Hacker Busted in Sri Lanka ( Real Story )

HIVOLTAG3

Banned
Feb 29, 2008
1,273
9
0
Z0nta got heavy reputation on 1nj3ct.in [also closed], may b z0nta showoff to much.

what is da point?,

i can c sum1 haz read this post too..

Code:
http://www.hackforums.net/archive/index.php/thread-82610.html
 

hasithw007

Member
Mar 31, 2009
2,656
11
0
muta kiyala tamilnet eka hack korawanna tiyenne.... oya wage eungen wadak ganna ona.. nikan tiyanna hoda na.
 

kenji86

Well-known member
  • Apr 18, 2007
    6,618
    62
    48
    @ Backyard-Spot



    Ya some of us including me was surprised by this sudden attack on the WPC website. Since it was at the end of war, I thought it must be done by some canadian *%@#!! LTTE supporter. But no, then I got to know about Zonta, who pretty much like ZeroThunder is a kid who is just very curious about hacking stuff. Nothing wrong there. most of us are or were at some stage.

    I posted this incident on elakiri out of interest earlier
    http://www.elakiri.com/forum/showthread.php?t=188735

    Anyway what Zonta did may have been sort of an experiment, which it seems eventually had backfired on him. I think i can guess how he did the hack attack.

    Pls bear in mind hacking innocent websites that are useful to people, especially as Sri Lankans, defacing a government website is not at all approved :dull:

    So pls do not try your script kiddie activities on our national sites.

    Okay so here's what I think Zonta got up to
    :P

    Zonta used Shell Upload attack to gain access to the WPC site. You don't need to be so clever for this.
    The attacker uses a google dork to find potentially vulnerable websites:
    so he/she goes to Google and types:
    inurl:upload.php

    Or go to Advanced Search, select 'Date, usage rights, numeric range, and more' and set 'Region:' to Sri Lanka and then use the Google dork

    you will get a list of SL sites that will probably let you upload files. not all of them are vulnerable. some are. what's common about these sites is that they provide file upload services to users. some of them already got hacked by our curious SL hacking enthusiasts!

    so you go to such a site, check the way it lets you upload files and if you know what you are doing you can guess whether it's vulnerable. You simple find an r57, c99, c100 etc.. shell and upload it. and that's all!

    in Zonta's case, he seems to have uploaded a c100 shell. When uploaded to a site and then when accessed, the php script in those uploaded files gets executed and you get a shell prompt into the server where you can manipulate the website. for example you can replace the index file with your hack sigi.

    you don't always have to upload this malicious file (shell script) in php format. there are some other formats that servers still identify the php code in. not jpg, no that rarely works.

    you have to check the file type if you are offering file uploading services. and make the file go through proper validations to see through disguises (malicious scripts in the file etc..). i am still learning about building a proper file upload function and how to make it more secure. a colleague of mine told me that file mime type check alone is not enough as it's set by the client side, therefore can be forged. anyway this para was only for those interested web app developers. read on..

    although WPC have now taken off that mistake of its site, which was their website's file upload section (upload.php), i was still able to find it in google cache until recently. so my doubt was a bit more confirmed. you can't see that cache anymore...

    anyway here's what you can see now on a google search:
    e5idc5.jpg


    surprised why Zonta didnt use any proxies. but then again maybe he did...

    Proud of our skilled investigators!
    ;)

    wow machan, nice information bro..Actually I was reading ur post than the original thread..thnx for the info:yes:
     

    viraj_slk

    Active member
  • Oct 1, 2007
    505
    35
    28
    wow machan, nice information bro..Actually I was reading ur post than the original thread..thnx for the info:yes:

    thanks mchn. i forgot to mention that not only jpg but most of the time no image file type works. but i hv seen cases where many other innocent looking formats, for eg. *.flv working surprisingly well. so the file does not have to be like c100.php . the attacker can rename it to sm like 'butterfly.flv'. ;)

    WPC jst happened to be really vulnerable to shell upload at that time. so the attacker simply took advantage of it. good lesson for all web developers why learning attack techniques and countermeasures is an important part of learning to become a better developer.
     
    Last edited:

    pjayampathi

    Well-known member
  • Jan 20, 2008
    6,253
    39
    48
    I think this is what happend..
    Zonta's wasn't going to hack the web site.. So he didn't use
    any IP crypter or proxy. What he wanted to do was to test or learn a
    PHP Shell script attack. He did a google search and found a web site.
    ( for more kick he used the option; Search Sri Lankan Sites )
    He Uploaded c100 PHP Script and the site was vulnarable . The
    script got executed and it was too late to use protection.
    CID guz got the IP from the log file. Did a WhoIs test and
    got the ISP. From the ISP, found who used the IP when the webpage was hacked.
    And arrested the poor bastard who I think is a maXXa kollek..

    That is why I say.. Weather it is a test or not, u
    should wear rubbers.. always ...

    :):):):)
     

    pjayampathi

    Well-known member
  • Jan 20, 2008
    6,253
    39
    48
    Real Zonta is not a Sri Lankan. The guy how did the c100
    Script is Real Zonta. He uploded it to the web with a tutorial.
    And our Zonta found it and tested it . :oo::baffled: poor SL Zontaa