Copyright Policy Privacy Policy Contact Us Instagram Facebook
Top Rated Posts ....
Cricketer Imad Wasim confirms separation from his wife Sania Ishfaq Cricketer Imad Wasim confirms separation from his wife Sania Ishfaq Engineer Muhammad Ali Mirza’s First Interview with Irshad Bhatti After 103 Days in Jail Engineer Muhammad Ali Mirza’s First Interview with Irshad Bhatti After 103 Days in Jail President Asif Zardari criticizes Imran Khan in his speech President Asif Zardari criticizes Imran Khan in his speech Wakalat Kar Ray Ho Ya Badmashi? Exchange of harsh words b/w Rajab Butt's lawyer Mian Ali Ashfaq and the other lawyer Wakalat Kar Ray Ho Ya Badmashi? Exchange of harsh words b/w Rajab Butt's lawyer Mian Ali Ashfaq and the other lawyer CM KP Suhail Afridi pays visit to Shah Mahmood Qureshi’s house, meets his family CM KP Suhail Afridi pays visit to Shah Mahmood Qureshi’s house, meets his family Famous YouTuber Rajab Butt physically assaulted at sessions court in Karachi Famous YouTuber Rajab Butt physically assaulted at sessions court in Karachi

Habib Bank Website Hacked - Database Leaked Out Online - Only in 17 Minutes

Posted By: Abdul Ahad, July 11, 2013 | 06:35:13



Official website of Habib Bank Limited – the largest bank of Pakistan – yesterday got hacked, when a hacker called Xploiter hacked the website and leaked the databases of the website and posted credentials online.

Hacker said that it took him just 17 minutes to hack into the website.

The section that handles the online banking or Internet Banking of Habib Banking was not impacted with the hack. No customer data was compromised or leaked during the incident.

14 databases belonging to the official website of Habib Bank – relating to the generic information available on the website – were posted online with the names and tables.

While explaining the flaw in bank’s website, the hacker posted following in the leaked file:

Link:- www.HBL.Com > Error Based SQLi

File:- search_results_carbranch.php

Vulnerable Perameter:- branch_Alphabet

Method:- GET > MySQL Union Query

A list of login credentials were also posted in the online document, containing username, plain password and emails. Its strange that a bank stores password in plain language, revealing the security level of the bank.

Leaked information can be access here: https://pastebin.com/SMRPVYB6

Luckily, the Internet Banking section or customers’ data was not compromised, but considering the hack, it is high-time for the banks to increase their security levels.

Source: ProPakistani.pk





Advertisement





Popular Posts Follow Us on Social Media

Join Whatsapp Channel Follow Us on Twitter Follow Us on Instagram Follow Us on Facebook


Comments...