Indian Gov websites hacked!

47 views
Skip to first unread message

Vivek Ponnulliyil

unread,
Jan 28, 2010, 12:46:47 PM1/28/10
to null-...@googlegroups.com
Dear all,
On 27/01/2010 these sites were hacked...

Some Info...

http://rajbhavan.maharashtra.gov.in/login.htm notified by Red-D3v1L
http://www.zone-h.org/mirror/id/10154905
http://tantamukta.maharashtra.gov.in/gr/ notified by Red-D3v1L
http://www.zone-h.org/mirror/id/10154896
http://zpthane.maharashtra.gov.in/scripts/ notified by Red-D3v1L
http://www.zone-h.org/mirror/id/10154873
http://fisheries.maharashtra.gov.in notified by Red-D3v1L
http://www.zone-h.org/mirror/id/10154834
http://mhada.maharashtra.gov.in notified by Red-D3v1L
http://www.zone-h.org/mirror/id/10154837
http://www.zone-h.org/mirror/id/10160423
http://iscmumbai.maharashtra.gov.in notified by j0rd4n14n.r1z
http://www.zone-h.org/mirror/id/10160424
http://rmvs.maharashtra.gov.in notified by j0rd4n14n.r1z
http://www.zone-h.org/mirror/id/10160426
http://mahilaayog.maharashtra.gov.in notified by j0rd4n14n.r1z
http://www.zone-h.org/mirror/id/10160427
http://maha-ss.maharashtra.gov.in notified by j0rd4n14n.r1z
http://www.zone-h.org/mirror/id/10160428
http://mshrc.maharashtra.gov.in

Vivek Ponnulliyil
Director Technology, Research & Development [Europe & Asia Pacific Region]

Bel Q UG (haftungsbeschraenkt)
Markt 1, 07958, Hohenleuben, Germany
Phone : +4915120522269, +493662283690

>
> Mobile: Europe:+447550040766
> Mobile: India: +919654414992, +919847309545
>
> Official Email: vi...@belqinc.com
> Personal Email: iamher...@gmail.com
> VOIP/ Chat: Skype: iamherevivek
>
>
"The information in this e-mail and any attachments is confidential and may
be legally privileged. It is intended solely for the addressee or
addressees. If you are not an intended recipient, please delete the message
and any attachments and notify the sender of mis delivery. Any use or
disclosure of the contents of either is unauthorized and may be unlawful.
All liability for viruses is excluded to the fullest extent permitted by
law.²
>

rockey killer

unread,
Jan 28, 2010, 7:35:52 PM1/28/10
to null-...@googlegroups.com
What else could be the result when government officials are not even replying ....
I have tried almost every contact listed or I can find in any nic , gov and cert sites asking
If I can report the vulnerability to them related to vulnerability in government sites ..
none of them replied .. i don't want to disclose these vulnerabilities publicly as this can
further harm Indians ..... now I am thinking like no one cares about it ...

--
It's all about Hacking and Security

http://h4ck3r.in/

Sasi Kumar

unread,
Jan 28, 2010, 10:54:20 PM1/28/10
to null-...@googlegroups.com
Rockey,
 
there are people in the middle management who care about it but their contact lists are far from known..... Let me try with one of my contacts let us see if that helps...
 
Dont take me wrong Security is a joke in india until media could make it public and debates happen... and media keeps chewing it...

 

--
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/

rajan ways

unread,
Jan 29, 2010, 1:36:58 AM1/29/10
to null-...@googlegroups.com
If you people are interested in to bring it in media ,then i can help ...one of my relative is into it..let me know what you decide..
another thing I want to clear is what impact can be made to those site after hacking it.....give me some concrete point where it can be exploited at substantial level..

Vivek Ponnulliyil

unread,
Jan 29, 2010, 2:06:15 AM1/29/10
to null-...@googlegroups.com
Just click that link from zone-h mirror, you can see what was done after hacking it..
It can be exploited to any level, once we gain access to the server (shell or server side app to access data on the server).. These defacements are hybrid PUT method & other manipulations to static / dynamic code on these servers..



On 1/29/10 12:06 PM, "rajan ways" <raja...@gmail.com> wrote:

If you people are interested in to bring it in media ,then i can help ...one of my relative is into it..let me know what you decide..
another thing I want to clear is what impact can be made to those site after hacking it.....give me some concrete point where it can be exploited at substantial level..


Vivek Ponnulliyil
Director Tec
hnology, Research & Development [Europe & Asia Pacific Region]

Bel Q UG (haftungsbeschraenkt)
Markt 1, 07958, Hohenleuben, Germany
Phone : +4915120522269, +493662283690

Mobile: Europe:+447550040766
Mobile: India: +919654414992, +919847309545

Official Email: vi...@belqinc.com
Personal Email:
iamher...@gmail.com
VOIP/ Chat: Skype: iamherevivek


"The information in this e-mail and any attachments is confidential and may be legally privileged. It is intended solely for the addressee or addressees. If you are not an intended recipient, please delete the message and any attachments and notify the sender of mis delivery. Any use or disclosure of the contents of either is unauthorized and may be unlawful. All liability for viruses is excluded to the fullest extent permitted by law.”


image.png

SUDHAKAR PATIBANDLA

unread,
Jan 29, 2010, 5:03:36 AM1/29/10
to null-...@googlegroups.com
Dear All,

                I am also working with Media in VIJAYAWADA i have contacts in Cyber Crime team. Please tell me all sites which are vulnerable so that i can work those teams. We will inform same to media also


Thanks & Regards,
Sudhakar.P,
Mobile :-
+919966737740-AP



image.png

Sudhanshu Ambesange

unread,
Jan 29, 2010, 6:27:26 AM1/29/10
to null-...@googlegroups.com
send an email with URGENT as subject as mentioned on http://www.cert.org.in/contact.htm and send a cc to mo...@nic.in (http://www.mit.gov.in/default.aspx?id=705) and secr...@mit.gov.in
Reply all
Reply to author
Forward
0 new messages