Not a Hack: Lahore Electric Supply Companies (LESCO) Website Privacy Leaks不是一个黑客:拉合尔电力供应公司( LESCO )网站的隐私外泄

Lahore Electric Supply Companies (LESCO) is a major electricity power provider in Lahore region of Pakistan.拉合尔电力供应公司( LESCO )是一个重要的电力供应商在拉合尔地区的巴基斯坦。 LESCO’s main official website which is used for public access is located at LESCO的官方网站主要是用来供市民查阅位于 http://www.lesco.gov.pk/ , but apparently LESCO has another web site probably for support staffs and personnels or for training purpose, which allowed everybody from public to ‘hack’ into, and access supposedly private and confidential data. ,但显然LESCO另一网站可能的支持和人员的工作人员或作训练之用,使每个人都从公共'砍'到,并理应获得私人和机密数据。 (But who cares about privacy in Pakistan?) (但是谁在乎隐私在巴基斯坦? )

The website of Lahore Electric Supply Companies that has major security flaw and privacy leaks is located at该网站拉合尔电力供应公司有重大安全漏洞和隐私外泄位于 http://www.lesco.info/ . To ‘hack’ the website, simply browse to LESCO Human Resource Management System via Customer Service link at要'砍'的网站,只要浏览到LESCO人力资源管理系统通过客户服务链接 http://www.lesco.info/mc/default.htm . You don’t even need any skill to hack the website.您甚至不需要任何的技巧,黑客网站。 The login page has User ID (which is Guest) and password nicely filled in. Just hit “Enter Now !” button to log in to the system.登入页面已经用户ID (这是客户)和密码填入很好只要按下“输入现在! ”按钮登录到该系统。

LESCO Lahore Backend System Hack Login

After logging in, ‘hacker’ can find various LESCO customers’ information from database (looks like is MySQL) such as name, address and phone number.登录之后, '黑客'可以在网上找到各种LESCO客户的信息资料库(看起来是MySQL的) ,如姓名,地址和电话号码。 Also available is application for electricity connection, date of application, status, next course of action and electricity load.也可以是应用电力方面,申请日期,地位,今后的行动方针和用电负荷。 (If you apply to LESCO and heard no news, this hack for you!) Best of all, search functions is provided. (如果您申请LESCO并没有听到消息,这个技巧为你! )最重要的是,搜索功能是提供。

LESCO Customer Details

LESCO Consumers Search

From the design of the website, with failed MySQL commands and broken links which link to ClickSoft.com.pk, which probably is the developer for the site, LESCO.info is probably still in construction, and not mean for public access.从设计的网站,并没有MySQL的命令和损坏的链接链接到ClickSoft.com.pk ,这可能是开发商的网站, LESCO.info可能是仍然在建设,并不意味着供市民查阅。 We inclined to believe that the website is mainly used by LESCO staffs for training purpose and not as their back-end system, in view of the poor security measure.我们倾向于认为,该网站主要是利用LESCO工作人员进行培训的目的,而不是作为他们的后端系统,鉴于安全性差的措施。 But why the true live data of customers is been used as the sample is out of comprehension, which conveniently provide backdoor access for those want to gather these information.但是,为什么真正的实时数据的顾客是被用来作为样品的理解,这方便地提供后门进入那些想收集这些资料。

Probably this is the style of doing work in South Asia part of the world, but does Pakistan has nuclear weapon?也许这是风格的工作做在南亚世界的一部分,但巴基斯坦的核武器? Can nuclear weapon of mass destruction be trusted to someone who can’t even protect personal data, albeit only name, address and phone of its own citizens?可以核武器大规模杀伤性值得信赖的人谁可以甚至没有保护个人数据,但只有姓名,地址和电话的本国公民?

IMPORTANT : You're reading a machine translated page which is provided "as is" without warranty. 重要:您正在阅读的机器翻译网页这是“原样”提供,无保修。 Unlike human translation, machine translation does not understand the grammar, semantics, syntax, idioms of natural language, thus often produce inaccurate and low quality text which is misleading and incomprehensible.不同人的翻译,机器翻译不明白的语法,语义,句法,成语自然语言,因此,往往产生不准确,低质量的文字这是误导和费解。 Thus, please refer to因此,请参阅 original English article英文原文的文章 when in doubt.当怀疑。



6 Responses to “Not a Hack: Lahore Electric Supply Companies (LESCO) Website Privacy Leaks” 6日回应“不是哈克:拉合尔电力供应公司( LESCO )隐私泄漏”

  1. Jav
    May 8th, 2008 16:52 08年5月8日16:52
    1

    “”"Probably this is the style of doing work in South Asia part of the world, but does Pakistan has nuclear weapon? Can nuclear weapon of mass destruction be trusted to someone who can’t even protect personal data, albeit only name, address and phone of its own citizens?”" “ ” “也许这是风格的工作做在南亚世界的一部分,但巴基斯坦的核武器能否核武器大规模杀伤性值得信赖的人谁可以甚至没有保护个人数据,尽管只是名称,地址和电话的本国公民? “ ”

    why does everything has to finish on pakistan atomic power.为什么一切都结束对巴基斯坦原子能发电站。 Even if a rat dies in Pakistan the conclusion of the debate will end on Pakistan atomic power.即使死老鼠在巴基斯坦辩论结束将结束对巴基斯坦原子能发电站。 what about other countries like UK for instance lost 2 cd’s containing more than 100 thousand people’s benefit details containing bank account details as well as personal data.那么其他国家如英国例如下跌2裁谈会含有超过100万人的利益详情载有银行帐户的详细资料以及个人资料。

  2. johndoe
    May 9th, 2008 03:25 08年5月9日3点25分
    2

    judging by the content of the post and the grammar used, i’d be highly suspicious it was gw bush posting that message看的内容后,并使用的语法,我会非常可疑这是毛重布什张贴该讯息 :搭扣

    “but does Pakistan has nuclear weapon?” “但巴基斯坦的核武器? ” :搭扣 :D :搭扣 :搭扣

  3. Jav
    May 9th, 2008 10:51 08年5月9日10:51
    3

    Oh yes after having a look on this article on other sources, it looks like someone added the last bit(paragraph) by him/her self.啊之后就看此文章的其他来源,它看起来像有人说的最后位(段)的他/她的自我。 And after reading this article and having a look on that data, I don’t think SO it may cause any harm on large scale.后读此文章,并看看这些数据,我不这么认为它可能造成任何伤害大规模。

  4. Jav
    May 9th, 2008 10:51 08年5月9日10:51
    4

    :搭扣

  5. SAF苏丹
    May 9th, 2008 15:30 08年5月9日15:30
    5

    Shows great Narrow mindedness of the website.显示伟大胸襟窄的网站。
    Bad display of Writing.不良展示写作。

  6. Fahd Murtaza法赫德Murtaza
    May 13th, 2008 18:49 2008年五月13日18:49
    6 6日

    Mr Bush says Usama is in Pakistan.布什说,乌萨马是在巴基斯坦。 The article is too BUSHY lol.文章过于浓密的上海。 The quality of the Protection given to Weapons of Mass destruction and Nuclear resources can’t be measured by a security given to a website which is in Beta Mode.的质量保护提供大规模杀伤性武器和核资源不能衡量一个安全考虑到一个网站上,是在测试模式。

    I strictly disagree to the last para of your artcle.本人不严格的最后段的国籍法。

Leave a Reply留下一个回复

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> 您可以使用这些标签: href="" title="">的<a <abbr title=""> <acronym title="">的<b> <blockquote cite=""> <cite>的<code> “删除日期时间= “ ” “的<em> <i> <q cite=""> <strike>的<strong>

Subscribe without commenting订阅没有评论


Custom Search

Incoming Search Terms for the Article收到的搜索字词的文章

www.lesco.gov.com www.lesco.gov.com - - www.lesco.gov.pk www.lesco.gov.pk - - www.lesco.gov.com.pk www.lesco.gov.com.pk - - lesco.gov.com.pk lesco.gov.com.pk - - lesco.gov.com lesco.gov.com - - lesco.gov.pk lesco.gov.pk - - lesco pakistan lesco巴基斯坦 - - hack electricity 破解电力 - - electricity hack 电力破解 - - Companies in Lahore 公司在拉合尔 - - lesco lahore lesco拉合尔 - - lesco lahore pk lesco拉合尔峰 - - lesco lesco - - hacking electricity 黑客电力 - - lahore electricity 拉合尔电力 - - lahore pakistan electricity 巴基斯坦拉合尔电 - - lahore electric supply co pakistan 拉合尔供电公司巴基斯坦 - - http/www.lesco.gov.pk 的http / www.lesco.gov.pk - - gov.com.pk gov.com.pk - - how does electrical supply used for mobile phone function 请问电力供应用于移动电话功能 - - lescoinfo lescoinfo - - http://www.lesco.gov.pk http://www.lesco.gov.pk - - lesco.info lesco.info - - turkish electric supply companies 土耳其电力供应公司 - - lesco power pk lesco功率峰 - - phone hack 手机黑客 - - Lesco Web Site Lesco网站 - - Lahore Electric Supply Company (Pakistan) 拉合尔电力供应公司(巴基斯坦) - - pak hacker to rapidshare accounts hacking 巴黑客入侵rapidshare帐户 - - Lahore Electrical Firms 拉合尔电气公司 - - lesco lahore lesco拉合尔 - - electrical power supply for lahore pakistan 电力供应巴基斯坦拉合尔 - - www lesco.gov.pk 的www lesco.gov.pk - - www.lesco.gov www.lesco.gov - - lahore board 8th 2008 拉合尔2008年董事会第8次 - - dsm-210 hacking 帝斯曼- 210攻击 - - lahore electricity demand 拉合尔的电力需求 - - lahore electric supply company 拉合尔供电公司 - - lahore electric supply hack 拉合尔电力供应破解 - - logging electrical data on website 测井数据的电器网站 - - lesco govt pakistan 巴基斯坦政府lesco - - usb electricity in pakistan USB接口的电力在巴基斯坦 - - lahore electric supply 拉合尔电力供应 - - hack .pk website password 破解。峰网站的密码 - - electricity lahore pakistan 电力巴基斯坦拉合尔 - - turkish company in lahore 土耳其公司在拉合尔 - - pakistan web cam hacks 巴基斯坦黑客网络摄像机 - - how to hack electricity 如何破解电力 - - password for lesco.gov.pk 密码lesco.gov.pk - - lahore electric supply co. 拉合尔供电公司。 - -