Wednesday, February 1, 2012

TinKode-ESET NOD32 Taiwan Full Disclosure


ESET NOD32 Taiwan Full Disclosure

Posted by isrtinkode on March 22, 2010
#NOD32 Taiwan@ TinKode - Romania
About ESET:
ESET is an IT security company headquartered in Bratislava, Slovakia that was founded in 1992 by the merger of two private companies. The company is privately held and has branch offices in San Diego, California; Wexford, Ireland; London, United Kingdom; Buenos Aires, Argentina; Prague, Czech Republic and Kraków, Poland.
Vulnerable website: www.eset.com.tw to MySQL Injection.

Main Informations:
  • Version : 5.0.45
  • Database: nod32twnew
  • Datadir : /var/lib/mysql/
  • User    : censored

Databases:
  • information_schema
  • mysql
  • nod32twnew

Tables from main database:
  • article
  • category
  • enterprise_apply
  • estore_product
  • estore_product_20100106
  • estore_product_category
  • estore_product_category_20100106
  • estore_product_copy
  • faq_category
  • faq_category_detail
  • game3
  • manager
  • nodtwflash1
  • register
  • regkeyreplace
  • trial30
  • updates
We have permission to access mysql.user accounts:

MySQL.user account:
  • censored  :  censored
Accounts from manager table:
  • admin    :  censored
  • editor   :  censored
  • nod32@tw :  censored
  • soman    :  censored
The accounts are in plain-text… great!
Now some keys from “ censored key censored “:
  • J102- censored :J112- censored
  • J102- censored :J112- censored
  • J102- censored :J112- censored
  • J102- censored :J112- censored
  • J102- censored :J112- censored
  • J102- censored :J112- censored
  • J102- censored :J112- censored
  • J102- censored :J112- censored
  • J102- censored :J112- censored
~Verry simple!
Other webservers of ESET NOD32 hacked: NOD32 Hong Kong & NOD32 Romania
~Thanks, TinKode

TinKode-Daily Telegraph websites hacked


Daily Telegraph websites hacked

Posted by isrtinkode on April 15, 2010
Telegraph site hacked by Romanians
The ‘Romanian National Security’ logo on the Telegraph’s hacked site
Part of the Daily Telegraph‘s website has been hacked, apparently by people in Romania who were aggrieved at its identification of “gypsies” and “Romanians”.
Its “Short Breaks” and Wine And Dine sections were both hacked, with the Short Breaks site still up at 12.55pm today, with a picture of a Romanian flag claiming to be for the “Romanian National Security”, some comments in Romanian and the remark in English at the bottom that “Guess what, gypsies aren’t romanians, morons.” It also links to a Russian site which plays an MP3 called The Lonely Shepherd.
Sunbelt Software, which first noticed the hack, said that it had alerted the Telegraph when it noticed the hack.
The method used to hack into the site is not known. Chris Boyd, a researcher at Sunbelt, said that a translation of the text from the page says that the hackers are “sick of seeing garbage like this … calling us Romanians ‘gypsies’.” It also attacks Britain for “broadcasting shitty TV programs like Top Gear”.
But Boyd said that the group is apparently unknown even among Romanian hackers – suggesting that it may be one person with a grievance against the Telegraph.
In March 2009 the Telegraph’s system was also hacked, exposing the email addresses of registered users on part of its site. That hack also seems to have been done by a Romanian hacker – suggesting that the site has become a target.
A later posting in May on the Hackersblog site suggested that there was a weakness on the Telegraph site that allowed it to be hacked repeatedly.

TinKode-US Army Medical Department Regiment


US Army Medical Department Regiment Hacked

Posted by isrtinkode on April 15, 2010

About U.S. Army Medical Department:

The U.S. Army Medical Department was formed on 27 July, 1775, when the Continental Congress authorized a Medical Service for an army of 20,000 men. It created the Hospital Department and named Dr. Benjamin Church of Boston as Director General and Chief Physician. On 14 April, 1818 the Congress passed an Act which reorganized the staff departments of the Army. The Act provided for a Medical Department to be headed by a Surgeon General. Dr. Joseph Lovell, appointed Surgeon General of the United States Army in April 1818, was the first to hold this position in the new organization. The passage of this law marks the beginning of the modern Medical Department of the United States Army.
….
This web site been designed to provide you with useful information about the U.S. Army Medical Department (AMEDD) Regiment. Through this web site, you will learn the history of the AMEDD Regiment, the symbolism behind our heraldic items, how to wear the Regimental Distinctive insignia, and various programs available to you and your unit.
URL: http://ameddregiment.amedd.army.mil