Sajha.com Archives
Nepali web sites hacked

   > Date: Sun, 21 Oct 2001 22:02:23 -0700 22-Oct-01 ashu
     Hackers use computers with ID: (makalu.m 22-Oct-01 GP
       Is this kind of hacking a routine thing 22-Oct-01 oohi_ashu
         This kind of attacks are made possible b 23-Oct-01 Paakhe
           Heard that a nepali guy was arrested on 01-Nov-01 Ukyab


Username Post
ashu Posted on 22-Oct-01 01:02 AM

> Date: Sun, 21 Oct 2001 22:02:23 -0700 (PDT)
> Subject: nepalisites

> On a separate note, most of the websites hosted by
> World Llink was hacked last night by a nepali hacker group
> for about 10 hours. The sites included Sagarmatha
> radio site, British Council Nepal, Music Nepal,
> Wlinkonline.com, NPC.gov.np (national planning
> commsion).
>
> Go to

http://groups.yahoo.com/group/ysgnet/messages

> and look at the messages there.






http://groups.yahoo.com/group/ysgnet/messages
GP Posted on 22-Oct-01 01:26 AM

Hackers use computers with ID: (makalu.mos.com.np) (202.52.255.1).
What about MOS.COM.np ? Is it safe? Hackers having any
connection with MOS.COM.np?


From antisecure2001@y... Sun Oct 21 06:34:04 2001
Return-Path:
X-Sender: antisecure2001@y...
X-Apparently-To: ysgnet@yahoogroups.com
Received: (EGP: mail-8_0_0_1); 21 Oct 2001 13:34:03 -0000
Received: (qmail 97055 invoked from network); 21 Oct 2001 13:34:03 -0000
Received: from unknown (10.1.10.26)
by l8.egroups.com with QMQP; 21 Oct 2001 13:34:03 -0000
Received: from unknown (HELO makalu.mos.com.np) (202.52.255.1)
by mta1 with SMTP; 21 Oct 2001 13:34:01 -0000
Received: from chulu.mos.com.np (root@c... [202.52.255.6])
by makalu.mos.com.np (8.11.6/8.11.2) with ESMTP id f9LDXtb23966
for ; Sun, 21 Oct 2001 19:18:55 +0545 (NPT)
Received: from server (ptn-5300-88.mos.com.np [202.52.252.88])
by chulu.mos.com.np (8.11.6/8.11.2) with SMTP id f9LDXsj21884
for ; Sun, 21 Oct 2001 19:18:54 +0545 (NPT)
Message-ID: <000a01c15a34$98e77770$0100cdc3@s...>
To:
Subject: major ATTACK completed!!!
Date: Sun, 21 Oct 2001 19:15:42 +0545
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
From: "sinetheta"
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
oohi_ashu Posted on 22-Oct-01 02:53 PM

Is this kind of hacking a routine thing or is this something we should all be
concerned about?

These guys seem mighty proud of their achievements.

oohi
ashu
ktm,nepal
Paakhe Posted on 23-Oct-01 04:32 PM

This kind of attacks are made possible by negligence of site administrator. One of my friend, who works for one of the ISP in Nepal, said to me one day that he got an anonymous email from Australia saying that his system is vulnerable. But he didn't took any precautions. After some days, he found that his password files are deleted.

Site administrator in Nepali ISPs donot take comprehensive security precautions. First, they shouldnot let many unwanted ports open to outside world. Second, they should continuously monitor whether any IP address is scanning its ports. There are lots of other securiyt measure to take before making site accessible to outside world. In US, if someone is found scanning port, s/he may be prosecuted. But Nepal has not IT law. So, it is easier to do that in Nepal.

Dedicated people with Internet access and compute knowledge can do these kind of mischiefs. And after such incident, we should expect more of this in near future also.
Ukyab Posted on 01-Nov-01 12:26 PM

Heard that a nepali guy was arrested on charges of hacking (the incident of nepali websites being hacked 2 weeks ago) by Nepali police. Does anyone know more about this?

BTW, they have a press release on this site.

http://www.ysgnet.com/hn/