Friday, July 17, 2009

Hacker left trail in legitimate website (gov, edu, my, sg and etc)

When trying to search for under "Index of /" in Google search engine, I accidentally find out that lots of legitimate website were compromised to host files and left trails. Hackers leave their trail in those websites and some of them if belong to education and government domain.


Figure 1


Figure 2


Figure 3


Figure 4: Malaysia government website http://www.customskedah.gov.my


Below are the links suspected were compromised to host malicious files.

SG Domains

http://zhikai.shooting-stars.sg/phpfg/forms/voipbuster-2009-username-password.html
http://lovebydesign.com.sg/admin/backups/intergraph-plant-design-system-8-0-password.html
http://iloveyou.sg/memories/data/password-partyhardcore.html
http://shop.noble.sg/downloader/pearlib/download/Mage_Downloader-1.2.1/downloader/js/WP/ugas-password.html
http://eyera.com.sg/catalog/images/of-myspace-password.html
http://lovebydesign.com.sg/admin/backups/password-rising_tied.rar.html
http://eyera.com.sg/catalog/images/ghettogaggers-password.html
http://sunlink.com.sg/intra/include/altiverb-password.html
http://herbalworks.com.sg/media/content/thumb/pandora-sims-password.html

MY Domains
http://customskedah.gov.my/bkh/administrator/backups/keygen-de-msn-password-finder-v.2.0.html
http://www.tunhabab.edu.my/v2//components/com_pollxt/password-ishotmyself-2009.html
http://www.giacomo.com.my/userfile/password-kinder-para-msn.html
http://mbm.com.my/catalog/intel/images/password-rapidshare.html
http://landasan.com.my/onlinestore/sites/all/modules/WP/password-recovery-radmin.html
http://thetasp.com.my/cms/content/gt/msn-password-local-cracker-torrent.html
http://pasadana.com.my/images/cms/wpThumbnails/rubbervita-password.html
http://webpresence.com.my/joomla2/administrator/backups/xtcs-password.html
http://investor.net.my/PDF/http-www-nicolegraves-com-password.html
http://teochew.net.my/forum/images/avatars/conquer-password.html
http://ikhlas.com.my/admin/data/rcon-password-hack.html
http://thedesignstudio.com.my/images/dooza-password.html
http://dsi.com.my/v1ws/components/com_shell/ppb-password.html
http://www.skshas.my/v1/templates/eplusv2.skin/images/teen-gfs-password.html
http://riverbankacademy.com.my/data/falconstudios.com-free-password.html
http://flexxi.com.my/languages/redtube-password-username.html
http://thetasp.com.my/cms/content/gt/folder-password-expert-serial.html
http://investor.net.my/PDF/kryztalred-password.html
http://landasan.com.my/onlinestore/sites/all/modules/WP/als-scan-password.html
http://www.bidadari.com.my/wp-content/uploads/2008/03/michelle-trachtenberg.jpg&imgrefurl=http://www.bidadari.com.my/masalapornmovies.com-username-&-password.html
http://www.proactiv.com.my/wordpress/wordpress/mr-skin-password-hacks.html
http://www.tunhabab.edu.my/v2//components/com_pollxt/free-password-for-assparade.html
http://mbm.com.my/catalog/intel/images/40320543-password.html
http://adg.my/desaparkcity/wearelittlestars-site-password.html
http://chakri.com.my/e-zine/WP/groped-asians-password.html
http://win.mpcs.com.my/tmp/password-celebmoviearchive.html
http://howabout.my/wp-content/uploads/password-login-x.com.html

IN Domains
http://graycells.in/demo/awortinkos/all/album2/password-index-porn.html
http://www.nitte.ac.in/admin/css/convent-rar-password.html
http://crb.co.in/demo/files/forum-downloadexcel-password-recovery-master.html
http://coffeecreek.co.in/images/torturesru-password.html
http://graycells.in/demo/awortinkos/all/album2/belami-password-hack.html
http://eastcoastaudios.in/ecv/getid3/download-habbo-sg-password-hack.html
http://truevision.co.in/home/admin/images/graphs/nokia-series-40-theme-studio-cracks-password.html
http://connect2mayank.in/cache/redclouds.com-password.html
http://malayattoorkurisumudy.in/admin/htmls/mr-skin-login-and-password.html
http://adsplanet.in/adpics/twisted-metal-ii-password.html
http://stonecastle.in/images/image/freeware-Quicken-password-recovery-forum.html
http://jks.net.in/discussionforum/images/avatars/gallery/free-password-copart.html
http://re-feel.in/sugar/ModuleInstall/PackageManager/metadata/free-sexkey-password.html
http://lovebyte.co.in/lovebyte/userimages/mikrotik-os-password-how-to.html
http://icba.in/act-rules/wp-content/uploads/domkarin-password.html
http://rabs.in/blog/hydra-password-txt.html
http://xcelcom.in/joomla/language/password-recovery-nzb.html
http://loc.net.in/images/wpThumbnails/active-speed-username-and-password-crack.html
http://poweryourweb.in/joom/administrator/backups/abby-part1-password.html

0 comments: