The Hackers News

Bookmark and Share

The Hackers News


Video Demonstration : Vsftpd backdoor discovered by Mathias Kresin

Posted: 04 Jul 2011 09:41 PM PDT

Video Demonstration : Vsftpd backdoor discovered by Mathias Kresin
2.3.4 of vsftpd's downloadable source code was compromised and a backdoor added to the code. Evans, the author of vsftpd . This module exploits a malicious backdoor that was added to the VSFTPD download archive. This backdoor was present in the vsftpd-2.3.4.tar.gz archive sometime before July 3rd 2011.

The bad tarball included a backdoor in the code which would respond to a user logging in with a user name ":)" by listening on port 6200 for a connection and launching a shell when someone connects. Read more here

Affected versions :
vsftpd-2.3.4 from 2011-06-30

Metasploit demo :
use exploit/unix/ftp/vsftpd_234_backdoor
set RHOST localhost
set PAYLOAD cmd/unix/interact
exploit
id
uname -a

Video Demonstration :

NATO Server Hacked by 1337day Inj3ct0r and Backup Leaked !

Posted: 04 Jul 2011 02:03 PM PDT

NATO Server Hacked by 1337day Inj3ct0r and Backup Leaked !


Team Inj3ct0r ( 1337day ) claim to hack Apache Tomcat Version 5.5.9 of NATOThe North Atlantic Treaty Organization or NATO also called the (North) Atlantic Alliance, is an inter governmental military alliance based on the North Atlantic Treaty.


They Leak a Backup of Random 2,646 files from Server as Proof of Hack . The archive uploaded by hackers is available at http://www.mediafire.com/?s2chp1v2jqsf52z .



We talk to Team Inj3ct0r about this hack They said :
1.) The Reason of Hacking is "Nuclear weapons. its development and financing"
2.) They hack Tomcat 5.5 Server using 1337day privat exploit (0day) .
3.) They get the root privilege to the Server.
4.) They are able to Deface the website of NATO also, but they will not do this. They have just take the backup of server and trying to distribute that on Internet.



This archive contains various configurations XML/Batch/Bash files. Some of them as listed below :
1.) tomcat-users.xml
2.) Smartfinder.log


3.) Digest.sh
Some Weeks ago NATO Reports Data Breach to One of Its Websites NATO's e-Bookshop & Also NATO was on the target of  Anonymous. This time Team Inj3ct0r ( 1337day ) Hack whole Server of NATO and dump the backup. 

RedHack deface 1000 sites for Turkey #AntiSec

Posted: 04 Jul 2011 12:59 PM PDT

RedHack deface 1000 sites for Turkey #AntiSec
RedHack Hackers Group deface more than 1000 websites today. The complete list of hacked sites are here . The hack is done in support of Anonymous and Operation Antisec. The hackers also release a press Release as below with Reason of this hack. 


Press Release By Redhack :

Our people from all nationalities and Revolutionary,
Democrat, Patriotic and Opposition Comrades,
Since 1997 our objective is, to be the "common voice" of revolutionaries in digital arena and have carried out our actions according to this strategy. On the anniversary of Sivas Massacre which took place on 2nd July 1993 and resulted in death of thirty-five intellectuals, singer, authors and poets; we have hacked hundreds of websites belongs to Adnan Oktar also known as Harun Yahya bigot and collaborating fascist websites in order to announce that we have not forgotten this massacre and will not let it be forgotten.  We have also taken opportunity to highlight the censorship laws due to take effect in Turkey and strongly protest this. We deface 1000+ domain for anti-censorship


Adnan Oktar is responsible of forced shutdown of lots of sites in Turkey. He has send a police to the addresses of online dictionary writers and got them arrested just because they have criticised him.  While we are engaged in the activities of AntiSec, it has been our honour to show our reaction in the name of our people, to stop this vile bigoted man who uses his estate and his money for his  paranoid and fascist ideas. (WordPress.com has been blocked by Turkey 2007.) It has been our honour to show our reaction in the name of our people, to stop this vile bigoted man who uses his estate and his money for his paranoid and fascist ideas, while we are engaged in the activities of AntiSec.
These attacks have taken place to send a clear message to the authorities and the canines of the system that we are still strong and will do everything in our power to raise our voice against the censorship laws which are an attack to our human rights. We will act together with AntiSec and Anons to continue our fight against the hands that are reaching to silence our internet.
We will also announce the server data and the details of this hacking operation in the future.


Acronym of the defacement (hacking) text:
The Perpetrators of the Sivas Massacre are still amongst us!
We have not forgotten! We will ask for the account of this massacre!


It's been 16 years since this massacre took place and the perpetrators are not far away from us, they are the ones who governs us.


Who are the murderers?
The President of Turkey Abdullah Gul; defender of 6th Navy Fleet of USA while they were poured out to the sea in 1969 by the revolutionaries.


Prime Minister of Turkey Recep Tayyip Erdogan, the servant of USA under oath, the loyal guard of Imperialism, the enemy of the working class of Turkey, ruler of Greater Middle East Initiative.


The murderers are the defenders of military coups, spokesperson of USA's Moderate Islam project such as Feytullah Gulen and Adnan Oktar whose brains are full of pornography. 
(Addressed to Adnan Oktar)
You believe you are a man by operating hundreds of websites that spreads groundless articles and claim that they are an "opinion" through stealing from ordinary people by using the religion. You act instantly to shut down the sites which are opposing you. We heard that you were so proud that your sites never been hacked. You have chosen a duty of silencing the opposition by hiding behind those in power and even send the security forces to addresses that criticise you. We have a duty to be against this and used our legitimate right of defence. You attack the common values of intellectuals by swearing at Darwin theory and Che Guevera, do you know who they are? Answer is clear, no you don't you bigoted man. Put this in your mind Adnan Oktar, you have gone a step too far. The internet and this world are not unclaimed. Neither your people in power nor any of your forces are capable of stopping us. It is legitimate to resist against oppression and censorship. 
Special Thanks: Anonymous - LulzSec - Antisec - Opturkey - all anonopsIRC


Friends: MrFox - RedJunior - JiX - Neka - Sdkd - Partizan - muaddib - CaNCeR-X - tr0jan - kcy 
And..: ek$i - uludag - inci - kotu - anarsist - zeykur ve tum muhalif, "insan gibi insanlara" selam olsun..



Hacking for People since 1997!
They asked for the fire, we have been the hell!
Censorship is a crime against humanity!
Down with Fascism!
Long Live our struggle for Fair, Just, and Equal World!
AntiSec you are not alone in digital world!
We will never forget, forgive or compromise!
Long live the organised power of the people and their struggle against censorship!
Long live the opinion struggle of the people who are information thirst!
Long Live AntiSec!
Long Live Anonymous!
Long Live LulzSec!
Long Live RedHack!


REDHACK (Red Hackers Association) 
3nd July 2011 
http://www.kizilhack.org 
members@kizilhack.org