May 8, 2008
Tip and Trick Editorial

Not a Hack: Lahore Electric Supply Companies (LESCO) Website Privacy Leaks

Lahore Electric Supply Companies (LESCO) is a major electricity power provider in Lahore region of Pakistan. LESCO’s main official website which is used for public access is located at http://www.lesco.gov.pk/, but apparently LESCO has another web site probably for support staffs and personnels or for training purpose, which allowed everybody from public to ‘hack’ into, and access supposedly private and confidential data. (But who cares about privacy in Pakistan?)

The website of Lahore Electric Supply Companies that has major security flaw and privacy leaks is located at http://www.lesco.info/. To ‘hack’ the website, simply browse to LESCO Human Resource Management System via Customer Service link at http://www.lesco.info/mc/default.htm. You don’t even need any skill to hack the website. The login page has User ID (which is Guest) and password nicely filled in. Just hit “Enter Now !” button to log in to the system.

LESCO Lahore Backend System Hack Login

After logging in, ‘hacker’ can find various LESCO customers’ information from database (looks like is MySQL) such as name, address and phone number. Also available is application for electricity connection, date of application, status, next course of action and electricity load. (If you apply to LESCO and heard no news, this hack for you!) Best of all, search functions is provided.

LESCO Customer Details

LESCO Consumers Search

From the design of the website, with failed MySQL commands and broken links which link to ClickSoft.com.pk, which probably is the developer for the site, LESCO.info is probably still in construction, and not mean for public access. We inclined to believe that the website is mainly used by LESCO staffs for training purpose and not as their back-end system, in view of the poor security measure. But why the true live data of customers is been used as the sample is out of comprehension, which conveniently provide backdoor access for those want to gather these information.

Probably this is the style of doing work in South Asia part of the world, but does Pakistan has nuclear weapon? Can nuclear weapon of mass destruction be trusted to someone who can’t even protect personal data, albeit only name, address and phone of its own citizens?



  • Bernie Mac

    Thank God there are still some decent sanctuaries left for internet privacy havens. You don't have to be doing anything shady or crazy to simply want your privacy back.

  • http://www.searchmoney.com.au/ Tami C

    That's why I carry bundles of cash..

  • http://www.master-gift.ru George

    Very interesting… thanks.

  • Tort King

    LOL, NO ONE could hack my site. I do all the security myself.

  • http://www..fahdmurtaza.com Fahd Murtaza

    Mr Bush says Usama is in Pakistan. The article is too BUSHY lol. The quality of the Protection given to Weapons of Mass destruction and Nuclear resources can't be measured by a security given to a website which is in Beta Mode.

    I strictly disagree to the last para of your artcle.

  • SAF

    Shows great Narrow mindedness of the website.

    Bad display of Writing.

  • Jav

    :D

  • Jav

    Oh yes after having a look on this article on other sources, it looks like someone added the last bit(paragraph) by him/her self. And after reading this article and having a look on that data, I don’t think SO it may cause any harm on large scale.

  • johndoe

    judging by the content of the post and the grammar used, i'd be highly suspicious it was g w bush posting that message :D

    "but does Pakistan has nuclear weapon?" :D :D :D

  • Jav

    """Probably this is the style of doing work in South Asia part of the world, but does Pakistan has nuclear weapon? Can nuclear weapon of mass destruction be trusted to someone who can’t even protect personal data, albeit only name, address and phone of its own citizens?""

    why does everything has to finish on pakistan atomic power. Even if a rat dies in Pakistan the conclusion of the debate will end on Pakistan atomic power. what about other countries like UK for instance lost 2 cd's containing more than 100 thousand people's benefit details containing bank account details as well as personal data.