Lahore Electric Supply Companies (LESCO) is a major electricity power provider in Lahore region of Pakistan. LESCO’s main official website which is used for public access is located at http://www.lesco.gov.pk/, but apparently LESCO has another web site probably for support staffs and personnels or for training purpose, which allowed everybody from public to ‘hack’ into, and access supposedly private and confidential data. (But who cares about privacy in Pakistan?)
The website of Lahore Electric Supply Companies that has major security flaw and privacy leaks is located at http://www.lesco.info/. To ‘hack’ the website, simply browse to LESCO Human Resource Management System via Customer Service link at http://www.lesco.info/mc/default.htm. You don’t even need any skill to hack the website. The login page has User ID (which is Guest) and password nicely filled in. Just hit “Enter Now !” button to log in to the system.
After logging in, ‘hacker’ can find various LESCO customers’ information from database (looks like is MySQL) such as name, address and phone number. Also available is application for electricity connection, date of application, status, next course of action and electricity load. (If you apply to LESCO and heard no news, this hack for you!) Best of all, search functions is provided.
From the design of the website, with failed MySQL commands and broken links which link to ClickSoft.com.pk, which probably is the developer for the site, LESCO.info is probably still in construction, and not mean for public access. We inclined to believe that the website is mainly used by LESCO staffs for training purpose and not as their back-end system, in view of the poor security measure. But why the true live data of customers is been used as the sample is out of comprehension, which conveniently provide backdoor access for those want to gather these information.
Probably this is the style of doing work in South Asia part of the world, but does Pakistan has nuclear weapon? Can nuclear weapon of mass destruction be trusted to someone who can’t even protect personal data, albeit only name, address and phone of its own citizens?
- BBC iPlayer Finally Arrives on Windows Phone 8 Free Download
- Viber Desktop for Windows & Mac Desk with Video Calling Feature
- Enable SugarSync to Sync External USB and Network Drives
- Sony Xperia ZR Waterproof Smartphone Allows Underwater Full HD Video Shooting
- How to Access Files to SD Cards and Flash Key Drives For Modern Windows 8 Apps