[iwar] [fc:India:.Atomic.Energy.Regulatory.Board.&.AIIMS.website.defaced]

From: Fred Cohen (fc@all.net)
Date: 2001-10-25 10:28:07


Return-Path: <sentto-279987-3410-1004030920-fc=all.net@returns.onelist.com>
Delivered-To: fc@all.net
Received: from 204.181.12.215 [204.181.12.215] by localhost with POP3 (fetchmail-5.7.4) for fc@localhost (single-drop); Thu, 25 Oct 2001 10:30:07 -0700 (PDT)
Received: (qmail 8820 invoked by uid 510); 25 Oct 2001 17:28:08 -0000
Received: from n10.groups.yahoo.com (216.115.96.60) by 204.181.12.215 with SMTP; 25 Oct 2001 17:28:08 -0000
X-eGroups-Return: sentto-279987-3410-1004030920-fc=all.net@returns.onelist.com
Received: from [10.1.1.220] by n10.groups.yahoo.com with NNFMP; 25 Oct 2001 17:28:43 -0000
X-Sender: fc@red.all.net
X-Apparently-To: iwar@onelist.com
Received: (EGP: mail-8_0_0_1); 25 Oct 2001 17:28:39 -0000
Received: (qmail 71778 invoked from network); 25 Oct 2001 17:28:04 -0000
Received: from unknown (10.1.10.27) by 10.1.1.220 with QMQP; 25 Oct 2001 17:28:04 -0000
Received: from unknown (HELO red.all.net) (65.0.156.78) by mta2 with SMTP; 25 Oct 2001 17:28:04 -0000
Received: (from fc@localhost) by red.all.net (8.11.2/8.11.2) id f9PHS7R14506 for iwar@onelist.com; Thu, 25 Oct 2001 10:28:07 -0700
Message-Id: <200110251728.f9PHS7R14506@red.all.net>
To: iwar@onelist.com (Information Warfare Mailing List)
Organization: I'm not allowed to say
X-Mailer: don't even ask
X-Mailer: ELM [version 2.5 PL3]
From: Fred Cohen <fc@all.net>
X-Yahoo-Profile: fcallnet
Mailing-List: list iwar@yahoogroups.com; contact iwar-owner@yahoogroups.com
Delivered-To: mailing list iwar@yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:iwar-unsubscribe@yahoogroups.com>
Date: Thu, 25 Oct 2001 10:28:07 -0700 (PDT)
Reply-To: iwar@yahoogroups.com
Subject: [iwar] [fc:India:.Atomic.Energy.Regulatory.Board.&.AIIMS.website.defaced]
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

Source: http://www.srijith.net/indiacracked/

Following up on their threat to deface Indian sites, the group PHC
(Pakistan Hackerz Club) and AIC (Anti India Crew) scored major hits when
they defaced the website of Atomic Energy Regulatory Board and All India
Institute of Medical Sciences respectively. 

In the message left over at the defaced Atomic Energy Regulatory Board
website, 'Doctor Nuker' of PHC left another warning for zeenews.com "/*
Message To Zeenews.com: "I'll be back...trust me!" */ ".  In the same
page, 'Doctor Nuker' claims to have got some documents which are named
as "docs/formula1.xls", "docs/formula- final.xls" and "backup/maps.zip"
from the compromised server.  In the message left at the AIIMS site, AIC
says "Hacked again as promised" and challenges YIHAT to "TRY US give it
your best shot". 

The NMap output shows that Atomic Energy Regulatory Board machine was
running IIS 3.0 webserver while the AIIMS machine was running
Netscape-FastTrack/2.01 on IRIX 6.x.  The AIIMS website had been defaced
earlier by a group called "Crime Lordz". 

Defaced Atomic Energy Regulatory Board  mirror:
<a href="http://defaced.alldas.de/mirror/2001/10/24/www.aerb.gov.in/">http://defaced.alldas.de/mirror/2001/10/24/www.aerb.gov.in/>

Defaced AIIMS website:
<a href="http://defaced.alldas.de/mirror/2001/10/24/www.aiims.ac.in/">http://defaced.alldas.de/mirror/2001/10/24/www.aiims.ac.in/>

------------------------ Yahoo! Groups Sponsor ---------------------~-->
Pinpoint the right security solution for your company- Learn how to add 128- bit encryption and to authenticate your web site with VeriSign's FREE guide!
http://us.click.yahoo.com/yQix2C/33_CAA/yigFAA/kgFolB/TM
---------------------------------------------------------------------~->

------------------
http://all.net/ 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 



This archive was generated by hypermail 2.1.2 : 2001-12-31 20:59:57 PST