Larnaca Airport Cyber Attack hermesairports.com: It seems that Turkish hacker RootAyyildiz Turkish Defacer continues his attacks on critical infrastructures in Cyprus unhindered, without being stopped by the competent authorities so far. According to EXCLUSIVE information from SecNews, from reliable sources on the internet, the would-be hacker from our neighboring country attacked and extracted databases with confidential (?) -according to his statement- data of employees and customers of Hermes Airport in Larnaca. HermesAirports has taken over the management and control of the Larnaca and Paphos International Airports.

RootAyyildiz Turkish Defacer, the “Father of Turkish Hackers” as hackers call him in their communication forums, has proven to be one of the most dangerous hackers, scoring dozens of high-profile attacks on government targets in many countries (including Greece, Cyprus and the USA). With each successful hacking attack he manages to catch the attention of authorities and security experts. However, the Turkish hacker does not seem to be deterred, on the contrary, at every opportunity, he attacks his next target.
His identity remains unknown to this day, with some suggesting that he is either an individual or a group of hackers working with the intelligence services of the neighboring country. For hackers internationally, he is a recognizable attacker with extensive activity against targets, while his pseudonym (RootAyyildiz Turkish Defacer) is known in all hacking forums and to the general public.

It should be noted that a few days ago, the Turkish hacker had successfully carried out an attack via SQL injection on the information systems of the Ministry of National Defense of Cyprus (www.mod.gov.cy) according to exclusive information brought to the attention of SecNews. The RootAyyildiz Turkish Defacer managed to gain unauthorized access to the servers of the Ministry of National Defense of Cyprus. During this specific attack, emails and passwords of admin accounts were stolen, while according to the information published on a messaging platform it seems that he had gained access to the Ministry's databases that support the website and related internet services of the Ministry.
Learn more: RootAyyildiz Turkish Defacer: Turkish hacker attacks Cyprus!

This time, the target was Hermes Airports Ltd (backlink), which controls the Larnaca and Paphos International Airports of the Republic of Cyprus.
The hacker, following the same strategy, identified and attacked via SQL injection a weakness in a website belonging to the Airport, penetrated the company's servers and stole databases with personal information of employees and customers. More specifically, as the hacker claims (without being confirmed by SecNews at this time) among the data that was breached we find interdepartmental conversations, employee-customer email correspondence, statements with the company's monthly expenses as well as databases with personal personnel information (emails, names, contact details, passwords).
Related security news: Phishing attacks use fake COVID-19 vaccine research to steal personal information

Below you will find the relevant screenshots that prove the validity of the attack. In the reported material that was shared, sensitive data has been hidden for reasons of protecting the community as a whole, as well as the passwords of individuals who were allegedly obtained by the Turkish hacker.

The name of the hacking attack by RootAyyildiz was “Let Ayse go on vacation”.

As can be seen, RootAyyildiz has gained SQL Shell access to a server running SQL Server 2008 R2 Standard edition, allowing him to run raw queries on the database and extract data at will. A sample of his searches is shown below:

It should be emphasized that in this particular hacking attack, as well as in the attack on the information systems of the Ministry of National Defense of Cyprus, after evaluating the data brought to our attention, we find that the Turkish hacker RootAyyldiz has the ability to alter data on the server, add/remove websites or spread malware to unsuspecting users using the Larnaca Airport website! Furthermore, it is not clear from the screenshots that have been provided regarding the type of personal data that has been extracted and is located on the targeted server, nor can the exact time of extraction be determined. What is certain, however, is that the attack is ongoing.
See also: Microsoft – Users still not updating Windows 10
SecNews warned that Cyprus' critical infrastructure is in the hacker's sights!

In communication with the Turkish hacker on a well-known secure messaging platform that announces very important information regarding the attacks he carries out, after the update regarding the attack against the Ministry of National Defense of Cyprus, SecNews notified through a relevant article/update that RootAyyildiz Turkish Defacer has targeted Cyprus and is preparing significant attacks on other critical infrastructures, without specifying which ones.
More hacking attacks: Cyberattack on innovation.gov.gr of the Ministry of Interior
He specifically stated "Very difficult days await for Cyprus, There is too much data to be analyzed and leaked, RootAyyldiz wants to destroy Cyprus and will target banking and military systems". His threat seems to be turning into action, starting from the Larnaca and Paphos International Airport.

Hermes Airports Ltd
Hermes Airports Ltd assumed on May 12, 2006 the management and control of Larnaca and Paphos International Airports, based on a 25-year BOO (Build-Operate-Removal) concession agreement with the Republic of Cyprus. It is a consortium of 9 shareholders, with Cypriot and international partners, based in Cyprus.
Construction of the terminal buildings commenced immediately after the signing of the agreement, under a fast-track Design and Build Contract. The new building at Paphos International Airport was opened for use in November 2008, while the new building at Larnaca International Airport was handed over to the public a year later, in November 2009. The Build-Operate-Disposal project is the first privatization of its kind in Cyprus. The airports offer world-class, state-of-the-art facilities with an emphasis on excellent passenger and customer service.
They remain committed to optimizing Cyprus’ connectivity while enhancing the passenger experience. Both airports serve a combined total of over 11 million passengers annually.
Source of information: https://el.hermesairports.com/

RootAyyildiz Turkish Defacer- Turkish hacker
In hacking circles, he is called “The Father of Turkish Hackers” given his knowledge and hacking skills as well as his successful hacking attacks. Among his successful attacks are critical Greek infrastructures. The Ministry of Foreign Affairs, the Ministry of Interior, the Ministry of Labor and many high-profile targets in Greece have been cyberattacked by this hacker in the past.
Learn more about RootAyyildiz Turkish Defacer in his exclusive interview with SecNews.
SQL injection attack
SQL injection is a code injection technique that allows an attacker to “run” SQL commands against a target server. A successful SQL injection attack allows the execution of any query on the target database, which means the ability to collect sensitive information, such as passwords, usernames, emails, credit card numbers, etc.

These attacks exploit vulnerabilities in web applications that communicate with backend servers that store databases. SQL stands for Structured Query Language. It is a programming language used to insert, manipulate, and retrieve data from an SQL database. Attackers can easily find out, with a few simple commands, if a page is vulnerable to an SQL injection vulnerability. If it is, they will be able to steal data, corrupt it, and even become administrators of the database server.
SQL Injection news: Sophos fixes a SQL injection vulnerability in Cyberoam OS

Prevention measures
- Perhaps the most basic preventive measure is proper design, good construction, and constant monitoring of the database, so that it is not vulnerable to this specific attack.
- Restricting server configuration data: Restricting access to incorrect parameters can reduce the likelihood of an attack on the target server. While it does not offer 100% security, it is a first step in database security.
- Good knowledge of all SQL Servers on the network by administrators: First, administrators should know how many SQL servers are on the network. This process may not be as simple as it seems, as the majority of servers operate on dynamic TCP ports and usually these servers operate only when the user “needs” them. Therefore, some servers may not be active. To find all SQL Servers, SQL ping, SQL scan and more specialized software could be used.
- Continuous updates. Software companies frequently release updates to fix potential vulnerabilities. Therefore, organizations must make sure to update the applications, software, and systems they use in general to stay secure.
- Denying access to specific server ports by unknown users: It does not offer absolute security, especially against SQL injection attacks, but it is an important security measure for the entire network of a company or organization. For example, closing UDP Port 1434 [this port is used for mapping Microsoft SQL databases (Microsoft SQL monitor database)] and all TCP ports on which SQL Server “listens” can enhance security.
- Adopt strong admin passwords. Using a strong password can prevent brute force, SQL injection, and many other attacks. It is also recommended to change them frequently.
SecNews continues to investigate the incident and will keep you updated on any new developments. Administrators should immediately take down the website and conduct a forensic analysis of the attack data and all affected servers, in order to determine whether additional internal Airport information systems have been compromised, using the affected server as a jump point!
