Not a Hack: Lahore Electric Supply Companies (LESCO) Website Privacy Leaks

Lahore Electric Supply Companies (LESCO) is a major electricity power provider in Lahore region of Pakistan. LESCO’s main official website which is used for public access is located at http://www.lesco.gov.pk/, but apparently LESCO has another web site probably for support staffs and personnels or for training purpose, which allowed everybody from public to ‘hack’ into, and access supposedly private and confidential data. (But who cares about privacy in Pakistan?)

The website of Lahore Electric Supply Companies that has major security flaw and privacy leaks is located at http://www.lesco.info/. To ‘hack’ the website, simply browse to LESCO Human Resource Management System via Customer Service link at http://www.lesco.info/mc/default.htm. You don’t even need any skill to hack the website. The login page has User ID (which is Guest) and password nicely filled in. Just hit “Enter Now !” button to log in to the system.

LESCO Lahore Backend System Hack Login

After logging in, ‘hacker’ can find various LESCO customers’ information from database (looks like is MySQL) such as name, address and phone number. Also available is application for electricity connection, date of application, status, next course of action and electricity load. (If you apply to LESCO and heard no news, this hack for you!) Best of all, search functions is provided.

LESCO Customer Details

LESCO Consumers Search

From the design of the website, with failed MySQL commands and broken links which link to ClickSoft.com.pk, which probably is the developer for the site, LESCO.info is probably still in construction, and not mean for public access. We inclined to believe that the website is mainly used by LESCO staffs for training purpose and not as their back-end system, in view of the poor security measure. But why the true live data of customers is been used as the sample is out of comprehension, which conveniently provide backdoor access for those want to gather these information.

Probably this is the style of doing work in South Asia part of the world, but does Pakistan has nuclear weapon? Can nuclear weapon of mass destruction be trusted to someone who can’t even protect personal data, albeit only name, address and phone of its own citizens?



10 Responses to “Not a Hack: Lahore Electric Supply Companies (LESCO) Website Privacy Leaks”

  1. Bernie Mac
    September 24th, 2009 23:25
    10

    Thank God there are still some decent sanctuaries left for internet privacy havens. You don’t have to be doing anything shady or crazy to simply want your privacy back.

  2. Tami C
    July 28th, 2009 14:46
    9

    That’s why I carry bundles of cash..

  3. George
    June 18th, 2009 19:36
    8

    Very interesting… thanks.

  4. Tort King
    June 11th, 2009 12:42
    7

    LOL, NO ONE could hack my site. I do all the security myself.

  5. Fahd Murtaza
    May 13th, 2008 18:49
    6

    Mr Bush says Usama is in Pakistan. The article is too BUSHY lol. The quality of the Protection given to Weapons of Mass destruction and Nuclear resources can’t be measured by a security given to a website which is in Beta Mode.

    I strictly disagree to the last para of your artcle.

  6. SAF
    May 9th, 2008 15:30
    5

    Shows great Narrow mindedness of the website.
    Bad display of Writing.

  7. Jav
    May 9th, 2008 10:51
    4

    :D

  8. Jav
    May 9th, 2008 10:51
    3

    Oh yes after having a look on this article on other sources, it looks like someone added the last bit(paragraph) by him/her self. And after reading this article and having a look on that data, I don’t think SO it may cause any harm on large scale.

  9. johndoe
    May 9th, 2008 03:25
    2

    judging by the content of the post and the grammar used, i’d be highly suspicious it was g w bush posting that message :D

    “but does Pakistan has nuclear weapon?” :D :D :D

  10. Jav
    May 8th, 2008 16:52
    1

    “”"Probably this is the style of doing work in South Asia part of the world, but does Pakistan has nuclear weapon? Can nuclear weapon of mass destruction be trusted to someone who can’t even protect personal data, albeit only name, address and phone of its own citizens?”"

    why does everything has to finish on pakistan atomic power. Even if a rat dies in Pakistan the conclusion of the debate will end on Pakistan atomic power. what about other countries like UK for instance lost 2 cd’s containing more than 100 thousand people’s benefit details containing bank account details as well as personal data.

Leave a Reply

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Subscribe to comments feature has been disabled. To receive notification of latest comments posted, subscribe to Tip and Trick Comments RSS feed or register to receive new comments in daily email digest.
Custom Search

Incoming Search Terms for the Article

Www.lesco.gov.pk - www.lesco.com.pk - www.lesco.gov.com.pk - www.lesco.gov.com - LESCO.COM.PK - lesco pakistan - lesco.gov.pk - lesco.gov.com.pk - www.lesco.pk - www.lesco.gov.pk.com - lesco.gov.com - www.lesco.govt.pk - lesco lahore - wordpress blogs - lesco.pk - www.lesco.pk.com - lahore electric supply company - www.lessco.gov.pk - www.lessco.com.pk - LESCO LAHORE PAKISTAN - lessco.com.pk - lesco pak - hack electricity - http www.lesco.gov.pk - Lesco - www.lesco.com - electricity hack - www.lesco.govt.com - LESSCO.GOV.PK - lahore electricity - www.lesco.gov - www.lesco.gov.pak - lesco.govt.pk - lesco.gov.pk.com - lahore electric supply company pakistan - lahore electric supply - www.lesco.govt.com.pk - lessco pakistan - lesco pakistan lahore - lesco of pakistan - emails Nos. of LESCO LAHORE - Companies in Lahore - www.lessco.pk.com - ? www.lesco.com.pk - http://www.lesco.gov.pk/ - lahore electric supply co pakistan - lesco.govt.com.pk - www.lessco.gov.com - lesco gov pk - Lahore Electricity supply company pakistan - lesco lahore pk - lesco.pk.com - lesco.govt.com - lesco.pak - lahore electricity supply company - lesco.info - Lesco Web Site - lesco pk - lesco in pakistan - www lesco gov pk - lesco.gov - www.lesco.gov.pk. - www.lessco gov.pk - http://www.lesco.gov.pk - pakistan lesco - hacking electricity - lahore pakistan electricity - how to hack electricity - www.lesco.govt.pk.com - lahore electric supply co - lessco lahore - www.@lesco.com.pk - WWW.LESCO PAKISTAN.COM - www.lessco.com.pakistan - power companies in lahore -