Google News fooled and spammed by a hacked Hyderabad govt. website


The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSS) website, ‘hyderabadwater.gov.in.’ [File]

The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSS) website, ‘hyderabadwater.gov.in.’ [File]
| Photo Credit: Google News

Google News algorithm was fooled and spammed on Friday (November 8, 2024) by a hacked Hyderabad government website. The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSS) website, ‘hyderabadwater.gov.in.’ The website is used by Hyderabad residents to pay their water bills online.

It is unclear when the hack itself happened, but promotional links on betting, online rummy, and casinos began trending up on Google News under the latest news tab in the technology section earlier today. With an exception of one sub-section that highlighted Garena Free Fire MAX redeem codes, most other links were from HMWSS, promoting gambling. The links were redirecting users to an online betting platform, betwww20.com.

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code
| Photo Credit:
Google News

The hack reveals the vulnerability in both HMWSS’s website and Google News’s algorithm. While the method of the attack could not be verified, it looks like a Structured Query Language Injection (SQLi) attack — a common website hacking technique.

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code into web forms, URL parameters, or other input fields. This is possible when the website fails to properly validate or sanitise user input before using it in SQL queries.

The spam links were redirecting users to an online betting platform, betwww20.com.

The spam links were redirecting users to an online betting platform, betwww20.com.
| Photo Credit:
Google News

SQLi can be used to delete or modify information in the database, or to extract sensitive data like usernames, passwords, and credit card details. Attackers could also inject malicious code to further compromise the website or server.

Hackers often use automated tools to scan and attack large numbers of websites. These tools can try different variations of SQL injection payloads on forms, URLs, and other input fields until they find one that works.



Source link

spot_img

More from this stream

Recomended

Here are the big stories from Karnataka today‘Here’ movie review: Join Tom Hanks in this living room at the end of the universeM. Selvarasan receives Kalaignar M. Karunanidhi Semmozhi Tamil AwardComing to Netflix: ‘Vijay 69,’ ‘Meet Me Next Christmas,’ ‘Countdown: Paul vs. Tyson,’ and moreTwo Naxalites killed in encounter with security forces in BijapurNo power in the world can restore Article 370 in J&K: PM ModiOwaisi hails Supreme Court ruling on AMU’s minority statusT.N. CM Stalin inaugurates over 700 new classrooms in 141 State-run schoolsJharkhand Assembly polls 2024: AJSU Party releases manifesto, promises ₹1.21 lakh annually to poor familiesPolice step up security for forthcoming Assembly session in A.P.Tata Motors Q2 consolidated net profit declines 11% to ₹3,343 crYadadri is Yadagirigutta, again, forthwith! Union Finance Minister Nirmala Sitharaman lists out six points to stress Karnataka is not ignoredPakistan bans entry to parks, zoos as air pollution worsensCentre will firmly put forth its stand before Supreme Court on question of AMU's minority status: BJPपूरे 10 घंटे घर में गूंजेगी भजन की मधुर धुन, ले आएं Blaupunkt का ये तगड़े साउंड वाला Bluetooth Speakerदुनियाभर में बजा Singham Again का डंका, बॉक्स ऑफिस पर मचा तहलका, अंधाधुंध कमाई पर फिल्म ने किया कब्जाRupee falls 5 paise to hit new all-time low of 84.37 against U.S. dollar‘Vijay 69’ movie review: Anupam Kher takes a dip in the channel of mediocritySensex, Nifty fall for 2nd day amid foreign fund exodus, muted corporate earnings