Hacked! #################################################### cia.gov #################################################### Vulnerabilities : [*] https://www.cia.gov/library/publications/the-world-factbook/geos/va.html [*] https://www.cia.gov/library/publications/the-world-factbook/region/region_mde.html [*] https://www.cia.gov/library/publications/the-world-factbook/maps/refmap_africa.html [*] https://www.cia.gov/library/publications/the-world-factbook/region/region_ant.html [*] https://www.cia.gov/library/publications/the-world-factbook/region/region_eas.html [*] https://www.cia.gov/library/publications/the-world-factbook/region/region_afr.html [*] https://www.cia.gov/library/publications/the-world-factbook/region/region_soa.html [*] https://www.cia.gov/library/publications/the-world-factbook/maps/p_refmap_asia.html [*] https://www.cia.gov/library/publications/the-world-factbook/maps/p_refmap_time_zones.html #################################################### cia.gov #################################################### Exploit ColdFusion : File "/usr/local/lib/python2.6/dist-packages/requests-0.13.6-py2.6.egg/requests/api.py", line 63, in get return request('get', url, **kwargs) File "/usr/local/lib/python2.6/dist-packages/requests-0.13.6-py2.6.egg/requests/safe_mode.py", line 38, in wrapped return function(method, url, **kwargs) File "/usr/local/lib/python2.6/dist-packages/requests-0.13.6-py2.6.egg/requests/api.py", line 50, in request return session.request(method=method, url=url, **kwargs) File "/usr/local/lib/python2.6/dist-packages/requests-0.13.6-py2.6.egg/requests/sessions.py", line 238, in request r.send(prefetch=prefetch) File "/usr/local/lib/python2.6/dist-packages/requests-0.13.6-py2.6.egg/requests/models.py", line 603, in send timeout=self.timeout, File "/usr/local/lib/python2.6/dist-packages/requests-0.13.6-py2.6.egg/requests/packages/urllib3/poolmanager.py", line 153, in urlopen return self.proxy_pool.urlopen(method, url, **kw) File "/usr/local/lib/python2.6/dist-packages/requests-0.13.6-py2.6.egg/requests/packages/urllib3/connectionpool.py", line 415, in urlopen body=body, headers=headers) File "/usr/local/lib/python2.6/dist-packages/requests-0.13.6-py2.6.egg/requests/packages/urllib3/connectionpool.py", line 267, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.6/httplib.py", line 910, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.6/httplib.py", line 947, in _send_request self.endheaders() File "/usr/lib/python2.6/httplib.py", line 904, in endheaders self._send_output() File "/usr/lib/python2.6/httplib.py", line 776, in _send_output self.send(msg) File "/usr/lib/python2.6/httplib.py", line 735, in send self.connect() File "/usr/local/lib/python2.6/dist-packages/requests-0.13.6-py2.6.egg/requests/packages/urllib3/connectionpool.py", line 95, in connect sock = socket.create_connection((self.host, self.port), self.timeout) File "/usr/lib/python2.6/socket.py", line 514, in create_connection raise error, msg #################################################### cia.gov #################################################### Here are some Leaked Accounts of some CIA Field Agents(stationed at Virginia), Documents, and website infos of - https://cia.gov To CIA - Where is your security gals ;) ---------------------------------------------------------------------------------- website - https://www.cia.gov/ Location - Virginia - Reston WebSite Last Updated - Mon, 09 Apr 2012 16:53:44 GMT (At time of exploitation) --------------------------------------DETAILS-------------------------------------- [ localityName=Mclean stateOrProvinceName=Virginia countryName=US serialNumber=Government Entity businessCategory=Government Entity 1.3.6.1.4.1.311.60.2.1.3=US ] Website SSL serial Number - 1B6E90CFD3E033B37EA656F068ECB80F(Registered to Jason Robert, cia-intercom chief) using SSL v3.0[non updated] Server IP - 156.154.70.10 (apache) Lookup for A records of cia.gov Host - cia.gov. TTl - 14400 A answer- 198.81.129.107 Site Etag : 890e-4bd41d95b3600 Admin Login Handle - ucia-gw.customer.alter.net (157.130.59.190) ---------------------------------------------------------------------------------- [[[[[[[[[ Hacked Accounts ]]]]]]]]]] ---------------------------------------------------------------------------------- 1. Nathan C. Shea Address - Lockwood Rd Henrico, VA Zip - 20190 B'Day - September 5, 1976 (35 years old) Visa - 4916 5207 0220 XXXX UPS tracking number -1Z 8Y3 327 95 5468 353 9 Email ID: nathacsh@cia.gov Password - Nee1zu3Ai91d4 2. Daniel Vida Address - Pretty Lake Ave Norfolk, VA B'Day - January 10, 1974 (38 years old) Visa - 4716 5639 4375 XXXX CVV2 - 027 UPS tracking number - 1Z 199 062 00 5717 481 2 Email ID: dan.vida3@cia.gov Password - tiXue2vooL4fdwq 3. Kevin Morehead Address - Ox Rd Woodstock, VA Zip - 20194 B'Day - October 27, 1975 (36 years old) Visa - 5207 9306 2697 XXXX CVC2 - 370 UPS tracking number - 1Z 831 725 07 7755 563 5 EMail ID : morehead.kev@cia.gov Password - MeijaaG8eimm6 4. Ronnie B. Allen Address - Richmond VA Zip - 20191 B'Day - April 5, 1973 (39 years old) MasterCard - 5208 6923 4319 XXXx CVC2 - 947 UPS tracking number - 1Z 581 796 27 1185 535 6 Email ID - RonnieBAllen@cia.gov Password - eiqu7kae1Rt 5. Darrell A. Dunleavy Address - Montpelier Ct Woodbridge, VA Zip - 20194 B'Day - November 20, 1973 (38 years old) MasterCard - 5480 7450 0976 XXXX CVC2 - 820 UPS tracking number - 1Z 054 879 87 9434 053 8 Email ID : darrelladunl41@cia.gov Password - Uth2a675hheG 6. Patricia L. Schatz Address: 1631 Big Indian Metairie, LA 70001 Phone: 504-628-9374 Email Address: PatriciaLSchatz@cia.gov Username: Wasend Password: AhrieCowui7 Birthday: November 28, 1959 MasterCard: 5226 8835 4490 7005 Expires: 10/2014 CVC2 287 SSN:437-03-4245 Occupation: CIA Officer Weight: 130.0 pounds Height: 5' 6" Enjoy :D ........ SOme more details will be leaked soon, CIA Beware! -CyberZeist (Against Online Censorship)