Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 26-04-2008, 11:17 PM   #1 (permalink)
The Devil's Advocate
 
iMav's Avatar
 
Join Date: Mar 2006
Location: Masti Ki Paathshaala
Posts: 7,019
Default ThinkDigit Site Hacked


How can something like this wither away as a post in a thread, this needs a full blown thread of it's own.

Our fellow member rohan_shenoy (who's wedding card is most probably gonna be in php) has found vulnerabilities in ThinkDIgit's site and gained access to the admin panel cool if I were him I would have sent raaabo to shameful misery for 15 days but that's just me, however...

check out his post on his blog:

http://www.w3hobbyist.com/view.php?id=10

and here is the post he made in the blogger's corner of this forum:

http://www.thinkdigit.com/forum/show...&postcount=240

good going bro, what's next?
__________________
"The problem that shows up with the three red lights on the console is a complex interaction with some very complex parts.” - Robbie Bach

http://beingmanan.com
twitter: manan | Last.FM: manan
iMav is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 26-04-2008, 11:19 PM   #2 (permalink)
Human Spambot
 
Cool G5's Avatar
 
Join Date: Aug 2006
Location: Aamchi Mumbai !!!
Posts: 4,227
Default Re: ThinkDigit Site Hacked

Saw his post.
The thinkdigit webmaster is a n00b.
Congrats Rohan_shenoy.
__________________
ShutterTux - Photography, Linux & Life! : http://shuttertux.wordpress.com
Cool G5 is offline  
Old 26-04-2008, 11:25 PM   #3 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: ThinkDigit Site Hacked

Thanks Manan and Gaurav.

Now something more:
Though I managed to hack into the admin section of the website(Screenshots on my blog post), I immediately informed Digit about it(You can check copies of emails too on my blog post).

That is the reason now they have put the admin/ folder under .htaccess protection. If you try to visit http://www.thinkdigit.com/admin/ you will get a basic authentication type of popup which was implemented after i informed them about it.
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 26-04-2008, 11:28 PM   #4 (permalink)
Human Spambot
 
Cool G5's Avatar
 
Join Date: Aug 2006
Location: Aamchi Mumbai !!!
Posts: 4,227
Default Re: ThinkDigit Site Hacked

I visited your blog, but was unable to read the responses of nimish ?& the other which was in .pdf format.
Donno i am unable too view it.
Also I was not able to post comment.
__________________
ShutterTux - Photography, Linux & Life! : http://shuttertux.wordpress.com
Cool G5 is offline  
Old 26-04-2008, 11:31 PM   #5 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Default Re: ThinkDigit Site Hacked

good going, shenoy!
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
praka123 is offline  
Old 26-04-2008, 11:32 PM   #6 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: ThinkDigit Site Hacked

^
Are you browsing with disabled javascript?
The comment form is visible only with javascript.

wait, I will make some modifications that will not need javascript to be enables.
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 26-04-2008, 11:35 PM   #7 (permalink)
Human Spambot
 
Cool G5's Avatar
 
Join Date: Aug 2006
Location: Aamchi Mumbai !!!
Posts: 4,227
Default Re: ThinkDigit Site Hacked

Javascript is already unable. I do get the comment box.
Filled the required details but still unable to comment.
__________________
ShutterTux - Photography, Linux & Life! : http://shuttertux.wordpress.com
Cool G5 is offline  
Old 26-04-2008, 11:38 PM   #8 (permalink)
Banned
 
slugger's Avatar
 
Join Date: May 2004
Location: Baudland
Posts: 2,433
Default Re: ThinkDigit Site Hacked

Really noble of you not to mess up anybody's accounts and report it immediately

while we here go about badmouthing and abusing things that contain i* M.S. or the tux, somebody did something realllllllly useful and note-worthy but chose not to blow his own trumpet

Great going buddy
slugger is offline  
Old 26-04-2008, 11:40 PM   #9 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: ThinkDigit Site Hacked

@Cool G5
right now people are getting this error, but their comment is being inserted into the database.
Quote:
Warning: Cannot modify header information - headers already sent by (output started at /home/mhtcet/public_html/w3hobbyist.com/comments.php:4) in /home/mhtcet/public_html/w3hobbyist.com/admin/config.php on line 12
Ignore this error if you get it. Ur comment will be inserted into the database, but it will be visible only after moderation.

@Slugger
Thanks dude! I actually intruded into their admin CP just by "matka". Just use some exploits and whoa!I could log in
I had not expected that the exploit wud work with this site.
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 26-04-2008, 11:48 PM   #10 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Default Re: ThinkDigit Site Hacked

@Rohan:Yes,I got the same error message ! ofcourse,java script enabled!but I was using firefox3beta5
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
praka123 is offline  
Old 26-04-2008, 11:51 PM   #11 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: ThinkDigit Site Hacked

^Prakash,
Ignore that error, btw ur comment is visible now on the blog.

and yeah, I don't use linux, stuck with ms box
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 26-04-2008, 11:53 PM   #12 (permalink)
Human Spambot
 
Cool G5's Avatar
 
Join Date: Aug 2006
Location: Aamchi Mumbai !!!
Posts: 4,227
Default Re: ThinkDigit Site Hacked

@Rohan - No buddy, I just get that plz check ur email id,ur name etc etc.
Do not get the error you mentioned.
__________________
ShutterTux - Photography, Linux & Life! : http://shuttertux.wordpress.com
Cool G5 is offline  
Old 26-04-2008, 11:54 PM   #13 (permalink)
Banned
 
slugger's Avatar
 
Join Date: May 2004
Location: Baudland
Posts: 2,433
Default Re: ThinkDigit Site Hacked

something wrong with your comment feature
i keep getting this messasge

Quote:
Dear visitor,
Your comment could not be due to one of the following reasons.
The 'name' field can contain only alphabets, numbers and spaces.
The email address is invalid. Email address can contain only alphabets, numbers, underscores, hyphens, dot and the '@' character.
Please go back and correct the errors.

Thank you.
i used slugger as the name and contact[at]shubhspace[dot]co[dot]cc as mail id (put it correctly in the section)
slugger is offline  
Old 27-04-2008, 12:03 AM   #14 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: ThinkDigit Site Hacked

@ Slugger And Cool G5,
enter email in format "johnsmith@ms.com"

There is no need for using [AT] or [DOT]. The email address is NEVER put on the comment page. Only I can see through the backend database.


Also, .co.cc email addresses are not accepted as yet because of the standar email pattern, but I will soon allow that too. For now, if you want to use some fake email address, u can do so.

@Slugger,
Thanks for the compliments
I have received ur comment and it is visible now.

btw I coded the blog script myself-from scratch.
Was tired of standard blog scripts that are susceptible to comment spam
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता

Last edited by victor_rambo; 27-04-2008 at 12:03 AM. Reason: Automerged Doublepost
victor_rambo is offline  
Old 27-04-2008, 12:03 AM   #15 (permalink)
Banned
 
slugger's Avatar
 
Join Date: May 2004
Location: Baudland
Posts: 2,433
Default Re: ThinkDigit Site Hacked

another problem. after i press submit (this time i put .com = fake id)

Quote:
404 Not Found

The server can not find the requested page:
74.86.90.81/view.php?id=10 (port 80)

Please forward this error screen to 74.86.90.81's WebMaster.
slugger is offline  
Old 27-04-2008, 12:04 AM   #16 (permalink)
The Devil's Advocate
 
iMav's Avatar
 
Join Date: Mar 2006
Location: Masti Ki Paathshaala
Posts: 7,019
Default Re: ThinkDigit Site Hacked

i guess it was the wrong time to link to rohan's site
__________________
"The problem that shows up with the three red lights on the console is a complex interaction with some very complex parts.” - Robbie Bach

http://beingmanan.com
twitter: manan | Last.FM: manan
iMav is offline  
Old 27-04-2008, 12:05 AM   #17 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: ThinkDigit Site Hacked

^That is some issue with server, it works perfectly on my localhost, I am aware of that problem and working on that too!
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 27-04-2008, 12:11 AM   #18 (permalink)
Banned
 
slugger's Avatar
 
Join Date: May 2004
Location: Baudland
Posts: 2,433
Default Re: ThinkDigit Site Hacked

LOL!!!!

not even an hour passes and the NEWS will start spreading like wildfire

Indexed on Google
slugger is offline  
Old 27-04-2008, 12:17 AM   #19 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: ThinkDigit Site Hacked

^ The web design firm "Indus Net Technologies" really deserves that kind on negative publicity for the risk they ran with thinkdigit.com website.

If they had been even a *bit* careful, all could be avoided.

Quote:
Originally Posted by iMav View Post
i guess it was the wrong time to link to rohan's site
If u are speaking this because of the error......
then all those errors were unexpected for me too
I had just upgraded few scripts tested them on localhost, they were fine.....but.........
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता

Last edited by victor_rambo; 27-04-2008 at 12:17 AM. Reason: Automerged Doublepost
victor_rambo is offline  
Old 27-04-2008, 12:20 AM   #20 (permalink)
Banned
 
slugger's Avatar
 
Join Date: May 2004
Location: Baudland
Posts: 2,433
Default Re: ThinkDigit Site Hacked

Raaaboseth and the new owners must be aghast now that the News is indexed

what a way to take up ownership of a high-selling tech mag

may actualy have faar reaching effects - credibility, sales all may take a hit (to make up for this they will probably give out some reallllly coool freebies )

the other pblications must be laughing thier guts out by now (or at least with their morning cup tommorow)
slugger is offline  
Old 27-04-2008, 12:27 AM   #21 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: ThinkDigit Site Hacked

^ It was possible to steal personal information of registered users using XSS attack.
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 27-04-2008, 12:56 AM   #22 (permalink)
Google Bot
 
Pathik's Avatar
 
Join Date: Aug 2005
Posts: 9,772
Default Re: ThinkDigit Site Hacked

Do you mean that there was no authentication for the admin panel before? Anyways great going doc!
__________________
My new blog: www.pathikshah.com
Pathik is offline  
Old 27-04-2008, 01:36 AM   #23 (permalink)
Wahahaha~!
 
Faun's Avatar
 
Join Date: Dec 2006
Location: Pune/there
Posts: 7,686
Default Re: ThinkDigit Site Hacked

lol...
__________________
Blog | Flickr | Battlelog
Spoiler:
Asus Z68 V-Pro|i5 2500k|TRUE Black|Ripjaws X|U2311H|N560GTX|D7000|XONAR STX|RE272|RE0|CC51|XE200PRO Walnut| TD II V2| Ultraphile|N5800

Mono
Faun is offline  
Old 27-04-2008, 02:02 AM   #24 (permalink)
die blizzard die! D3?
 
The_Devil_Himself's Avatar
 
Join Date: Aug 2007
Location: Event horizon
Posts: 2,361
Default Re: ThinkDigit Site Hacked

did you find out who is agent001?
__________________
Stealing your women and horses since 1843.
The_Devil_Himself is offline  
Old 27-04-2008, 02:11 AM   #25 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Default Re: ThinkDigit Site Hacked

^Nimish Chandiramani?
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
praka123 is offline  
Old 27-04-2008, 02:18 AM   #26 (permalink)
A LOTR fan
 
x3060's Avatar
 
Join Date: Dec 2007
Posts: 1,173
Default Re: ThinkDigit Site Hacked

he ha ha ha . . really funny to see this . . but yes it was commendable that you did not screw them but immediately notified about it . . well done
__________________
How many kilometers are there from washington Dc to Miami beach?????....;)

unban praka123!!!....
x3060 is offline  
Old 27-04-2008, 03:44 AM   #27 (permalink)
Still Shining!
 
Lucky_star's Avatar
 
Join Date: Nov 2006
Location: Up 'n' above
Posts: 1,174
Default Re: ThinkDigit Site Hacked

Great work!...

Is your site's cms custom made?
__________________
Simplicity is the ultimate Sophistication
HP dv6 6121tx: Core i7 2630 QM | 4GB | AMD 6770M 2GB GDDR5 | 640 GB
Nokia N86 8MP
Lucky_star is offline  
Old 27-04-2008, 08:15 AM   #28 (permalink)
In The Zone
 
rosemolr's Avatar
 
Join Date: Sep 2007
Posts: 201
Default Re: ThinkDigit Site Hacked

glad to hear that thinkdigit is hacked..!
__________________
Extreme Mobile Professional..Ask anything about it..

Provide you all applications in symbian java uiq platforms

**THERE IS NO SPOON***
rosemolr is offline  
Old 27-04-2008, 08:37 AM   #29 (permalink)
Wahahaha~!
 
Faun's Avatar
 
Join Date: Dec 2006
Location: Pune/there
Posts: 7,686
Default Re: ThinkDigit Site Hacked

^^why ?
you hold some personal grudge ?
__________________
Blog | Flickr | Battlelog
Spoiler:
Asus Z68 V-Pro|i5 2500k|TRUE Black|Ripjaws X|U2311H|N560GTX|D7000|XONAR STX|RE272|RE0|CC51|XE200PRO Walnut| TD II V2| Ultraphile|N5800

Mono
Faun is offline  
Old 27-04-2008, 09:46 AM   #30 (permalink)
PhotonAttack
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,285
Default Re: ThinkDigit Site Hacked

haha rohan bro nice find.. I knew you would come up with something like this with all those posts in the feedback thread


_
__________________
In a time of universal deceit, telling the truth is a revolutionary act - George Orwell

|| तमसो मा ज्योतिर्गमय ||
DigitalDude is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Feedback] ThinkDigit.com Web site Raaabo Feedback 563 24-01-2012 08:23 PM
Site got hacked what next? axxo QnA (read only) 12 18-06-2008 11:07 AM
Some (wicked) fun with the new ThinkDigit site :D victor_rambo Chit-Chat 17 20-04-2008 03:15 PM
JMIt hariyana university site hacked :) Desi-Tek.com Chit-Chat 6 09-10-2007 11:43 AM
I think India Today's Site is Hacked patelpk Technology News 8 18-09-2007 12:18 PM

 
Latest Threads
- by chris
- by abhidev
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 05:41 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2