Not a Hack: Lahore Electric Supply Companies (LESCO) Website Privacy Leaks不是一個哈克:拉合爾的電力供應公司( lesco )網站隱私外洩
Lahore Electric Supply Companies (LESCO) is a major electricity power provider in Lahore region of Pakistan.拉合爾電力供應公司( lesco )是一個重大的電力供應商在拉合爾地區的巴基斯坦。 LESCO’s main official website which is used for public access is located at lesco的主要官方網站是用來供市民查閱,是位於 http://www.lesco.gov.pk/ , but apparently LESCO has another web site probably for support staffs and personnels or for training purpose, which allowed everybody from public to ‘hack’ into, and access supposedly private and confidential data. ,但顯然lesco有另一個網站可能是工作人員和支持人員,或作訓練用途,從而使每個人都從市民'黑客'到,並獲得理應私人和機密數據。 (But who cares about privacy in Pakistan?) (但誰關心的隱私在巴基斯坦? )
The website of Lahore Electric Supply Companies that has major security flaw and privacy leaks is located at網站拉合爾電力供應公司,具有重大的安全漏洞和隱私洩漏的是位於 http://www.lesco.info/ . 。 To ‘hack’ the website, simply browse to LESCO Human Resource Management System via Customer Service link at '黑客'的網站,只要瀏覽到lesco的人力資源管理系統通過客戶服務連結 http://www.lesco.info/mc/default.htm . 。 You don’t even need any skill to hack the website.你甚至不需要任何技巧,黑客網站。 The login page has User ID (which is Guest) and password nicely filled in. Just hit “Enter Now !” button to log in to the system.登錄頁有用戶ID (即客戶)和密碼,很好的填補英寸只需點擊“進入現在! ”按鈕,登錄到該系統。

After logging in, ‘hacker’ can find various LESCO customers’ information from database (looks like is MySQL) such as name, address and phone number.登錄後, '黑客'可以在網上找到各種lesco客戶的資料從資料庫(看起來象是MySQL的) ,如姓名,地址和電話號碼。 Also available is application for electricity connection, date of application, status, next course of action and electricity load.還有是應用電力方面,申請日期,地位,在未來的行動過程和用電負荷。 (If you apply to LESCO and heard no news, this hack for you!) Best of all, search functions is provided. (如果您申請lesco ,並聽取了沒有消息,這個技巧為您服務! )最重要的是,搜索功能是提供。


From the design of the website, with failed MySQL commands and broken links which link to ClickSoft.com.pk, which probably is the developer for the site, LESCO.info is probably still in construction, and not mean for public access.從設計的網站,與失敗的MySQL命令和斷開的鏈接鏈接到clicksoft.com.pk ,這可能是開發商為網站, lesco.info可能是仍然在施工,而不是意味著,供市民查閱。 We inclined to believe that the website is mainly used by LESCO staffs for training purpose and not as their back-end system, in view of the poor security measure.我們傾向於認為,該網站主要是用來由lesco人員培訓的目的,而不是作為他們的後端系統,鑑於對窮人的保安措施。 But why the true live data of customers is been used as the sample is out of comprehension, which conveniently provide backdoor access for those want to gather these information.但為何真正的實時數據的客戶是被用來作為該樣本是出於理解,方便地提供後門進入對於那些想收集這些資料。
Probably this is the style of doing work in South Asia part of the world, but does Pakistan has nuclear weapon?也許,這是作風,是做人的工作,在南亞地區是世界的一部分,但巴基斯坦是否已核武器呢? Can nuclear weapon of mass destruction be trusted to someone who can’t even protect personal data, albeit only name, address and phone of its own citizens?可以核大規模殺傷性武器信任誰,有人甚至不能保障個人資料,雖然只有姓名,地址及電話,自己的公民?
IMPORTANT : You're reading a machine translated page which is provided "as is" without warranty. 重要說明:您正在閱讀的機器翻譯網頁是“按原樣”提供的擔保。 Unlike human translation, machine translation does not understand the grammar, semantics, syntax, idioms of natural language, thus often produce inaccurate and low quality text which is misleading and incomprehensible.不像人類翻譯,機器翻譯不明白的語法,語義,語法,成語自然語言,因此,往往產生不準確的和低品質的文字,是具誤導性的和難以理解的。 Thus, please refer to因此,請參閱 original English article原來的英語文章 when in doubt.有疑問時。
Related Articles相關文章
- Intel Experiences Atom Supply Shortage Due to Overwhelming Demand英特爾的經驗,原子的供應短缺,由於絕大多數的需求
- Free Online Phonemyphone Service Helps Locating Misplaced Mobile Phone免費在線phonemyphone服務,幫助定位錯誤的移動電話
- Order Hero Hack Pack with Free Open Source Tools為了英雄哈克包與免費開源工具
- Website Grader: Free Website Analytics and Traffic Measurement Tool網站年級:免費的網站分析和流量測量工具
- Virus Attack Via Infected Gizmo病毒攻擊通過受感染gizmo
- Free Genuine License Code for Privacy Guardian by Signing Up PC Tools Newsletter免費真正的授權碼隱私監護人簽署了PC工具時事通訊
- Toshiba Innovative Idea of Implementing Sleep and Charge USB ports in Satellite Laptop Series東芝創新的理念貫徹睡眠和收費USB連接埠,在衛星的筆記型電腦系列
- Exciting Potential of China in e-Commerce令人振奮的潛力,中國在電子商貿
- How to Make a Laser Pointer from Mini Maglite Flashlight如何使激光指針從迷你手電筒maglite
- Steganos Security Suite 2007 Full Version Free Download and Serial Number steganos安全套件2007完整版免費下載和序號

































May 8th, 2008 16:52 2008年5月8日16時52分
“”"Probably this is the style of doing work in South Asia part of the world, but does Pakistan has nuclear weapon? Can nuclear weapon of mass destruction be trusted to someone who can’t even protect personal data, albeit only name, address and phone of its own citizens?”" “ ” “大概這是作風,是做人的工作,在南亞地區是世界的一部分,但巴基斯坦是否已核武器?可以核大規模殺傷性武器信任誰,有人甚至不能保障個人資料,雖然只有姓名,地址電話和其本國公民“ ? ”
why does everything has to finish on pakistan atomic power.為什麼一切都以完成對巴基斯坦的原子發電站。 Even if a rat dies in Pakistan the conclusion of the debate will end on Pakistan atomic power.即使老鼠死亡,在巴基斯坦的辯論結束時將結束對巴基斯坦的原子發電站。 what about other countries like UK for instance lost 2 cd’s containing more than 100 thousand people’s benefit details containing bank account details as well as personal data.如何看待其他國家,如英國,例如失去了二裁談會的載有100多萬人的利益的詳情載有銀行帳戶的詳情,以及個人資料。
May 9th, 2008 03:25 2008年5月9日3時25分
judging by the content of the post and the grammar used, i’d be highly suspicious it was gw bush posting that message從內容的郵政和語法使用的,我願意非常可疑,這是毛重,布什發布了這一信息
“but does Pakistan has nuclear weapon?” “但巴基斯坦是否有核武器” ?
:D : d 
May 9th, 2008 10:51 2008年5月9日10時51分
Oh yes after having a look on this article on other sources, it looks like someone added the last bit(paragraph) by him/her self.哦是後一看就這條對其他來源的,它看起來像有人說,過去位元(段) ,由他/她的自我。 And after reading this article and having a look on that data, I don’t think SO it may cause any harm on large scale.及後讀此文章後看看就這一數據,我不這麼認為,它可能會造成任何傷害,在大尺度上。
May 9th, 2008 10:51 2008年5月9日10時51分
May 9th, 2008 15:30 2008年5月9日15時30分
Shows great Narrow mindedness of the website.表明,偉大的狹隘意識的網站。
Bad display of Writing.壞的展示寫作。
May 13th, 2008 18:49 2008年5月13日18時49分
Mr Bush says Usama is in Pakistan.布什說,烏薩馬是在巴基斯坦。 The article is too BUSHY lol.文章過於濃密lol 。 The quality of the Protection given to Weapons of Mass destruction and Nuclear resources can’t be measured by a security given to a website which is in Beta Mode.質量給予的保障,以大規模殺傷性武器和核資源不能衡量一個安全考慮到一個網站上,是在測試模式。
I strictly disagree to the last para of your artcle. i ,嚴格不同意到最後第您的artcle 。