RootAyyildiz Turkish Defacer, the “Father of Turkish Hackers” as he is called, strikes again! According to exclusive information from SecNews, from reliable internet sources, he will completely attack the critical infrastructure of Cyprus, mainly banking institutions and government services!
RootAyyildiz Turkish Defacer, the “Father of Turkish Hackers” as he is called, is one of the most recognizable hackers in the world who carries out high-profile attacks on government targets. He has certainly caught the attention of many law enforcement agencies with his actions, due to his successful hacking attacks. For hackers, he is a formidable opponent who with each successful attack, raises the bar even higher, while for his victims/targets, his name causes terror and concern.

The would-be hacker (of Turkish origin, according to his statement) targeted Cyprus and specifically the information systems of the Ministry of National Defense of Cyprus (www.mod.gov.cy), according to exclusive information available to SecNews.
More News: AKINCILAR: New hacking attack on the Ministry of Foreign Affairs (?) (Updated)
The Ministry of Defence is responsible for the implementation of Government Policy regarding the security and territorial integrity of Cyprus. Within the framework of this policy, the Ministry of Defence has promoted and continues to promote a series of measures aimed at strengthening the Republic's defense shield to prevent any foreign intrusion and, consequently, at strengthening its negotiating capacity. With consistency and a high sense of responsibility, the Ministry of Defence promotes the implementation of this policy. The Minister is Mr. Charalambos Petrides since 29 June 2020.

RootAyyildiz Turkish Defacer, as evidenced by the screenshots below which were brought to SecNews’ attention via anonymized email and social media communication, managed to gain unauthorized access via SQL injection attack to the servers of the Ministry of National Defense of Cyprus. the Turkish hacker holds in his hands the emails and passwords of the admin accounts which manage the Ministry’s databases that support the website and related internet services of the Ministry.
SecNews lists the relevant material in the hands of the Turkish hacker (ed. that which has been communicated to SecNews). The editorial team's assessment is that the Turkish Father of Hackers (RootAyyildiz) has further access, since from the data mentioned he has obtained administrator access to a specific central server using a SQL Injection. In fact, the Turkish hacker chose as the date of notification of the attack, one day before March 25 (National Day in Greece) where symbolic movements were also carried out to honor the 200th anniversary of the Greek Revolution.
See Also: Powerful attack by hackers on the Greek .gr Domain Name Registry!
In the material that was shared, sensitive data has been hidden for reasons of protection of society as a whole, as well as the passwords of individuals (administrators and armed forces officers) that were allegedly obtained by the Turkish hacker.
Here are the relevant screenshots:







The mentioned screenshots without the relevant hiding that we have carried out for the protection of society as a whole are available to the Ministry of National Defense of Cyprus from SecNews.gr, upon request, in order to establish the methods of access and the files that have allegedly been intercepted. The relevant evidence is distributed via a secure application/group chat that the Turkish hacker has and has been checked by the editorial team of SecNews regarding its reliability.
Security News: Counter.Social The most secure social network!
We do not know the time at which the Turkish hacker gained access to the servers. The only thing that is certain is that the legitimate administrators do not seem to have detected the attack yet, resulting in them being a pawn in the hands of the hacker. From the evaluation of the data brought to our attention, we find that the Turkish hacker RootAyyldiz has the ability to alter data on the server, add/remove web pages or spread malware to unsuspecting users using the website of the Ministry of National Defense of Cyprus. Furthermore, it is not clear from the screenshots that have been provided regarding the type of personal data that has been extracted and is located on the server that has been targeted.

In questions posed by the editorial team to Root Ayyldiz after the briefing regarding the attack against the Ministry of National Defense of Cyprus, he told us that the access he has gained is based on a SQL Injection attack. The worrying thing is that, as he says, he has targeted Cyprus and is preparing attacks on other critical infrastructures. He specifically stated “Very difficult days await for Cyprus, There is too much data to be analyzed and leaked, RootAyyldiz wants to destroy Cyprus and will target banking and military systems”

The unauthorized access to high-profile websites in Cyprus and especially the threat of an attack on the banking sector has as a logical consequence the estimated immediate risk of theft of personal accounts of hundreds of users with all the negative consequences that this entails! The authorities should immediately take measures after the relevant warning made by the Turkish hacker RootAyyldiz.
Personal data of critical databases belonging to Cypriot banks and the state agency are at risk, while at the same time there is fear of a second, more sophisticated and orchestrated attack that will endanger banking apps and banking information systems with the ultimate aim of stealing money.

Who is RootAyyildiz Turkish Defacer?
In hacking circles, he is called “The Father of Turkish Hackers” given his knowledge and hacking skills as well as his successful hacking attacks. Among his successful attacks are critical Greek infrastructures. The Ministry of Foreign Affairs, the Ministry of Interior, the Ministry of Labor and many high-profile targets in Greece have been cyberattacked by this hacker.
Learn more about RootAyyildiz Turkish Defacer in his exclusive interview with SecNews.
TECHNICAL ANALYSIS
What is a SQL injection attack?
SQL injection is a code injection technique that allows an attacker to “run” SQL commands against a target server. A successful SQL injection attack allows the execution of any query on the target database, which means the ability to collect sensitive information, such as passwords, usernames, emails, credit card numbers, etc.
These attacks exploit vulnerabilities in web applications that communicate with backend servers that store databases. SQL stands for Structured Query Language. It is a programming language used to insert, manipulate, and retrieve data from an SQL database. Attackers can easily find out, with a few simple commands, if a page is vulnerable to an SQL injection vulnerability. If it is, they will be able to steal data, corrupt it, and even become administrators of the database server.

According to research, SQL injection vulnerabilities are among the most common application vulnerabilities in recent years. The first discussions about this attack began in 1998. From 2007 to 2010, SQL injection was among the top 10 web application vulnerabilities. From 2005 to 2011, SQL attacks accounted for 83% of all (known) data breaches.
There are four subcategories of SQL injection attacks:
- Classic SQL injection
- Blind SQL injection
- SQL injection based on the Database Management System
- Complex SQL injection (SQL injection + weak authentication, SQL injection +DDoS attacks, SQL injection +DNS hijacking, SQL injection + XSS).
SQL injection is a relatively simple type of attack, as it does not require any special tools to carry it out. An experienced attacker can gain access to the entire system, not just the database. Therefore, companies and organizations should take it seriously, as after so many years of this attack, everyone should be much more prepared.

Prevention measures
- Perhaps the most basic preventive measure is proper design, good construction, and constant monitoring of the database, so that it is not vulnerable to this specific attack.
- Restricting server configuration data: Restricting access to incorrect parameters can reduce the likelihood of an attack on the target server. While it does not offer 100% security, it is a first step in database security.
- Good knowledge of all SQL Servers on the network by administrators: First, administrators should know how many SQL servers are on the network. This process may not be as simple as it seems, as the majority of servers operate on dynamic TCP ports and usually these servers operate only when the user “needs” them. Therefore, some servers may not be active. To find all SQL Servers, SQL ping, SQL scan and more specialized software could be used.
- Continuous updates. Software companies frequently release updates to fix potential vulnerabilities. Therefore, organizations must make sure to update the applications, software, and systems they use in general to stay secure.
- Denying access to specific server ports by unknown users: It does not offer absolute security, especially against SQL injection attacks, but it is an important security measure for the entire network of a company or organization. For example, closing UDP Port 1434 [this port is used for mapping Microsoft SQL databases (Microsoft SQL monitor database)] and all TCP ports on which SQL Server “listens” can enhance security.
- Adopt strong admin passwords. Using a strong password can prevent brute force, SQL injection, and many other attacks. It is also recommended to change them frequently.
SecNews continues to investigate the incident and will keep you updated on any new developments. Administrators should immediately take down the website and conduct a forensic analysis of the attack data to determine if additional Ministry information systems have been affected, using the affected server as a jump point!
Stay tuned!
