Wednesday, July 10, 2013
HBL- Habib Bank Limited Hacked by Xploiter From PakBugs
14 databases belonging to the HBL bank posted online by the hacker with database names and tables. Error based SQL Injection was found by the hacker on the website with vulnerable file search_results_carbranch.php. The hacker exploited the vulnerability with mysql Union Query method and accessed the databases of the website, according to the leaked document.
This is not the first time Xploiter hacked the banking System, before Soneri Bank was hacked by the same hacker.
A list of login credentials also posted in the document, containing username, plain password and emails. Its really pathetic that Bank stored the passwords in the plain text which shows HBL security level. HBL really needs to take a look at its security to protect it from these kind of attacks.
Attacked Site:
www.HBL.com
The hacker mocked at the HBL website security by saying it took 17 minutes to get into HBL system. Complete note can be found below.
A note left by the hacker on the leaked document:
You must have listen about us in news , blogs , headlines , gov charges etc. etc. What I See, Same Like Soneri Bank , HBL is in Untelanted Hands ! Just 17 minutes and We are Inside HBL's Database lol. Your are just hiring noobs with Degree
Categories : Habib Bank Limited , HBL , HBL Hacked , Pakbugs , Pakistani Hackers , Xploiter
About Author:
Nauman Ashraf is a security researcher, developer and blogger. He is Founder and Chief Editor of The Hackers Post. Follow him on
Twitter
0 Responses to “ HBL- Habib Bank Limited Hacked by Xploiter From PakBugs ”
Post a Comment