Black hat hackers attacks local websites using new Drupal exploit called Drupalgeddon2


By AJ Dumanhug

Multiple local websites were attacked by different black hat hackers on April 21, 2018, leading to the defacement and leakage of sensitive information on some websites.

In this Tuesday, Jan. 31, 2017 photo, a computer screen shows an archived copy of the Twitter feed belonging to Phineas Fisher, a hacker who claimed responsibility for breaching the union of the Mossos d'Esquadra, Catalonia's regional police, last year. Spanish police have arrested three people over a data breach linked to a series of dramatic intrusions at European spy software companies — feeding speculation that the net has closed on an online Robin Hood figure known as Phineas Fisher. (AP Photo/Raphael Satter) | Manila Bulletin (AP Photo/Raphael Satter) | Manila Bulletin

The Drupal security team released patches on March 28, 2018 for CVE-2018–7600 also known as Drupalgeddon2, an unauthenticated remote code execution vulnerability in Drupal core. This vulnerability affects Drupal version 6, 7 and 8.

Secuna strongly recommends users to apply all critical patches and fixes that vendors provide for security issues as soon as possible. These patches will provide the strongest level of defense against any potential attacks like this one.

For more information, visit https://www.drupal.org/sa-core-2018-002.

Here are the list of Hacked Local Websites:

Government
http://www.laguna.gov.ph/try.html (Official Website of Laguna)
https://www.doe.gov.ph/hacked.txt (Department of Energy)
http://golokal.dti.gov.ph/sibat.html (Department of Trade & Industry)
http://openstat.psa.gov.ph/sibat.html (Philippine Statistics Authority)
http://openbub.gov.ph/lulu.txt (Bottom-up Budgeting of the Government)
http://rhrc.armm.gov.ph/sibat.html (Regional Human Rights Commission of ARMM)
https://deped.gov.ph/scripts/sibat.html (Department of Education)
http://ecs.nmis.gov.ph/m.txt (National Meat Inspection Service)
http://www.depedcar.ph/ruur.txt (Department of Education in Cordillera Administrative Region)
http://libraryhubnational.laguna.gov.ph/m.txt (Provincial Government of Laguna)
http://www.sbgfc.org.ph/sibat.html (Small Business Corporation a government financial institution)
http://web.nlp.gov.ph/nlp/m.txt (National Library of the Philippines)
http://www.owwa.gov.ph/sites/default/m.txt (Overseas Workers Welface Administration)
http://qchealth.vbusiness.ph/n.txt (Quezon City Private Lying-in Clinics)
http://bookstore.nhcp.gov.ph/m.txt (National Historical Commission of the Philippines)
http://milaor.gov.ph/m.txt (Local Government of Milaor Camarines Sur)
http://sagnay.gov.ph/m.txt (Local Government of Sagnay Camarines Sur)
http://lacarlotacitywaterdistrict.gov.ph/dz.txt (La Carlota City Water District)

Academe
https://apc.edu.ph/validate/sibat.html (Asia Pacific College)
https://pages.upd.edu.ph/sibat.html (University of the Philippines Diliman)
http://tip.edu.ph/1337.txt (Technological Institute of the Philippines)
http://theologicalforum.ktsfi.edu.ph/m.txt (Koinonia Theological Seminary Foundation, Inc)
http://www.pcom.ph/sibat.html (Philippine College of Occupational Medicine)
http://www.vma.edu.ph/sibat.html (VMA Global College & Training Centers, Inc.)
https://umak.edu.ph/krd.html (University of Makati)

Private
http://www.composite.com.ph/sibat.html (Composite Technology, Inc.)
http://flyfast.com.ph/sibat.html (Flight and Simulator Training Academy, Inc.)
http://filigrenasia.ph (Filigrenasia)
http://beta5n.smgroup.ph/m.txt (SM Group)
http://www.nameless.org.ph/sibat.html (Nameless)
http://www.ayfoundation.com.ph/sibat.html (AY Foundation, Inc.)
http://intranet.ernest.com.ph/m.txt (Ernest Logistics Coporation)
http://buysellads.ph/sibat.html (BuySellAds)
http://www.idealvisa.com.ph/sibat.html (IdealVisa Consultancy Philippines)
http://pwwa.ph/sibat.html (Philippine Water Works Association)
http://www.lpmconstruction.com.ph/sibat.html (LPM Construction Supply and Wood Center Corporation)
http://www.thepetshop.ph/sibat.html (The Petshop)
http://www.ibuild.ph/sibat.html (iBuild Web Solutions)