Loading....
Loading....

    Posted by unu in English News

    Posted on March 6th, 2009

    telegraphcouk
    “Latest news, business, sport, comment, lifestyle and culture plus content from the Daily Telegraph and Sunday Telegraph newspapers and video from Telegraph” and an SQLi that allows full acces to ALL the databases of this famous newspaper.

    Here are some of the database names and their version:

    Users passwords are in plain view:

    Besides numerous interesting tables there is one that contains email addresses of those receivingt he newsletter. A real treasure for spammers. In the syntax you can see there quite a bunch of them. I concatanated the 700.000th email address.

    Later edit: if you are a member of telegraph.co.uk read this article too and follow the advice regarding passwords.

    —–

    RO Version

    “Latest news, business, sport, comment, lifestyle and culture plus content from the Daily Telegraph and Sunday Telegraph newspapers and video from Telegraph”… si un sql injection, care permite full acces in toate bazele de date al respectivului ziar online.

    Sa vedem o parte din denumirile bazelor de date cat si versiunea :

    Parolele userilor sunt tinute in text clar:

    Pe langa multe alte tabele interesante avem si una cu adresele de email, a celor inscrisi pentru newsletter. O adevarata comoara pentru potentialii spammeri.In sintaxa, sa vedeti numarul mare a celor inregistrati, am concatanat adresa de email cu numarul 700.000

    Related Posts

    35 Responses to “Telegraph.co.uk hacked, sql injection”

    1. B7ackAnge7z Says:

      Am si eu o intrebare, daca asa site-uri mari si renumite, care (cred) cheltie o gramada de bani, au asa vulnerabilitati, ce se intimpla cu site-urile de talie mica si medie? :)

    2. anon Says:

      this is not the live website… easy to compare by the pictures above.

    3. unu Says:

      yes it is one of the sections of the live website, with full access to all database’s tables

    4. TREND MICRO Countermeasures » UK Telegraph web site compromised Says:

      [...] have made some high profile web site compromises recently and today they posted evidence that they had compromised the website of the UK national daily newspaper, The [...]

    5. Dave Says:

      Looks like this area of the site is no longer available

    6. Zorba Says:

      Hey guys, you are not really hackers, you are just simple php + mysql developers which find poorly written websites. That’s all I see from you, sql injection in php. Is that the best you guys can do?

    7. 2fingers Says:

      Of course not. We are also able to eat tons of ice cream.

    8. Dingo Says:

      Hmm… date on site says Tue 17 Feb 2009…

    9. Dingo Says:

      ..and Mon 23 Feb 2009… Robin Hood hacking?

    10. 2fingers Says:

      “We will do a full disclosure if the vulnerability isn’t patched in usefull time or if it’s been patched after the admin is contacted.”

      http://www.hackersblog.org/about/

      Sometimes we don’t have enough time to make all the screenshots and we make the rest of screenshots after a day or two.

    11. The Daily Telegraph website hacked | (-) HatSecurity.com Says:

      [...] Romanian group, HackersBlog, has struck again and this time it is not an infosec firm. This time it is the website of the [...]

    12.   Daily Telegraph web site compromised, hackers claim by Dinters Technology News Says:

      [...] Daily Telegraph’s web site has been compromised using an SQL injection attack, according to HackersBlog. It says: “Latest news, business, sport, comment, lifestyle and culture plus content from the [...]

    13. Links » The Telegraph Show How Not To Do It Says:

      [...] I’m a bit stunned that an organisation the size of The Telegraph would store user passwords in plaintext, but, well … they do. [...]

    14. Hackers claim attack over Daily Telegraph web site | Digital Prank Says:

      [...] claim attack over Daily Telegraph web site An ethical hacker from HackersBlog today claimed that he was able to carry out a SQL injection attack successfully and has got access [...]

    15. Telegraph site attacked, claim hackers : SupaFeed Says:

      [...] Daily Telegraph’s web site has been compromised using an SQL injection attack, according to HackersBlog. It says: “Latest news, business, sport, comment, lifestyle and culture plus content from the [...]

    16. Get It For Free » Telegraph website is hacked, says blog Says:

      [...] Spotify’s breach last week, hackersblog has posted up proof that hackers have used the SQL injection technique to gain entry to the [...]

    17. Andrew Fryer's Blog : SQL Injection, still there after all these years Says:

      [...] goes unnoticed and if you let down your guard for a minute you can be front page news, like the Daily Telegraph (interestingly on the Guardian web site).  In this case the method of attack is old chestnut, [...]

    18. Shane Richmond Says:

      Thanks guys. There is a statement from Telegraph.co.uk’s CIO on my blog here: http://blogs.telegraph.co.uk/shane_richmond/blog/2009/03/09/hackersblog_and_telegraphcouk

    19. 2fingers Says:

      With pleasure Shane.

    20. Telegraph.co.uk hacked | Developer Oracles Says:

      [...] to a blog post at hackersblog.org , Telegraph.co.uk has been [...]

    21. theStick Says:

      felicitari, ati ajuns pe digg. ;)

    22. Telegraph site attacked, claim hackers Says:

      [...] Daily Telegraph’s web site has been compromised using an SQL injection attack, according to HackersBlog. It says: “Latest news, business, sport, comment, lifestyle and culture plus content from the [...]

    23. Naughty Naughty | MadeByPi® Blog Says:

      [...] reported on the register – grey hat hackers discovered an SQL injection vulnerability in the Daily Telegraph property website. Not only did their website allow malacious users to access information stored in their website but [...]

    24. JOhn Says:

      PRINT screen cu digg ?

    25. Byron Acohido Says:

      I’m a tech security reporter for USA TODAY; I’d like to interview unu. Can anyone advise how I can get in touch with him? Thanks, Byron Acohido

    26. 2fingers Says:

      You can contact him at hackersblog.org [at] gmail.com

    27. Byron Acohido Says:

      Many thanks, 2fingers
      Byron

    28. OkiZoo Says:

      The sign up page seems like a good hack http://my.telegraph.co.uk/signup1/

    29. HackersBlog » Blog Archive » Telegraph.co.uk hacked - when will they learn? Says:

      [...] of afected users? It seems allot bigger than the first time, mostly because now we are talking full access on the server which allows data extraction of ALL [...]

    30. Daily Telegraph websites hacked « TinKode Stuff Says:

      [...] March 2009 the Telegraph’s system was also hacked, exposing the email addresses of registered users on part of its site. That hack also seems to have been done by a Romanian hacker – suggesting [...]

    31. Daily Telegraph website hacked | Reaction Radio Says:

      [...] March 2009 the Telegraph’s system was also hacked, exposing the email addresses of registered users on part of its site. That hack also seems to have been done by a Romanian hacker – suggesting [...]

    32. Daily Telegraph website hacked | World News Says:

      [...] March 2009 the Telegraph’s system was also hacked, exposing the email addresses of registered users on part of its site. That hack also seems to have been done by a Romanian hacker – suggesting [...]

    33. tazy Says:

      BRAVOOOOO. Toata stima din partea mea. Sper ca nu va opriti aici? Ma sunt imbecili destui in lumea asta.

      TOT RESPECTUL MEU

    34. Hackeri Romani se revolta pe The Telegraph | W2 Says:

      [...] The Telegraph este tinta atacurilor de genul, in martie anul trecut, websitul a fost supus unui SQL injection si la scurt timp dupa alt articol pe Hackersblog arata cum websitul are mari probleme de [...]

    35. alex Says:

      BRAVO FRATIORII MEI. NU VA OPRITI AICI! RESPECT

    Leave a Reply

    Studio videochat bucuresti Studio videochat Bucuresti
    Download Muzica Filme
    Studio videochat Iasi videochat Iasi