Loading....

Posted by 2fingers in English News

Posted on May 29th, 2009

It seems that some companies dont learn from their mistakes and continue to jeopardise the informations they have on their users.

We again talk about telegraph.co.uk and this time it seems it is possible to upload a shell which gives full access on their server. This is facilitated by an SQLi vulnerability. We cannot overlook the fact that even to this date, user passwords are in plain view, regardless of the fact that all experts in IT security recommend that ANY passwords should have a minimum encription.

Number of afected users? It seems allot bigger than the first time, mostly because now we are talking full access on the server which allows data extraction of ALL users data from all services offered by the site. This could mean millions of accounts. Last time, a single affected service of telegraph.co.uk allowed extraction of 700.000 accounts.

According to “unu”, he tried to start a dialog with someone in the company but it was ignored so he decided to send us all the information for a full disclosure.

We RECOMMEND to all registered users of telegraph.co.uk to change their passwords ASAP as soon as the problem is solved. In the meantime, change email passwords if those happen to be the same as the one used to log in to telegraph.co.uk . We also recommend to follow the advices listed here: here. Please read this too if you want to make an article about this.

The vuln is still active!

User host and password

mysquser telegraph.co.uk

version,database and user

+

/etc/passwd content (load_file is on)

version-database-user-etc_password2

First name, last name, email, address, date of birth + password (plain text)

all_userdata11

Another table from db:

First name, last name, address password (plain text)

all_userdata22

DB5_data – main db of the website

schema_name

Submitted by unu

Related Posts

19 Responses to “Telegraph.co.uk hacked – when will they learn?”

  1. David Says:

    I already noticed with my own experience some big companies discarding huge security leaks. Well…

  2. Blackie Says:

    :) )))

  3. virjil Says:

    hhahahahhahahahashahahhahahahahahhahahahhhahahahah: )))))))))))) =)))))))) :) )) =))))

  4. fanfan Says:

    lol hahahahahahhahaha :) ))))))))))))))))))))))))

  5. virjil Says:

    virjil

  6. Blackie Says:

    Tabela cu emailurile pt newsletter nu se afla pe acolo(din ce cautai eu), so ghinion spammeri!
    In schimb, se gasesc foarte multe databases-uri, iar cineva rauvoitor ar putea face mult rau.
    Sa speram ca “specialistii” englezi vor remedia rapid vulnerabilitatea.

  7. Jay Says:

    I know the company who produced this lousy website… they well deserve these problems because of their attitude and development habits/management.

  8. Jay Says:

    I suspect that the data you see is not related to Telegraph itself. It may well be that this domain (stats.telegraph.co.uk) is provided by the company I mentioned earlier but the data in the database relates to other projects of that company rather than Telegraph itself.

  9. 2fingers Says:

    It’s the main database of the Telepgraph according to unu. They have everything in there, probably beta (or other) projects too.

  10. Jay Says:

    Hmm I doubt it however I do not argue it cannot be true. The DB names you’ve listed are clients of the company responsible for the vulnerability. Seems to me that this subdomain provides some iframes for Telegraph along with other websites (hence those other DB databases listed) for the company responsible.
    If you contacted Telegraph, would you mind describing what was their response this time?

  11. keane Says:

    Hi Jay,

    I came across this thread and would like to discuss this with you in a bit more detail if you dont mind?

    I work with both the Telegraph and the 3d party company i beleive you are referring. It would be good to understand the issue and see if there is anything i/we can do to resolve the issue.

    Please contact me on dkhendy509@hotmail.co.uk

    Thanks

  12. Pyro Says:

    Urmeaza a 3 oara? (cica e cu noroc atunci) =))

  13. Alexu` Says:

    Good job unu and HB ! :)

  14. Jay Says:

    Can you confirm they’ve fixed the problem now? :) And I stand behind my claim that it doesn’t contain Telegraph’s own user data.

  15. Blackie Says:

    Se pare ca au rezolvat problema.
    Unu, asteptam a treia buba.

  16. unu Says:

    Jay…1. If you read the article carefully, you noticed that I did mention I wrote them emails but to no avail. I asked to speak to someone in their IT dept. ( I even wrote to Paul Cheesbrough) and still got no answer
    2. In vain you still hope that the injection didnt give full access to users data on the site. I have to dissapoint you. DB5_data it the main data base. The one that has all the data of the users. Accessing this DB you can access the clients. If you look closely, you can see in the the first article on hackersblog http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/) that DB5_data is the name of one of those databases. That same database is circled in the image in this article.If that database belonged to the Telegraph back then, I dont see how it could belong to someone else now. Especially since we talk about a subdomain of telegraph.co.uk.

  17. keane Says:

    Hi Guys

    It seems you guys have been looking further into this. I am unsure at what capacity however i am now in contact with the Telegraph so would be greatful to have your insight into the situation and maybe look to recruit your expertise to resolve it, as they are keen to sort this asap.

    Please do contact me dkhendy509@hotmail.co.uk

    Thanks,
    Daniel

  18. Эпидемия уязвимостей на британских сайтах - Персональный блог Вороны Богдана Says:

    [...] одновременно с отчетом XSSed сайт HackersBlog опубликовал детали уязвимости к SQL-инъекциям, которую команда его хакеров обнаружила [...]

  19. David Says:

    Did they reply already??

Leave a Reply

Download Muzica Filme Porno