Saturday, March 29, 2014

Hindustan Book Agency – dataBase Dump

Hindustan Book Agency ( http://goo.gl/kEa7ul )
dataBase Dump for hindbook.com :-
Password for zip: whiteHatMrNervous
Summary:
Date First Contacted:February 07, 2014
Reward demanded:USD 5,000
Any Reward Paid:No
Communication Channel:Got No Reply
Vulnerability ListSQL Injection
Infected object:Main website
Retest Infection:Definitely will
Leaked database dump/files:Yes
Received Respect:NA
Received Appreciation for Intimation about Existence of Security Vulnerabilities:NA
Hall of Fame:No
Hindustan Book Agency is a company that publishes books, OfCourse that is evident by the name. But despite the huge profits, they do not spend nor care much about their online security. Hence their data saved online including details of books they publish, Order information, contact details of who they deal with is all published online.

Flight Centre Travel Group – dataBase Dump

Flight Centre Travel Group (Australia based MNC)

dataBase Dump for fcm.travel :-
dataBase Dump for flightcentreassociates.com :-
Password for zip: whiteHatMrNervous(fcm.travel -> awp_users file contains encrypted passwords for 165 users including admin + email, phone etc. Other tables include email conversation between their customer/staff been carried online via website; flightcentreassociates.com -> shopdetails, tours contain confidential information valuable for competitors)
Vulnerability Details (Important): Flight Centre Travel Group uses ‘Parallels Plesk Panel’ for online login to server which is vulnerable to SQL Injection, Cross site scripting (XSS), Denial of Service, Remote Code Execution, Authentication Bypass, etc. I believe Parallels Plesk Panel current updated version might not be vulnerable to SQL Injection exploited here, but Flight Centre Travel Group’s IT Team had not updated theirs to the latest bug free version. It is because of this that I was able to exploit SQL Injection vulnerability to get access to their database. And then I asked them if the would pay a bug bounty for what I found. They didn’t reply, the very next day I published their leaked database online. Flight Centre Travel Group has not yet been able to catch me for this leak, now as they know Parallels Plesk Panel was at fault and is responsible for their database leak, they might want to take them to court.
Source (Parallels Plesk Panel is vulnerable or has serious security flaws):
http://www.cvedetails.com/product/21684/Parallels-Parallels-Plesk-Panel.html?vendor_id=5403
Being a whiteHat, I would strongly recommend Flight Centre Travel Group to upgrade Parallels Plesk Panel on all their domains / sub-domains to the latest version available onhttp://www.parallels.com/products/plesk. Only changing the sub domain for login from admin.fcm.travel or admin2.fcm.travel to any other does not protect you from any attacks. As I get list of all your sub domains using dns-mapping. I saw you removed login page from admin2.fcm.travel & admin.fcm.travel, but that move is no good. Please hire some good professional in your IT team, which do regularly check if the technologies they are using are obsolete or not. Lets hope such attacks do not occur again, lets hope that you will take a lesson from this and will not give me another chance to compromise your security and flee with your data in my bag.
Summary:
Date First Contacted:February 09, 2014
Reward demanded:USD 5,000
Any Reward Paid:No
Communication Channel:No Reply
Vulnerability List :SQL Injection
Infected object:Main domain
Retest Infection:Definitely will(Vulnerability exists as on 12 March 2014)
Leaked database dump/files:Yes
Received Respect:No
Received Appreciation for Intimation about Existence of Security Vulnerabilities:No
Hall of Fame:No
It is really disheartening to see how vulnerable companies under Flight Centre Travel Group (Australia) are.  Our details including our travel plans, contact details, etc are all stored by these Travel companies in their dataBase, which is now leaked only because their security is incompetent.
In Travel & Tourism Industry, Flight Centre Travel Group is a big name, a Multi National Company. They promise their clients that they are using best in class technology to gain confidence. While in reality, this is not the case. In addition to this, their staff also ignores a warning email sent to Flight Centre Travel Group informing them about the flaw in security. Now that they know, no one has yet gathered enough courage to come up and talk to the Pentester, provide him with a reward for finding flaw; and in-turn avoid this ShowUp. And they instead took a more drastic step which Amadeus IT Group, Abacus, Hindustan Book Agency, MatchMeCupid, SalesForce did not, they sent a notice under DMCA (Digital Media Copyright Act) for Copyright Infringement to take down the dataBase files uploaded by the pentester. This aggravated the whole situation and the pentester is now focussed on Flight Centre Travel Group of companies to find flaws in all of them and download their data to later publish it online. So that, next time they and any other company thinks twice before sending a Take Down notice or taking any action of any kind against the Tester.
Now it might just be the time, when the customers of Flight Centre Travel Group will rethink on whether they should continue to deal with this company as they do not actively monitor nor safeguard the security of their dataBase, which contains their client’s private data, contact details, and a lot.
If you are one of their Client or planning to deal with them for your travel plans, or if you even send them queries for travel plan, Please be informed that all the data you share with them will be all out there, published on the Internet. You might then want to file law suits against them if your confidential data is among the data which is leaked.
Flight Centre Travel Group, I will bring you on your knees!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Elizabeth Susan Carter – Photography
Store: http://goo.gl/kEa7ul
Facebook: http://goo.gl/mFei5t
Contact: http://goo.gl/ulA9Lm
About: http://goo.gl/pwPdiq
PortFolio:-

Unit Nexus – Deface

Unit Nexus
Have defaced http://www.unitnexus.com
unitnexus.com
unitnexus.com.wmnr
google_search
Reason of deface: Unit Nexus is a company that cheats job seekers. It takes students from Universities and gives them an offer letter. After which they are asked to pay for a 3 or 6 month industrial training program wherein they will be working on live projects, completing which they will get an assured job. They are not paid and nor they get a job post program completion.

Amadeus

Job seekers beware!
Working in Amadeus, how is it like?
Amadeus says that they have adopted new technology and not using the legacy systems anymore, however the same is a false statement. ‘Your technology partner’ is a line below in their logo below ‘Amadeus’, yet they do not have the security measures in place to find and eliminate security flaws in their own websites (made in Java – jsp & servlets) and the Amadeus Vista Selling Platform (developed using Visual C++).
The truth is, the old developers who made the application have left the company. Hence now the new people / freshers aren’t able to make good changes in the application (as they don’t understand the Architecture, poor people) and hence Amadeus is stuck. The applications like the Vista selling platform does not incorporate any major changes, infact the connectivity bugs are also not fixed as the company is short on resources. Amadeus has failed to retain good employees and hence their market value is depreciating. They feel good that they are top in Travel Industry as there are very less number of development companies focusing on Travel Industry. When Amadeus is compared with other major companies like Google, Facebook, Yahoo, HTC, Apple, Toyota, Honda, etc that excel in their fields as well as hold a position when compared to major companies of other fields.
Stepping outside of Travel Industry, Amadeus stands no where and has no comparison with other giants. Amadeus says they are superior as they compare themselves to Abacus & Galileo who also have a Computer Reservation System in place in Travel Industry.
As the Travel & Tourism industry has got less exposure and the major IT companies have not stepped in. Amadeus running a race alone says ‘I came first’, hiding the fact that its the only one running the race. Phew!
Source: Glassdoor.com + Amadeus IT Group reviews
Employee-Review-Amadeus-RVW3214972Employee-Review-Amadeus-IT-Group-RVW3504076Employee-Review-Amadeus-IT-Group-RVW2875029Employee-Review-Amadeus-IT-Group-RVW2769871Employee-Review-Amadeus-India-RVW3820924

Unit Nexus – Fraud

Unit Nexus (Zirakpur, Punjab, India) is a Fraud company that hires students from Universities and then opens up a surprise package to them. Surprise package is that the students should first complete a 6 month training programme, for which there is a fee and students would get 100% assured job. No job is provided by the end of training. Unit Nexus frames a picture of an IT company having clients and offices abroad. Whereas, the truth is that it does not have any office or clients, rather it is only to promote their Educational unit, to provide training in order to earn money.
Anyway, here is the source code for their website:
Source: http://www.pissedconsumer.com/reviews-by-company/unit-nexus-it/unit-nexus-it-pvt-ltd-is-a-scam-company-it-has-no-clients-ever-and-is-just-a-training-center-in-dres-20130410399561.html
UnitNexus

Amadeus Vista Selling Platform – Penetration Testing

Penetration Testing - Amadeus Vista Selling Platform
Excuse moi, this one is for all Penetration Testers. You all are invited to test Amadeus Vista Selling Platform (don’t go by name, it works on all Windows XP, Vista, 7 etc; but on Windows only).
To proceed, download the file:
Start with ‘Amadeus_Selling_Platform_3.1P120_Installation_Guide.pdf’ file as it has all installation instructions, plus you would need some reverse engineering and the talentno spoon feeding please.
Message to beginners: this one is not for you. Lets hope after a few months we see Zero day security flaws in Amadeus Vista Selling platform on websites like cvedetails, packetstormsecurity, etc.
Then finally we will have a payload which our fellow testers could use using Metasploit. There is a lot of mess that can be done (a lot of potential I mean), hence we need to pull their eye open so they fix flaws.
Useful Tips:
Buffer Overflow & Remote Code Execution will top the list of flaws. FYI, its coded in Visual C++.
IP 82.150.248.28 ncewpo01-ext.dev.amadeus.net
Refer to http://api.dev.amadeus.net for their code structure, in C & messages in XML.
Could also download some PDF’s here: http://www.mirrorupload.net/file/E1KHYPYT/#!pdf.zip
And SEO (search engine optimization) people can download AWStats for api.dev.amadeus.net here: http://www.mirrorupload.net/file/1APAGLFL/#!awstats.pl.zip
In yet another review, a developer not from the best university says that Amadeus is yet using the old technology and has not upgraded:
Hacker review
References:
http://www.sca.amadeus.com/download -> click on category -> user:download, pass:gogetit
amadeusvista.com
certificates.amadeusvista.com/sgwadmin
diagnostic.amadeus.com/travelagencies
webconfig.amadeus.com/diagnostic
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Elizabeth Susan Carter – Photography
Store: http://goo.gl/kEa7ul
Facebook: http://goo.gl/mFei5t
Contact: http://goo.gl/ulA9Lm
About: http://goo.gl/pwPdiq
PortFolio:-

Song – Lips of an Angel

Honey why are you calling me so late?
It’s kinda hard to talk right now
Honey why are you crying, is everything okay?
I gotta whisper cause I can’t be too loud
Well, my girl’s in the next room
Sometimes I wish she was you
I guess we never really moved on
It’s really good to hear your voice saying my name
It sounds so sweet
Coming from the lips of an angel
Hearing those words it makes me weak
And I never wanna say goodbye
But girl you make it hard to be faithful
With the lips of an angel
It’s funny that you’re calling me tonight
And yes I’ve dreamt of you too
And does he know you’re talking to me?
Will it start a fight?
No I don’t think she has a clue
Well my girl’s in the next room
Sometimes I wish she was you
I guess we never really moved on
It’s really good to hear your voice saying my name
It sounds so sweet
Coming from the lips of an angel
Hearing those words it makes me weak
And I never wanna say goodbye
But girl you make it hard to be faithful
With the lips of an angel
It’s really good to hear your voice saying my name
It sounds so sweet
Coming from the lips of an angel
Hearing those words it makes me weak
And I never wanna say goodbye
But girl you make it hard to be faithful
With the lips of an angel
And I never wanna say goodbye
But girl you make it hard to be faithful
With the lips of an angel
Honey why are you calling me so late?