Search This Blog

Powered by Blogger.

Blog Archive

Labels

About Me

Showing posts with label INTRA. Show all posts

Team INTRA hacked into canon and siemens websites


A hacker known as JoinSe7en from Team INTRA claims to have hacked into subdomains of Canon and Siemens.Apparently, the hacker has found and exploited a Blind SQL Injection vulnerability in Canon's website and a Error based SQL Injection in Siemens.

He published a full disclosure on both of the databases on pastebin:
Siemens:
http://pastebin.com/HBL966wh
Canon:
http://pastebin.com/fbL0s9aS

60 High Profile sites vulnerable to XSS ~Zer0Freak(Team Intra):Op#Zer0XSS

A hacker from Intra, -Zer0Freak-, has found countless XSS vulnerabilities on high profile websites i.e. Companies, News, Products, Famous sites and many more.

-Zer0Freak- didn’t take much time finding them; he was to have said that he found these vulnerabilities in less than 30 min. However, he admitted that he took a while trying to figure out which site to XSS.

Cross Site Scripting(XSS) is a very harmful method of hacking websites, in fact it’s the 2nd most malicious act against hacking websites.

High profiles sites including EA games, NASA, ABC, LG,Adidas,Harvard University and more high Profile sites are found to be vulnerable to XSS attack.  Hacker list of vulnerable sites in pastebin with screenshot:
http://pastebin.com/Np3LGY6Z

Hacker claimed that he did this operation for Educational XSS and malicious activity used for training. Some of them are patched, but most are still vuln

Hacker published the full disclosure in pasteit website with password protection and claimed only members who willing to learn XSS can have it.

Full Disclosure Can be found here
http://pasteit.com/16958

Epson Brasil, Canon Nepal, FUJIFILM and Nikon Asia website Hacked by Mx. from INTRA

A Hacker known as Mx. from Team INTRA hacked four high profile sites and exposed the database details in pastebin.

The website belong to Nikon Imaging Asia Pacific(Nikon Imaging Asia Pacific), FUJIFILM Portugal(www.fujifilm.pt/),Epson Brasil(www.epson.com.br/) and Canon Nepal(canon-nepal.com) has been hacked by Team INTRA.

Pastebin leak:
http://pastebin.com/L4wnPh6s
http://pastebin.com/py8491V5
http://pastebin.com/s4Eq97tq
http://pastebin.com/m40WuHqF

Hacker exploited the SQL injection vulnerability in the websites and managed to extract the database.  The dump contains the username ,passwords of the hacked websites.

Garmin Southern Africa & Sharp Malaysia Hacked by Mx. from Team INTRA

A hacker known as Mx., from Team INTRA hacked into a high profile website Garmin Southern Africa (garmin.co.za). GARMIN, the world leader in Global Positioning System (GPS) technology and an innovator in consumer lifestyle electronics.
 
Hacker dumped the database detail in pastebin.  The leak contains the login info(username, encrypted password).  Also, the leak contains User Id, name, email and other details.


Also he hacked into Sharp Malaysia and leaked the database information in pastebin.


Team INTRA hacked MTV.com.au and Toshiba Subdomain


Team INTRA, one of the infamous hacker group, hacked MTV.com.au website and exposed database in pastebin. MTV Australia is 24 hour general entertainment channel specialising in music and youth culture programming which serves Australia.

The dump of the database contains username and password of admin and other users.  Unfortunately, passwords are in plain text.  Also, The password are very simple to guess.

Hackers also provide a vulnerable link of the mtv.com.au website.  The subdomain gallery.mtv.com.au is vulnerable to SQL Injection attack.

Pastebin link:
http://pastebin.com/CpaAUuXN

Update
Hackers also discovered SQL injection vulnerability in one of subdomain of Toshiba and exploited the vulnerability.  They dump the database details in pastebin. The dump has the username and passwords in plain text.

Philips website has been hacked by Bch195 and HaxOr

Hackers Bch195 and HaxOr ,Team INTRA, hacked into Philips website and defaced one of the sub domain of Philips. Sub domain www.microsites.philips.com is defaced by hackers.

Philips is a Dutch multinational electronics company headquartered in Amsterdam. It was founded in Eindhoven in 1891 by Gerard Philips and his father Frederik. It had revenues of €25.42 billion in 2010.

Hackers exposed the details of the database belong to the philips websites in privatepaste website. They posted the private paste links(3 links) in pastebin with secure id for the paste.

The leak contains personal information ,including name, address, phone number and email id. From the screenshot of shell which is provided by hacker, It clears that hackers has access to other sub domain also.



Pastebin link:
http://pastebin.com/BDbrcx8b

Two XSS Vulnerabilities found in NASA websites by Team INTRA


The well known Hacker group "Team INTRA" discovered two XSS Vulnerabilities in NASA websites.  The vulnerabilities found in sub domain of nasa.gov , LANCE - Land Atmosphere Near real-time Capability for EOS(lance.nasa.gov) and EOSDIS - Earth Data Website (earthdata.nasa.gov) .

Vulnerability Details:
Type: Reflected-XSS

Target: nasa.gov
Author: Team Intra
Vulnerable link:
  • http://lance.nasa.gov/?s=<script>alert("HaxOr///INTRA");</script>
  • http://earthdata.nasa.gov/search?term=<script>alert("HaxOr///INTRA");</script>&site[1]=1&form_id=search-earthdata

Hacker said this is tribute to TinKode. Tinkode is one of famous hacker who Vulnerabilities in Government sites including NASA websites and exposed it. Few days back, Romanian authorities arrested a suspect as Tinkode.