HomeInvestigations Website alteration at the Decentralized Administration of Crete

[EXCLUSIVE] Website change at the Decentralized Administration of Crete

Decentralized Administration in Crete

 

 

 

 

 

 

 

 

 

A website was hacked and a message was posted to the Decentralized Administration of Crete, according to information brought to the attention of SecNews. As reported by SecNews associates, a Brazilian hacking group called “Slayers Brazil HackTeam” carried out a cyberattack by exploiting a vulnerability on the website of the Decentralized Administration of Crete.

The Decentralized Administration of Crete, as established in January 2011 by the Kallikratis Programme, includes the four prefectures of Crete (Lassithi, Heraklion, Rethymno and Chania) headed by the General Secretary.

The basic responsibilities of the ADC as it emerges from its Structure and consequently the data it manages mainly concern administrative issues of internal operation and control, spatial planning, environmental, water, agricultural, forestry. There is also data on issues related to civil protection, but also data of various content that have arisen from the various European Programs in which the ADC has participated.

The website https://www.opencrete.gov.gr/ , which was targeted by the “Slayers Brazil HackTeam”, has been designed to be constantly updated with data from more and more Public Administration bodies, while it is constantly enriched with additional functionality.

The Brazilian hackers “Slayers Brazil HackTeam”, of low cognitive level (as we found out through relevant research), possibly using a weakness of the website, proceeded to post their logo/message as shown below. We speculate that some weakness of the CMS or the website in general, allowed them to obtain administrator rights or rights to change the records displayed. The website that was altered is the internal website https://www.opencrete.gov.gr/group:

Opencrete.gov.gr: Αλλοίωση ιστοσελίδας στην Κρήτη
Αλλοίωση εγγραφών στην ιστοσελίδα του opencrete.gov.gr

The group of Brazilian hackers (of low cognitive level, as we mentioned above), directed their “electronic” fire against Greek targets either by chance (using automated tools that identified the agency’s website as insecure) or for reasons that remain unclear to this day. Since the website is in the gov.gr subdomain and within the Syzefxis network, the competent authorities must IMMEDIATELY take action and check the website.

syzefxis

As we have mentioned many times in the past, Syzefxis as a provider DOES NOT essentially bear the responsibility for managing the servers of each entity, but simply provides the means of access.

Comprehensive measures must be taken to ensure that at least the entities managing sensitive personal data draw on expertise from the Syzefxis management staff, who are properly trained and tasked with security issues.

cyber-crime-hackers-arrested

The competent administrators of the Decentralized Administration of Crete must IMMEDIATELY take the necessary measures and repair at a technical level the weaknesses that hackers used to gain unauthorized access.
The server that is indicated to have been attacked must be placed off the network and thoroughly analyzed for digital evidence, in order to identify the exact way the intrusion was carried out and to expel the attackers in case they have penetrated other servers in the network under investigation.

Stay tuned to SecNews, the reliable 24-hour information website on information systems security and cyber breaches.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS