FINANCIAL CHRONICLE™
Dear Reader,

Registration with the Sri Lanka FINANCIAL CHRONICLE™️ would enable you to enjoy an array of other services such as Member Rankings, User Groups, Own Posts & Profile, Exclusive Research, Live Chat Box etc..

All information contained in this forum is subject to Disclaimer Notice published.


Thank You
FINANCIAL CHRONICLE™️
www.srilankachronicle.com


Join the forum, it's quick and easy

FINANCIAL CHRONICLE™
Dear Reader,

Registration with the Sri Lanka FINANCIAL CHRONICLE™️ would enable you to enjoy an array of other services such as Member Rankings, User Groups, Own Posts & Profile, Exclusive Research, Live Chat Box etc..

All information contained in this forum is subject to Disclaimer Notice published.


Thank You
FINANCIAL CHRONICLE™️
www.srilankachronicle.com
FINANCIAL CHRONICLE™
Would you like to react to this message? Create an account in a few clicks or log in to continue.
FINANCIAL CHRONICLE™

Encyclopedia of Latest news, reviews, discussions and analysis of stock market and investment opportunities in Sri Lanka

Click Link to get instant AI answers to all business queries.
Click Link to find latest Economic Outlook of Sri Lanka
Click Link to view latest Research and Analysis of the key Sectors and Industries of Sri Lanka
Worried about Paying Taxes? Click Link to find answers to all your Tax related matters
Do you have a legal issues? Find instant answers to all Sri Lanka Legal queries. Click Link
Latest images

Latest topics

» Prepare to be blown away..
by cpriya Today at 1:05 am

» Hotel Sigiriya (HSIG) most undervalued & huge profit making Hotel
by LAMDA Sat Nov 16, 2024 11:38 pm

» ‘Buy the Rumour, Sell the News’
by God Father Sat Nov 16, 2024 12:00 pm

» Asian stocks drift higher amid rate cut speculation; Japan lags
by Rare Sat Nov 16, 2024 9:56 am

» Oil prices fall further
by Rare Sat Nov 16, 2024 9:40 am

» Post-election winners.
by Rare Sat Nov 16, 2024 9:36 am

» CSE to turn bullish after November 14 poll
by Rare Sat Nov 16, 2024 9:30 am

» Bullish about a sustainable turnaround - CSE Chairman
by Rare Sat Nov 16, 2024 9:25 am

» Plantation Companies
by Rare Sat Nov 16, 2024 9:19 am

» COMMERCIAL BANK OF CEYLON PLC (COMB.N0000)
by EPS Thu Nov 14, 2024 10:31 pm

» People's leasing VS Singer Finance IPO Analysis
by ddrperera Wed Nov 13, 2024 8:18 pm

» Insights into LOLC Advanced Technologies
by samaritan Wed Nov 13, 2024 10:41 am

» LOLC Tech's ambitious plans for global expansion
by samaritan Tue Nov 12, 2024 2:06 pm

» PLANTATION SECTOR
by God Father Sun Nov 10, 2024 8:19 pm

» People's leasing company, a hidden gem? (an analysis)
by Nandana Withanage Sun Nov 10, 2024 6:56 pm

» PEOPLE'S LEASING BUYING SIGNAL Target Price 19 ..PLEASE KEEP EYE ON THIS..
by nilantha suranga Sun Nov 10, 2024 9:16 am

» Peoples leasing technically positive Target Price Rs 20
by Shiranli Sun Nov 10, 2024 7:43 am

» Quarterly Research Updates (Sep 2024)
by God Father Sun Nov 10, 2024 7:42 am

» Peoples Leasing....!!! whts the target?
by rajithasahan Sun Nov 10, 2024 7:35 am

» PEOPLE'S LEASING & FINANCE PLC
by mafasmunaseer Sun Nov 10, 2024 12:45 am

» Will garment exports to U.S. be taxed under Trump administration?
by Quibit Sat Nov 09, 2024 4:34 pm

» LOLC Holdings & LOFC shines together in LMD's top 20 by profit for FY 23/24
by samaritan Sat Nov 09, 2024 4:12 pm

» Richard Pieris and Company performs better in the absence of its defamed Chairman Dr Sena Yaddehige.
by God Father Sat Nov 09, 2024 12:07 pm

LISTED COMPANIES

Submit Post
ශ්‍රී ලංකා මූල්‍ය වංශකථාව - සිංහල
Submit Post


CONATCT US


Send your suggestions and comments

* - required fields

Read FINANCIAL CHRONICLE™ Disclaimer



EXPERT CHRONICLE™

ECONOMIC CHRONICLE

GROSS DOMESTIC PRODUCT (GDP)



CHRONICLE™ YouTube


You are not connected. Please login or register

Commercial Bank of Ceylon Hacked?

Go down  Message [Page 1 of 1]

1Commercial Bank of Ceylon Hacked? Empty Commercial Bank of Ceylon Hacked? Mon May 16, 2016 10:44 am

Shiva911


Equity Analytic
Equity Analytic




  •  Twitter

  •  Facebook

  •  LinkedIn

  •  Credit Eligible

  •  Get Permission



Commercial Bank of Ceylon Hacked? Commercial-bank-ceylon-apparently-hacked-showcase_image-6-a-9103
Commercial Bank of Ceylon, based in Colombo, Sri Lanka, has apparently been hacked, with its data posted online May 12 by the Bozkurtlar hacking group, which has also posted seven other data dumps from banks in the Middle East and Asia since April 26.
See Also: Unite & Disrupt: Mitigate Attacks by Uniting Security Operations
The group, believed to have Turkish ties, released data from five South Asian banks on May 10. It also dumped data online from UAE-based InvestBank on May 7 and data from Qatar National Bank on April 26.
Commercial Bank of Ceylon did not immediately reply to Information Security Media Group's request for comment. But a researcher analyzing the data involved, who asked to remain anonymous, says that the hacked data appears to be genuine.
The files from the latest disclosure appear to contain the entire contents of the corporate website of the Commercial Bank of Ceylon, the researcher says, explaining that no customer data or payment card information was apparently exposed in the incident. The dump appears to have occurred in November of last year, which suggests the compromise took place before that, according to the researcher.
As with the other bank data compromises in the region in recent weeks, the attackers notified ISMG and others via Twitter about the file dump, which apparently was relatively quickly taken offline. Commercial Bank of Ceylon's web services at www.combank.net appear to have been taken offline briefly post the disclosure. The website was functional on May 13.

Data Dump Contents

The dump contains 158,276 files in 22,901 folders and is about 6.97 GB uncompressed. The compromised data contains annual reports, application forms, bank financial statements, .PHP files, web development backups and other files needed for the functioning of the bank's corporate front-end web infrastructure, the researcher tells ISMG.
Commercial Bank of Ceylon Hacked? Sawahir-enterprises_10-28-2015-02-15-04
A sample file from the Commercial Bank of Ceylon dump

The attackers appear to have compromised the bank's systems using a SQL injection attack and uploading a Web Shell - a script that enables remote administration - onto the bank's PHP server, the researcher says. He bases this conclusion on the presence of artifacts from the hack in the data dump, including logs and files the indicate where the SQL injection was used and where the Shell was injected.
Bozkurtlar attackers had posted on Twitter, on a handle which has since been taken offline, that they would continue posting data from Asian and Middle Eastern banks, after the first dump of data from QNB (see: Qatar National Bank Suffers Massive Breach).
Many have been questioning the motives of the Bozkurtlar attackers, given the lack of any hacktivist message, announcement or reports of attempts at blackmail. However, analysis has revealed some common patterns and methods in the attacks, the researcher claims.

The Havij Connection

Several of the attacks appear to have involved an Iranian automated SQL injection tool called Havij 1.18 Pro, as per logs found in the leaked data, which includes the tool's payload, the researcher says. The attackers seem to have been successful in compromising Commercial Bank of Ceylon's web-facing front-end using a combination of this tool and Web Shell upload, but were unable to pivot onto the internal network as a result of relatively strong internal security controls.
Commercial Bank of Ceylon Hacked? Combank-Havij
Havij log from Commercial Bank of Ceylon compromise dump

In addition to the Commercial Bank of Ceylon attack, the Havij advanced SQL injection tool was apparently used in the attacks against Kathmandu, Nepal-based Sanima Bank and Dhaka, Bangladesh-based Dutch Bangla Bank, the researcher confirms. The Qatar National Bank breach also involved an SQL injection and Web Shell combination, but it remains unclear if it involved the Havij tool (see: Dissecting a Hacktivist Attack).
The automated SQL injection tool has gained a lot of popularity with the cybercriminals and white hat researchers alike, because of the ease with which SQL injection attacks could be launched - literally at a click of a button - greatly reducing the effort and expertise required to launch such attacks.
Havij was written by Farshad Shahbazi, a security researcher at Iranian security firm the ITSecTeam, who also goes by hacker moniker r3dm0v3. The tool was released in July 2009 and the ITSecTeam started offering a free version in 2010, making the tool popular with hackers worldwide - regardless of the hat they are wearing, notes a blog on the Havij. While Havij was discontinued at the end of 2014, it is still freely available for download online.
ITSecTeam was in the news earler this year when a grand jury in New York indicted seven Iranian nationals who were allegedly working on behalf of the Iranian government - some of whom were employees of ITSecTeam - for their alleged involvement in conspiracies to conduct a coordinated campaign of distributed denial-of-service attacks against U.S. banks and others from 2011 through 2013 (see: 7 Iranians Indicted for DDoS Attacks Against U.S. Banks).

Back to top  Message [Page 1 of 1]

Permissions in this forum:
You cannot reply to topics in this forum