According to PeopleMediaVoice, Nation Web Portal of Myanmar ( Yatanarpon Web Portal) is being hacked by a hacker group named themselves “Humpty Dumpty”, defaced home page at around 12:30 AM local time yersterday, 13/11/2010.

At the same day, they hacked another gov news agency site The Mirror Online News Paper (KyayMon) http://www.kyaymon.info/.

Now, Yatanarpon Portal is currently under maintenance, and they are trying to discover their site!

Wat i wana talk is, they are not care security in their web site, We informed XSS, SQL Injection, Bypass Login from Myanmar Web Portal last month http://www.planetcreator.net/2010/10/critical-sql-injection-in-yatanarpon-web-portal/ . I know they fixed some vul but not at all.

Now, security vulnerability are still existing in some sub domain of Yatnarpon Web Portal, such as http://job.yatnarpon.com.mm and so on…

If you want to see detail of this vulnerability Click Here (Note :- Registered Member Only- If you are not PlanetCreator.Net Member Sign up Here)

We hope that your security staff will look into this issue and fix it as soon as possible.

Explore More

Timing Attacks with HTML5

HTML 5 and related technologies bring a whole slew of new features to web browsers, some of which can be a threat to security and privacy. This paper describes a

Yet another simple Google Docs hack

A simple hack that allow you to edit read only Google docs is explained here http://googlesystem.blogspot.com/2009/01/copy-google-documents-to-your-account.html It works and all you need is to hack the url a bit like

Detecting and Preventing Social Engineering and other Hacking Processes

Social engineering attacks are growing fast, and today majority of attackers use social engineering techniques to infiltrate into a victim’s network. It is very difficult for a technician to identify