Google News fooled and spammed by a hacked Hyderabad govt. website


The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSS) website, ‘hyderabadwater.gov.in.’ [File]

The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSS) website, ‘hyderabadwater.gov.in.’ [File]
| Photo Credit: Google News

Google News algorithm was fooled and spammed on Friday (November 8, 2024) by a hacked Hyderabad government website. The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSS) website, ‘hyderabadwater.gov.in.’ The website is used by Hyderabad residents to pay their water bills online.

It is unclear when the hack itself happened, but promotional links on betting, online rummy, and casinos began trending up on Google News under the latest news tab in the technology section earlier today. With an exception of one sub-section that highlighted Garena Free Fire MAX redeem codes, most other links were from HMWSS, promoting gambling. The links were redirecting users to an online betting platform, betwww20.com.

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code
| Photo Credit:
Google News

The hack reveals the vulnerability in both HMWSS’s website and Google News’s algorithm. While the method of the attack could not be verified, it looks like a Structured Query Language Injection (SQLi) attack — a common website hacking technique.

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code into web forms, URL parameters, or other input fields. This is possible when the website fails to properly validate or sanitise user input before using it in SQL queries.

The spam links were redirecting users to an online betting platform, betwww20.com.

The spam links were redirecting users to an online betting platform, betwww20.com.
| Photo Credit:
Google News

SQLi can be used to delete or modify information in the database, or to extract sensitive data like usernames, passwords, and credit card details. Attackers could also inject malicious code to further compromise the website or server.

Hackers often use automated tools to scan and attack large numbers of websites. These tools can try different variations of SQL injection payloads on forms, URLs, and other input fields until they find one that works.



Source link

spot_img

More from this stream

Recomended

Hombale Films to collaborate with Prabhas in a three-film partnershipJ&K special status resolution: BJP MLAs hold mock Assembly after ruckus continues for third daySony’s PS5 Pro launch in India entangled in telecom spectrum hitchSamosas, cakes meant for Himachal Pradesh CM Sukhu served to his security staff instead; CID probe onZika virus case detected in Gujarat, patient discharged after treatmentSupreme Court agrees to examine whistle-blower audio tapes against Manipur CM Biren SinghThe Moscow message: impressions & outcomes from PM Modi’s Russia VisitTirupati laddu row: Supreme Court dismisses PIL seeking CBI probe into the case‘D55’: Dhanush teams up with ‘Amaran’-maker Rajkumar Periasamy for his next; film goes on floorsस्मार्टफोन से दिन-रात चिपके रहते हैं बच्चे, तुरंत बदल लें ये सेटिंग्स, जानें कम्प्लीट प्रोसेसConcern over safety of food items from Kerala sold in Kodagu3 शादीशुदा मर्दों पर आया था दिल, फिर भी नहीं बसा घर, 49 की उम्र में टॉप हीरो से शादी के लिए तैयार है हीरोइन!CHD Group to lead multi-country delegation to COP29 in AzerbaijanRunway fire breaks out at Sydney Airport after emergency landingCollege student gang-raped in Odisha, six heldPost Bandhavgarh elephant deaths, M.P. to use satellite collars to track elephantsA second International Financial Services Centre should come to Mumbai: Milind DeoraSalman Khan gets another threat; message sent to Mumbai traffic police helplineSupreme Court overrules 1967 verdict, refrains from deciding whether Aligarh Muslim University is a minority institutionIndia, ASEAN collaboration can be crucial in tackling contemporary issues: EAM Jaishankar