FINANCIAL CHRONICLE™
Dear Reader,

Registration with the Sri Lanka FINANCIAL CHRONICLE™️ would enable you to enjoy an array of other services such as Member Rankings, User Groups, Own Posts & Profile, Exclusive Research, Live Chat Box etc..

All information contained in this forum is subject to Disclaimer Notice published.


Thank You
FINANCIAL CHRONICLE™️
www.srilankachronicle.com


Join the forum, it's quick and easy

FINANCIAL CHRONICLE™
Dear Reader,

Registration with the Sri Lanka FINANCIAL CHRONICLE™️ would enable you to enjoy an array of other services such as Member Rankings, User Groups, Own Posts & Profile, Exclusive Research, Live Chat Box etc..

All information contained in this forum is subject to Disclaimer Notice published.


Thank You
FINANCIAL CHRONICLE™️
www.srilankachronicle.com
FINANCIAL CHRONICLE™
Would you like to react to this message? Create an account in a few clicks or log in to continue.
FINANCIAL CHRONICLE™

Encyclopedia of Latest news, reviews, discussions and analysis of stock market and investment opportunities in Sri Lanka

Click Link to get instant AI answers to all business queries.
Click Link to find latest Economic Outlook of Sri Lanka
Click Link to view latest Research and Analysis of the key Sectors and Industries of Sri Lanka
Worried about Paying Taxes? Click Link to find answers to all your Tax related matters
Do you have a legal issues? Find instant answers to all Sri Lanka Legal queries. Click Link
Latest images

Latest topics

» SINS - the Tailwind effects of a crisis hit Economy
by Equity Win Today at 7:37 pm

» TAFL is the most undervalued & highly potential counter in the Poultry Sector
by atdeane Today at 7:09 pm

» Sri Lanka: Policy Challenge Addressing Poverty Vulnerability as the Economy Recovers
by God Father Today at 5:37 pm

» Sri Lanka: Country Information Report
by God Father Today at 5:22 pm

» Sri Lanka polls could risk economic recovery
by God Father Today at 5:12 pm

» AGSTAR PLC (AGST.N0000)
by ResearchMan Today at 12:21 pm

» Browns becomes world’s biggest tea exporter in deal with LIPTON
by sureshot Yesterday at 9:51 pm

» Colombo Stock Market: Over Valued against USD!
by ResearchMan Yesterday at 12:49 pm

» COCR IN TROUBLE?
by D.G.Dayaratne Mon May 06, 2024 9:31 am

» EXPO.N - Expo Lanka Holdings De-Listing
by eradula Tue Apr 30, 2024 3:21 pm

» Maharaja advise - April 2024
by celtic tiger Tue Apr 30, 2024 12:01 am

» Srilanka's Access Engineering PLC think and Win
by Dasun Maduwantha Mon Apr 29, 2024 11:40 pm

» PEOPLE'S INSURANCE PLC (PINS.N0000)
by ErangaDS Fri Apr 26, 2024 10:24 am

» UNION ASSURANCE PLC (UAL.N0000)
by ErangaDS Fri Apr 26, 2024 10:22 am

» ‘Port City Colombo makes progress in attracting key investments’
by samaritan Thu Apr 25, 2024 9:26 am

» Mahaweli Reach Hotels (MRH.N)
by SL-INVESTOR Wed Apr 24, 2024 11:25 pm

» THE KANDY HOTELS COMPANY (1983) PLC (KHC.N0000)
by SL-INVESTOR Wed Apr 24, 2024 11:23 pm

» ACCESS ENGINEERING PLC (AEL) Will pass IPO Price of Rs 25 ?????
by ddrperera Wed Apr 24, 2024 9:09 pm

» LANKA CREDIT AND BUSINESS FINANCE PLC (LCBF.N0000)
by Beyondsenses Wed Apr 24, 2024 10:40 am

» FIRST CAPITAL HOLDINGS PLC (CFVF.N0000)
by Beyondsenses Wed Apr 24, 2024 10:38 am

» LOLC FINANCE PLC (LOFC.N0000)
by Beyondsenses Wed Apr 24, 2024 10:20 am

» SRI LANKA TELECOM PLC (SLTL.N0000)
by sureshot Wed Apr 24, 2024 8:37 am

» Sri Lanka confident of speedy debt resolution as positive economic reforms echoes at IMF/WB meetings
by samaritan Mon Apr 22, 2024 9:28 am

» Construction Sector Boom with Purchasing manager's indices
by rukshan1234 Thu Apr 18, 2024 11:24 pm

» Asha Securities and Asia Securities Target AEL (Access Enginnering PLC )
by Anushka Perz Wed Apr 17, 2024 10:30 pm

LISTED COMPANIES

Submit Post
ශ්‍රී ලංකා මූල්‍ය වංශකථාව - සිංහල
Submit Post


CONATCT US


Send your suggestions and comments

* - required fields

Read FINANCIAL CHRONICLE™ Disclaimer



EXPERT CHRONICLE™

ECONOMIC CHRONICLE

GROSS DOMESTIC PRODUCT (GDP)



CHRONICLE™ YouTube

Disclaimer
FINANCIAL CHRONICLE™ Disclaimer

The information contained in this FINANCIAL CHRONICLE™ have been submitted by third parties directly without any verification by us. The information available in this forum is not researched or purported to be complete description of the subject matter referred to herein. We do not under any circumstances whatsoever guarantee the accuracy and completeness information contained herein. FINANCIAL CHRONICLE™ its blogs, forums, domains, subdomains and/or its affiliates and/or its web masters, administrators or moderators shall not in any way be responsible or liable for loss or damage which any person or party may sustain or incur by relying on the contents of this report and acting directly or indirectly in any manner whatsoever. Trading or investing in stocks & commodities is a high risk activity. Any action you choose to take in the markets is totally your own responsibility, FINANCIAL CHRONICLE™ blogs, forums, domains, subdomains and/or its affiliates and/or its web masters, administrators or moderators shall not be liable for any, direct or indirect, consequential or incidental damages or loss arising out of the use of this information. The information on this website is neither an offer to sell nor solicitation to buy any of the securities mentioned herein. The writers may or may not be trading in the securities mentioned.

Further the writers and users shall not induce or attempt to induce another person to trade in securities using this platform (a) by making or publishing any statement or by making any forecast that he knows to be misleading, false or deceptive; (b) by any dishonest concealment of material facts; (c) by the reckless making or publishing, dishonestly or otherwise of any statement or forecast that is misleading, false or deceptive; or (d) by recording or storing in, or by means of, any mechanical, electronic or other device, information that he knows to be false or misleading in a material particular. Any action writers and users take in respect of (a),(b),(c) and (d) above shall be their own responsibility, FINANCIAL CHRONICLE™ its blogs, forums, domains, subdomains and/or its affiliates and/or its web masters, administrators or moderators shall not be liable for any, direct or indirect, consequential or incidental violation of securities laws of any country, damages or loss arising out of the use of this information.


AI Live Chat

You are not connected. Please login or register

Commercial Bank of Ceylon Hacked?

Go down  Message [Page 1 of 1]

1Commercial Bank of Ceylon Hacked? Empty Commercial Bank of Ceylon Hacked? Mon May 16, 2016 10:44 am

Shiva911


Equity Analytic
Equity Analytic




  •  Twitter

  •  Facebook

  •  LinkedIn

  •  Credit Eligible

  •  Get Permission



Commercial Bank of Ceylon Hacked? Commercial-bank-ceylon-apparently-hacked-showcase_image-6-a-9103
Commercial Bank of Ceylon, based in Colombo, Sri Lanka, has apparently been hacked, with its data posted online May 12 by the Bozkurtlar hacking group, which has also posted seven other data dumps from banks in the Middle East and Asia since April 26.
See Also: Unite & Disrupt: Mitigate Attacks by Uniting Security Operations
The group, believed to have Turkish ties, released data from five South Asian banks on May 10. It also dumped data online from UAE-based InvestBank on May 7 and data from Qatar National Bank on April 26.
Commercial Bank of Ceylon did not immediately reply to Information Security Media Group's request for comment. But a researcher analyzing the data involved, who asked to remain anonymous, says that the hacked data appears to be genuine.
The files from the latest disclosure appear to contain the entire contents of the corporate website of the Commercial Bank of Ceylon, the researcher says, explaining that no customer data or payment card information was apparently exposed in the incident. The dump appears to have occurred in November of last year, which suggests the compromise took place before that, according to the researcher.
As with the other bank data compromises in the region in recent weeks, the attackers notified ISMG and others via Twitter about the file dump, which apparently was relatively quickly taken offline. Commercial Bank of Ceylon's web services at www.combank.net appear to have been taken offline briefly post the disclosure. The website was functional on May 13.

Data Dump Contents

The dump contains 158,276 files in 22,901 folders and is about 6.97 GB uncompressed. The compromised data contains annual reports, application forms, bank financial statements, .PHP files, web development backups and other files needed for the functioning of the bank's corporate front-end web infrastructure, the researcher tells ISMG.
Commercial Bank of Ceylon Hacked? Sawahir-enterprises_10-28-2015-02-15-04
A sample file from the Commercial Bank of Ceylon dump

The attackers appear to have compromised the bank's systems using a SQL injection attack and uploading a Web Shell - a script that enables remote administration - onto the bank's PHP server, the researcher says. He bases this conclusion on the presence of artifacts from the hack in the data dump, including logs and files the indicate where the SQL injection was used and where the Shell was injected.
Bozkurtlar attackers had posted on Twitter, on a handle which has since been taken offline, that they would continue posting data from Asian and Middle Eastern banks, after the first dump of data from QNB (see: Qatar National Bank Suffers Massive Breach).
Many have been questioning the motives of the Bozkurtlar attackers, given the lack of any hacktivist message, announcement or reports of attempts at blackmail. However, analysis has revealed some common patterns and methods in the attacks, the researcher claims.

The Havij Connection

Several of the attacks appear to have involved an Iranian automated SQL injection tool called Havij 1.18 Pro, as per logs found in the leaked data, which includes the tool's payload, the researcher says. The attackers seem to have been successful in compromising Commercial Bank of Ceylon's web-facing front-end using a combination of this tool and Web Shell upload, but were unable to pivot onto the internal network as a result of relatively strong internal security controls.
Commercial Bank of Ceylon Hacked? Combank-Havij
Havij log from Commercial Bank of Ceylon compromise dump

In addition to the Commercial Bank of Ceylon attack, the Havij advanced SQL injection tool was apparently used in the attacks against Kathmandu, Nepal-based Sanima Bank and Dhaka, Bangladesh-based Dutch Bangla Bank, the researcher confirms. The Qatar National Bank breach also involved an SQL injection and Web Shell combination, but it remains unclear if it involved the Havij tool (see: Dissecting a Hacktivist Attack).
The automated SQL injection tool has gained a lot of popularity with the cybercriminals and white hat researchers alike, because of the ease with which SQL injection attacks could be launched - literally at a click of a button - greatly reducing the effort and expertise required to launch such attacks.
Havij was written by Farshad Shahbazi, a security researcher at Iranian security firm the ITSecTeam, who also goes by hacker moniker r3dm0v3. The tool was released in July 2009 and the ITSecTeam started offering a free version in 2010, making the tool popular with hackers worldwide - regardless of the hat they are wearing, notes a blog on the Havij. While Havij was discontinued at the end of 2014, it is still freely available for download online.
ITSecTeam was in the news earler this year when a grand jury in New York indicted seven Iranian nationals who were allegedly working on behalf of the Iranian government - some of whom were employees of ITSecTeam - for their alleged involvement in conspiracies to conduct a coordinated campaign of distributed denial-of-service attacks against U.S. banks and others from 2011 through 2013 (see: 7 Iranians Indicted for DDoS Attacks Against U.S. Banks).

Back to top  Message [Page 1 of 1]

Permissions in this forum:
You cannot reply to topics in this forum