug 18, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
පම්පෝරි ආණ්ඩුව සහ ජාතික ආරක්ෂාව (තාමත් ලීක්)
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="gnilukshi" data-source="post: 30755821" data-attributes="member: 132616"><p>[MEDIA=facebook]numbers.lk/posts/1285092680287261[/MEDIA]</p><p></p><p>Sri Lanka <img class="smilie smilie--emoji" loading="lazy" alt="🇱🇰" title="Flag: Sri Lanka :flag_lk:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f1f1-1f1f0.png" data-shortname=":flag_lk:" /> Pension Department Data Breach – Vulnerability Still Exists and Nobody is Fixing It!</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️ "No data lost in cyberattack on Pensions Dept, systems restored" – The Department of Pensions</p><p></p><p>This is an absolutely false statement.</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️ The breach likely wasn’t even caused by sophisticated hacking – it’s probably due to EXPOSED PUBLIC API ENDPOINTS that anyone can access.</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️ These endpoint are still open, a person with basic IT knowledge can easily write a simple script with just a few lines of code and extract the entire database. This is basic web scraping, not even "hacking".</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️ The department has inadvertently created undocumented public API endpoints that expose their entire database to the world.</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️ After the initial data dump on the dark web, the department introduced an OTP authentication. However, this OTP implementation is laughably flawed.</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️ The OTP is generated on the front end (your browser) and sent to the back end for "verification." It’s like showing you the PIN on screen and then asking you to type it back. This provides zero actual security while creating dangerous false sense of security.</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️ Every W&OP scheme member’s complete data has been compromised: Name, Address, NIC, Phone, Photo, Gratuity amounts and Workplace details. Thousands of retired government employees, military, and police families are affected. (Anyone can enter the generated number shown in your browser and access the information.)</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️ Pensioners are prime targets for scams. Scammers now have everything needed to target Sri Lankan pensioners. They can call knowing exact ID numbers, addresses, pension amounts, and workplace history.</p><p></p><p>Tell your parents/grandparents: NEVER share personal info, OTPs, or card numbers with callers – even if they know your details. Hang up and verify independently.</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️ Considering the inclusion of military personnel and public data, this should be considered national security emergency affecting the public servants and most vulnerable citizens and security personnel. Every hour of delay puts more lives at risk.</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⭕" title="Hollow red circle :o:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/2b55.png" data-shortname=":o:" />️Someone needs to immediately shut down the Pensions Department login portal (<a href="https://service.pensions.gov.lk/pensionerservices/#/login" target="_blank">https://service.pensions.gov.lk/pensionerservices/#/login</a>). Conduct a full security audit and notify all affected individuals at once. immediately.</p><p></p><p>Note: We came across this over 48 hours ago and reported it to the relevant authorities through multiple independent channels capable of independently verifying the information. However, no action has been taken so far, and the vulnerabilities remain unresolved.</p><p></p><p>#SriLanka #PensionDepartment #DataBreach</p><p></p><p>[MEDIA=facebook]rasika.hendrix/posts/2539167903103108[/MEDIA]</p><p></p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="🇱🇰" title="Flag: Sri Lanka :flag_lk:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f1f1-1f1f0.png" data-shortname=":flag_lk:" /> The Sri Lankan Department of Pensions has become the latest victim of the Cloak Ransomware gang. (<a href="https://www.pensions.gov.lk/" target="_blank">https://www.pensions.gov.lk/</a>)</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="🗓️" title="Spiral calendar :calendar_spiral:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f5d3.png" data-shortname=":calendar_spiral:" /> First hinted at on April 2, 2025 as “pe*.lk”</p><p><img class="smilie smilie--emoji" loading="lazy" alt="🧨" title="Firecracker :firecracker:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f9e8.png" data-shortname=":firecracker:" /> Confirmed on May 26, 2025 with the full domain revealed</p><p><img class="smilie smilie--emoji" loading="lazy" alt="📁" title="File folder :file_folder:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f4c1.png" data-shortname=":file_folder:" /> Over 617 GB of sensitive data dumped on the dark web.</p><p>(2389719 directories, 1340906 files)</p><p></p><p>This isn’t an isolated attack.</p><p>Sri Lanka is being repeatedly targeted — financial institutions, public services, citizen data.</p><p></p><p>Why are we so vulnerable?</p><p><img class="smilie smilie--emoji" loading="lazy" alt="🔓" title="Unlocked :unlock:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f513.png" data-shortname=":unlock:" /> Outdated systems</p><p><img class="smilie smilie--emoji" loading="lazy" alt="🛑" title="Stop sign :octagonal_sign:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f6d1.png" data-shortname=":octagonal_sign:" /> No proactive cybersecurity strategy</p><p><img class="smilie smilie--emoji" loading="lazy" alt="🧑💻" title="Technologist :technologist:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f9d1-1f4bb.png" data-shortname=":technologist:" /> Weak incident response</p><p><img class="smilie smilie--emoji" loading="lazy" alt="🌐" title="Globe with meridians :globe_with_meridians:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f310.png" data-shortname=":globe_with_meridians:" /> No geopolitical footing in global cyber defense coalitions</p><p></p><p>Here’s the truth:</p><p></p><p>We’ve been spared a massive financial wipeout so far — only because many still don’t use online banking.</p><p></p><p>But that won’t last. A full-scale money-out op is inevitable if we go on like this. And next time, it won't be just "Data". It’ll be your bank account, and your Identity.</p><p></p><p>We cannot afford digital amnesia.</p><p></p><p>It’s time to:</p><p></p><p>• Modernize — not patch</p><p>• Build and retain cybersecurity talent</p><p>• Create a national cyber threat intelligence unit</p><p>• Join global alliances and share intelligence</p><p></p><p>We are being watched. We are being tested.</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⚠️" title="Warning :warning:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/26a0.png" data-shortname=":warning:" /> TECHNICAL ALERT:</p><p>The 617G+ dump isnt just Scanned PDFs. Inside the exposed config tree are files like tomcat-users.xml likely holding hardcoded admin credentials, and hibernate.cfg.xml containing plain-text database passwords, giving full access to backend data stores. Core Tomcat configs (server.xml, context.xml) expose JNDI paths, internal ports, and context definitions, making the system vulnerable to Remote Code Execution (RCE) via known deserialization exploits. Even worse, the leak includes source code and compiled .class files for live applications, .jsp logic, WAR deployments, and runtime logs (hs_err_pid*.log) — a goldmine for attackers to craft precise payloads based on actual environment variables. There’s also a Solr data directory (/solr-example/data/index/) — suggesting searchable sensitive data was indexed and left exposed. <img class="smilie smilie--emoji" loading="lazy" alt="🔓" title="Unlocked :unlock:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f513.png" data-shortname=":unlock:" /> This isn’t just PII theft — it’s a blueprint of our infrastructure, showing adversaries exactly how the system runs, how it breaks, and how to take it over. If this were a red team simulation, it would rank P1: Total Compromise. <img class="smilie smilie--emoji" loading="lazy" alt="🇱🇰" title="Flag: Sri Lanka :flag_lk:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/1f1f1-1f1f0.png" data-shortname=":flag_lk:" /> This should trigger a national cybersecurity emergency — . For every dev, sysadmin, or security engineer in the Sri Lankan public sector: assume compromise and act like this was your stack — because next time, it might be. (PS- I didnt access any of these, dont have the time, it's hosted you know where go take a look)</p><p></p><p><img class="smilie smilie--emoji" loading="lazy" alt="⚠️" title="Warning :warning:" src="https://cdn.jsdelivr.net/joypixels/assets/6.6/png/unicode/64/26a0.png" data-shortname=":warning:" /> Disclaimer:</p><p>This post is not intended to incite panic but to ensure the public is informed about the scale and nature of the attack.</p><p></p><p>Information and screenshots were taken from publicly accessible sources, including the Cloak ransomware gang’s dark web data dump.</p><p>No private systems were accessed, and no illegal activity was undertaken in preparing this post.</p><p>The goal is clear: to raise awareness, not fear — and to call for urgent national cybersecurity reform.</p><p></p><p>#SriLanka #CyberSecurity #DataBreach #CloakRansomware #DigitalRisk #Ransomware #GovTech #Pensions #OnlineBanking #CyberAlert #Infosec #DigitalResilience</p></blockquote><p></p>
[QUOTE="gnilukshi, post: 30755821, member: 132616"] [MEDIA=facebook]numbers.lk/posts/1285092680287261[/MEDIA] Sri Lanka 🇱🇰 Pension Department Data Breach – Vulnerability Still Exists and Nobody is Fixing It! ⭕️ "No data lost in cyberattack on Pensions Dept, systems restored" – The Department of Pensions This is an absolutely false statement. ⭕️ The breach likely wasn’t even caused by sophisticated hacking – it’s probably due to EXPOSED PUBLIC API ENDPOINTS that anyone can access. ⭕️ These endpoint are still open, a person with basic IT knowledge can easily write a simple script with just a few lines of code and extract the entire database. This is basic web scraping, not even "hacking". ⭕️ The department has inadvertently created undocumented public API endpoints that expose their entire database to the world. ⭕️ After the initial data dump on the dark web, the department introduced an OTP authentication. However, this OTP implementation is laughably flawed. ⭕️ The OTP is generated on the front end (your browser) and sent to the back end for "verification." It’s like showing you the PIN on screen and then asking you to type it back. This provides zero actual security while creating dangerous false sense of security. ⭕️ Every W&OP scheme member’s complete data has been compromised: Name, Address, NIC, Phone, Photo, Gratuity amounts and Workplace details. Thousands of retired government employees, military, and police families are affected. (Anyone can enter the generated number shown in your browser and access the information.) ⭕️ Pensioners are prime targets for scams. Scammers now have everything needed to target Sri Lankan pensioners. They can call knowing exact ID numbers, addresses, pension amounts, and workplace history. Tell your parents/grandparents: NEVER share personal info, OTPs, or card numbers with callers – even if they know your details. Hang up and verify independently. ⭕️ Considering the inclusion of military personnel and public data, this should be considered national security emergency affecting the public servants and most vulnerable citizens and security personnel. Every hour of delay puts more lives at risk. ⭕️Someone needs to immediately shut down the Pensions Department login portal ([URL]https://service.pensions.gov.lk/pensionerservices/#/login[/URL]). Conduct a full security audit and notify all affected individuals at once. immediately. Note: We came across this over 48 hours ago and reported it to the relevant authorities through multiple independent channels capable of independently verifying the information. However, no action has been taken so far, and the vulnerabilities remain unresolved. #SriLanka #PensionDepartment #DataBreach [MEDIA=facebook]rasika.hendrix/posts/2539167903103108[/MEDIA] 🇱🇰 The Sri Lankan Department of Pensions has become the latest victim of the Cloak Ransomware gang. ([URL]https://www.pensions.gov.lk/[/URL]) 🗓️ First hinted at on April 2, 2025 as “pe*.lk” 🧨 Confirmed on May 26, 2025 with the full domain revealed 📁 Over 617 GB of sensitive data dumped on the dark web. (2389719 directories, 1340906 files) This isn’t an isolated attack. Sri Lanka is being repeatedly targeted — financial institutions, public services, citizen data. Why are we so vulnerable? 🔓 Outdated systems 🛑 No proactive cybersecurity strategy 🧑💻 Weak incident response 🌐 No geopolitical footing in global cyber defense coalitions Here’s the truth: We’ve been spared a massive financial wipeout so far — only because many still don’t use online banking. But that won’t last. A full-scale money-out op is inevitable if we go on like this. And next time, it won't be just "Data". It’ll be your bank account, and your Identity. We cannot afford digital amnesia. It’s time to: • Modernize — not patch • Build and retain cybersecurity talent • Create a national cyber threat intelligence unit • Join global alliances and share intelligence We are being watched. We are being tested. ⚠️ TECHNICAL ALERT: The 617G+ dump isnt just Scanned PDFs. Inside the exposed config tree are files like tomcat-users.xml likely holding hardcoded admin credentials, and hibernate.cfg.xml containing plain-text database passwords, giving full access to backend data stores. Core Tomcat configs (server.xml, context.xml) expose JNDI paths, internal ports, and context definitions, making the system vulnerable to Remote Code Execution (RCE) via known deserialization exploits. Even worse, the leak includes source code and compiled .class files for live applications, .jsp logic, WAR deployments, and runtime logs (hs_err_pid*.log) — a goldmine for attackers to craft precise payloads based on actual environment variables. There’s also a Solr data directory (/solr-example/data/index/) — suggesting searchable sensitive data was indexed and left exposed. 🔓 This isn’t just PII theft — it’s a blueprint of our infrastructure, showing adversaries exactly how the system runs, how it breaks, and how to take it over. If this were a red team simulation, it would rank P1: Total Compromise. 🇱🇰 This should trigger a national cybersecurity emergency — . For every dev, sysadmin, or security engineer in the Sri Lankan public sector: assume compromise and act like this was your stack — because next time, it might be. (PS- I didnt access any of these, dont have the time, it's hosted you know where go take a look) ⚠️ Disclaimer: This post is not intended to incite panic but to ensure the public is informed about the scale and nature of the attack. Information and screenshots were taken from publicly accessible sources, including the Cloak ransomware gang’s dark web data dump. No private systems were accessed, and no illegal activity was undertaken in preparing this post. The goal is clear: to raise awareness, not fear — and to call for urgent national cybersecurity reform. #SriLanka #CyberSecurity #DataBreach #CloakRansomware #DigitalRisk #Ransomware #GovTech #Pensions #OnlineBanking #CyberAlert #Infosec #DigitalResilience [/QUOTE]
Insert quotes…
Verification
Asuwa dahayen wadi kalama keeyada?
Post reply
Top
Bottom