Trace the ip which attacked the server.
Check if some local guy logged in to that ip. Easy.
රිමොට් ඩෙස්ක්ටොප් එක කැන්සල් කරලා දානවා යූස් කරලා ඉවර වෙලා , එතකොට කොහොමද රිමොට් එකට ලොග් උනු අයිපී ගන්නේ ,
Trace the ip which attacked the server.
Check if some local guy logged in to that ip. Easy.
රිමොට් ඩෙස්ක්ටොප් එක කැන්සල් කරලා දානවා යූස් කරලා ඉවර වෙලා , එතකොට කොහොමද රිමොට් එකට ලොග් උනු අයිපී ගන්නේ ,

There is a concept called AAA in IT security. Authentication, Authorization & Accounting.
Accounting applies here. Each ISP keeps track of what the users access on the internet.
Check the isp if someone has logged into that remote server which attacked the government server.![]()
oka machan steps 2kin karoth....trace karanna ba neda?.....mama waradinam corection karapan......
.....
Eth puluwan ban. Habai lankawe policiyata / CERT ekata witharak ba.
Wena ratawal walin udaw ganna one ee ratawala service providers la gen.
ex - first from china then from russia, us.
Nikan interpol ekath ekka ekathu wela wada karanawa wage.
Eth puluwan ban. Habai lankawe policiyata / CERT ekata witharak ba.
Wena ratawal walin udaw ganna one ee ratawala service providers la gen.
ex - first from china then from russia, us.
Nikan interpol ekath ekka ekathu wela wada karanawa wage.






That's Right machan...........
wena wena country wala rules and regulation ekka baladdi godak kal yana wada..............dawas 2n thunen nam allanna nam ba........



Gedara gihin balannam ban. Dan yanna hadanne.
Ow kal yanawa. Eth dan owata international laws thiyanawa ban.
Nikanma servers walin bounce karala witharak hari yanne na. Policiyen gedaratama hoyagena ei.
Wena podi podi dewal thiyanawa karanna mulinma.
It takes a lot of time than those movies show us.
A hacker might take about 6 months to gather information about the target.
ඕක අල්ල ගත්ත හැටි කියපන් කෝ
කොහොමද ට්රෙස් කරේ
රිමෝට් ඩෙස්ක්ටොප් එකක් ඇතුලට වීපීඑස් දාගෙන ඕක කරානම් ලොවෙත් අහුවෙන්නෑ . මුන් ශුවර් එකටම ලංකාවේ අයි.පී එකක් යූස් කරන්න ඇත්තේ මාට්ටු වෙන්න හිතාගෙනමද දන්නෑ
සමහර විට කව්රුවත් බලන්නෙ නැති කාටවත් වැඩක් නැති සයිට් එකක් හැක් කරයි කියල හදපු එකා හිතන්නෙ නැතුව ඇති.




ඌ white hat කෙනෙක්. නැත්තන් උට හොද විනාශයක් කරන්ට තිබ්බා. ඒත් ඌ ලංකාවේ සයිට් වල security up කරන්ට කියල message එකක් තියලයි ගියේ, ඌ එහෙම නොකර නම් ඔය හිටන්ගේ ඇඩ්මින් ල සෙට් එක ඌ ආව කියලවත් දැන ගන්නේ නෑ.. ඌ ඔය කරපු දේ නිසා දැන් ගොඩ දෙනෙක්ට පණිවිඩේ ගියා කියලයි මට හිතෙන්නේ. including හිටං.
ඔය කොල්ලට පිං සිද්ධ වෙන්න මේ දවස් ටිකේ ට්රැෆික් තියෙන්න ඇති. නැත්තං ඕවට මැස්සෙක් වත් නෑ.අදාළ වීඩියෝ පටය කරන එකා එය කරන්නේ ඔබ වැනි ළදරුවන් ගොදුරු කර ගැනීමට නම්, ඒ “පයිඩ් පයිපරයාට” ඔබ පහසුවෙන් හසුවනු ඇත.


Still traceable because of international laws & CERT.actually this is wrong , you can trace .
all you have to do is find a vpn that does not keep logs , / find a ip of a country that will never corporate with sri lanka .
මචං ජනාදිපති තුමාගේ වෙබ් අඩවිය හදල තියෙන්නේ wordpress use කරල මම දන්න විදියට ඕක හැදුවේ Hameedul Aqeel (https://www.facebook.com/mnhaqeel) කියන මුස්ලිම් තරුණයෙක්.
![]()
http://www.president.gov.lk/wp-login.php?redirect_to=http://www.president.gov.lk/wp-admin/&reauth=1
ඔය තියෙන්නේ.
සයිට් එක හැක් උනේ sql injection එකකින්.
නමුත් ඒ wordpress වල වරදකින් නෙමේ. මෙයාලා Photo album එකක් දාන්න wordpress standard වලට අනුව wp plugin එකක් ලියාගන්න බැරි කමට හෝ කම්බැලි කමට එහෙමත් නැත්නම් තියෙන තීම් එකට ගැලපෙන හෝ අවශ්ය විදියට wp plugin එකක් හොයාගන්න බැරි උන නිසා web root එකේ custom php script එකක් දාල තියෙනව. ඒකෙන් පාස් වෙන query parameter එකෙන් තමයි sql injection එක දීල තියෙන්නේ. මොකද පැරාමීටර් එකෙන් පාස් වෙන values escaping කරල නෑ.
අන්න ඒකයි හැක් වෙලා තියෙන්නේ.
මේ තියෙන්නේ ඇටෑක් කරපු url එක.
Target: http://www.president.gov.lk/photoAlbumViewThumbs.php?titleId=20110421111233'
ඔය රතුපාටින් තියෙන්නේ පැරාමීටර් එක.
ඒ වගේම සෙකුරිටි ගැන කිසිම උනන්දුවක් තිබිල නෑ
මේතියෙන්නේ තිබ්ච්ච ඇඩ්මින් යූසර්නේම් පාස්වර්ඩ්ස්...
Code:username password email userlevel useronly b420243d6f14831b8a1098ee10fb0450 [email protected] 1 admin 8a8644842043beaf6fa725e1b71675b3 [email protected] 9 userName password UserLevel admin gvt123 1
යූසර් නේම් එක admin
password hasing algo එකත් පට්ටම පරන එකක්. ඇත්තම කියනවනම් ලෝකේ දැන් කිසිම කෙනෙක් md5 යූස් කරන්නෑ password hashing වලටදැනට තියෙන්නේ dcript blowfish slow algo එක හොදම එක.
මට හිතාගන්න බැරි උනා md5 යූස් කරල තියෙනව දැන ගත්තම.
මොකක්ද ඇත තේරුම two way algo password වලට යූස් කරන එක.
මම කියන්නේ බොරුනම් මේ සයට් එකට ගිහින් චෙක් කරල බලන්න.
http://md5decryption.com/
ඕකට ගිහින් MD5 Decription එක උබන්න එතනට මේ හෑෂ් එක 8a8644842043beaf6fa725e1b71675b3 දාල Decript කියල බටන් එක ඔබල බලන්න
පාස් වර්ඩ් එකට අකුරු 6යි gvt123letter case, special characters මුකුත් නෑ
දැන් හිතා ගන්න පුලුවන්නේ ඕවල වැඩ කරන අයගේ තරම, එක්කෝ තමන්ගේ වගකීම දන්නෑ,
මමනම් ජනාදිපති ඔය සයිට් එකට වගකියයුතු හැම කෙනාවම ගෙදර යවනව.![]()
There is a concept called AAA in IT security. Authentication, Authorization & Accounting.
Accounting applies here. Each ISP keeps track of what the users access on the internet.
Check the isp if someone has logged into that remote server which attacked the government server.![]()