0o0 Vulnerabilities 0o0
SQL Injection (60 vuls)
Cross Site Scripting (25 vuls)
Message to Admin : Improve your site security
If you wanna more about this , please contact me : blackcoder[at]ymail[dot]com
You probably read that story somewhere
last month, on December 17 2009 Twitter's homepage has been replaced by this
message:
"Iranian Cyber Army
THIS SITE HAS BEEN HACKED BY IRANIAN CYBER ARMY
iRANiAN.CYBER.ARMY@GMAIL.COM
U.S.A. Think They Controlling And Managing Internet By Their Access, But THey
Don’t, We Control And Manage Internet By Our Power, So Do Not Try To
Stimulation Iranian Peoples To….
NOW WHICH COUNTRY IN EMBARGO LIST? IRAN? USA?
WE PUSH THEM IN EMBARGO LIST ;)
Take Care."
They "simply" hacked their registrar (dyndns) and modified their DNS
entries.
Yesterday the Baidu homepage, China's n°1 search engine, got defaced by the same attacker and with the same method, but this time register.com was the vulnerable registrar.
According to AFP, the page was carrying the following message in persian:
"In reaction to the US authorities’ intervention in Iran’s internal affairs. This is a warning"
According to The Media Line, some Iranian governments websites have been taken down by Chinese hackers in response to the hijacking.
These attacks on registrars are nothing new, we published some articles last year about their increase, saying that registrars were often the weak link of the internet sites security:http://www.zone-h.org/news/id/4708
http://www.zone-h.org/news/id/4695
We didn't get any of those notifications (twitter, baidu), in the future, if you happen to see a defaced site while browsing, feel free to submit it to us, anybody can do this and it is anonymous


