Did Malaysia PMO website get hacked?

2008 June 5
by kormmandos

Update:
According to the “hack page”, a special officer called it an unsuccessful hacking attempt.
Wah lao! Either you are giving too much credit to the “hacker”, or you are telling us how un-savvy you are with computers lor.
Still, credits to the techies behind the website for rectifying the loop hole. It is now not possible to link an external webpage.

Not really, or at least I think it wasn’t. Here’s why:

A Malaysian contact on my multiply thought that the Malaysia Prime Minister Office website got hacked and posted a screen shot of the hacked page with the URL in it.

pmo_hacked

On closer look, I suspected something amiss about the URL, why would a the PMO site link to a geocities hosted page?

pmo_hacked_url

I tried to putting a different URL in place of the geocities URL and it worked, I successfully “hacked” the Malaysia PMO website.

So I shared my findings with the Multiply contact and by the time I was done posting the reply to his post, the Malaysia PMO website was down and “under construction”.

mypmo_site_down

I can’t be sure what exactly happened, but I’m guessing the tech support behind the PMO website must have had a knee jerk reaction from the screen shots that might have been circulated. If so, then it has been yet another case of self-pwn. Way to go, neighbour!

Hmm… Does anyone have a screen shot of the PMO page with a pr0n site “hacked” into it? :p

By the way, I have been nominated for ping.sg’s blog awards, running for The Best Photoblog and Best Photo Post. If you liked what you’ve found on my blog, please take a moment to vote for bLog by Pixels. Thanks!

Best Photoblog
Vote Me

Best Photo Post
Vote Me

3 Responses leave one →
  1. 2008 June 6

    it was a remote file inclusion. good thing – the attacker was not able to execute commands on the server, else it would have been worse.

  2. 2008 June 6
    malaysianx permalink

    it’s called cross-site scripting.. in layman .. the PMO server got hole inside..

    http://en.wikipedia.org/wiki/Cross-site_scripting

Trackbacks & Pingbacks

  1. Was the Malaysian Prime Minister Office website defaced or not? - IT Security Top Headlines

Leave a Reply

Note: You can use basic XHTML in your comments. Your email address will never be published.

Subscribe to this comment feed via RSS