Reflected Cross Site Scripting Vulnerability.

Sri Lankan popular daily deal website MyDeal.LK is having a cross site scripting vulnerability. Because of the vulnerability an attacker can craft a URL that contains a malicious script to be executed on a unsuspecting victim who thinks he is visiting MyDeal.LK.

The vulnerability exists in the “deals.php?id=[id]” parameter. Where an attacker can inject a malicious script like this :”><script>EVIL SCRIPT HERE</script>

The attacker can replace the EVIL SCRIPT HERE with a malicious script that’ll look for an exploit in the victims computer that can be used to gain access to the computer, it can be used to give a drive by download to the victim or the attacker can steal information like session cookies of the admins that can be used to gain access to the website.

I’ve reported the vulnerability to MyDeal.LK. Hope they will fix the vulnerability soon. The best way to keep yourself protected is not to click on links that are from suspicious sources.

GitHub Post Here


Staying Frosty On Facebook.

We say we’re living in a digital world and how people are connected through the internet more than ever. However, when it comes to using social networking most people are still very primitive. The latest addition to this came yesterday when a teacher was blackmailed on Facebook into sex by the suspect who befriended her on Facebook (News Here).

I think the reason for people to act differently online than in real life is a very complex one, social networking has only been here for like 10 years and most people on Facebook have been there since 2008 or later so most probably they’ve been social networking for only 4 years or less. It’s a new thing for all human beings and people have failed to understand the differences and similarities in real life and life online.

  • What makes people not to share their photos with everyone in real life while sharing them with everyone in the world on Facebook?
  • What makes people not be friendly and talk with strangers in real life while people accept every friend request on Facebook without even knowing that person exist in real life?and believe what they say.
  • What makes people not to share their private information in real life while they share everything what comes to their mind on Twitter?
Some good comments on the article “Teacher blackmailed into sex on Facebook” : 

I think people, specially children needed to be taught how to be safe on social networking and internet safety practices before they starting to use internet as we do with other things in real life. However, the fascinating thing is because internet and social networking has been there for a very short time it’s a new thing even for parents, and parents themselves don’t know how to be safe when it comes to being online.

I think I was lucky in that way because I started learning about computers and internet when I was 10 (I didn’t have my own computer, I got my first when I was 12) and I read the news and stories about how people got into trouble thanks to the internet. And when I got my own internet connection in 2010 when I was 20, I know how to protect myself on the internet and for me so far so good.

Being blackmailed into sex on Facebook is not the only thing that can happen to a person, there is an increasing trend where beautiful photos of girls are being posted on popular forums and sometimes even on porn forums, which can affect you for the rest of your life. These photos are then being used by other people in making fake profiles under fake names.

It’s amazingly simple for a fake profile on Facebook to get information from someone that they normally don’t share in real life, from mobile numbers to personal stories. Specially if you use a female profile it’s really easy to get information from both males and females alike.

This video on from Tom Ryan shows how easily how got access to military classifid information by using a fake profile called Robin Sage  : Tom Ryan | Palantir Technologies

There is another danger that you don’t understand in adding unknown people on Facebook. You can hack ANY, YES ANY Facebook account, if you can add 3 profiles in to your target profile. I won’t going to reveal the process, but trust me it’s very simple to hack any Facebook profile if you can slip 3 friends.

How to stay safe : 

  • Try to stay anonymous as possible, don’t even give your real date of birth to Facebook, Facebook only need it to confirm you are above the age to have a Facebook account.
  • Don’t add unknown people on Facebook, if you do make sure they don’t see personal stuff you post on Facebook.
  • Always use two factor authentication, so it’ll make your Facebook account almost always bullet proof. You can activate two factor authentication from the security settings on Facebook.
  • Don’t post any photos of you on Facebook, and it’s better to not to let others take photos of you if they are going to post them on Facebook.
  • And importantly learn how to be safe online before you jump into it.

Flame, Another Weapon of Industrial Cyber Warfare.

My Twitter Timeline is full news about the discovery of the malware called Flame, which was found mainly in Iran and some other middle east countries. This is also another malware targeting particular countries and used for espionage which has some unique features that separates it from other malware like Stuxnet, and Duqu and some features that resembles them.

  • It is a backdoor virus, a trojan virus and also a worm combined, it spreads mainly via USB devices and through networks.
  • It has a complete malware, it can record audio from the mic of the computer, take screenshots and also log key presses and send them to the command and control center. Although there have been malware with such features this is the first  malware to have all these features.
  • Flame malware is large which is 20mb, where most of the malware that are found these days are mostly smaller in size.
  • The malware is highly complex, it has multiple compression and encryption methods to be used for the data sending to the command and control servers.

According to researchers it has some features common to Stuxnet, which targeted nuclear power plants of Iran, Flame is also used for industrial espionage and use the same vulnerability in Windows to infect. This is another example for cyber attacks targeting governments and high-profile targets of countries.

It’s not hard for one to imagine that an average person or a group, because :

  • An average coder or a group can’t create malware with such complexity. It requires a group of highly talented group of people specialized in designing such malware which only very few countries in the world possess.
  • An average person or a group has no need of such a malware to spy on Iran and other Middle Eastern countries other than another country who are keen to keep an eye on Middle East, and only few countries have talent to build such a malware, like US, Israel or China who are famous for its hacking capabilities.

As this article from Reuters points out,

It is the most complex piece of malicious software discovered to date, said Kaspersky Lab security senior researcher Roel Schouwenberg, whose company discovered the virus. The results of the Lab’s work were made available on Monday.

According to Kaspersky the Flame malware has gone undetected for five years which is a pretty long time and if someone or a country can build such a tool five years ago. One can imagine how complex these industrial malware have evolved now, and the tech skills of the builders of Flame could have achived by now.

This also makes a question that how many unknown cyber operations are currently out there happening around the world done by countries, and cyber capabilities of other countries. Because, malware like Duqu, Stuxnet are not malware that are not made and being used by ordinary hackers. According to my friend @ipv10 who is a web researcher herself looking at the distribution and capabilities required to build such a malware the origin of the malware should be non other than USA.

If you are skeptic about cyber warfare, it has already begun. And when other countries are moving fast in the direction of arming themselves with cyber weapons inducing India, all we are doing is hunting perverts on Facebook, time for us to move on improving out cyber capabilities.

You can read Kaspersky’s blog post of comprehensive explanation of Flame malware :

How China Is Spying On Your Computer.

It’s not a new thing that Chines mobile firms like ZTE and Huawei are famous for helping the Chinese government to gather intelligence from around world, helped China to engage in intellectual property theft from leading companies, and the data that were being gathered by ZTE and Huwawei devices helped in Chinese hackers in breaking into important places. It’s a known thing now that ZTE and Huwawei devices are now banned in companies in US and other foreign countries. So what’s the state in Sri Lanka?

Today morning I came across this article at Groundviews, which in their post titled Are Chinese Telecoms acting as the ears for the Sri Lankan government? point out some of the facts that most people in the country don’t know about the connection between ZTE, Huwawei and Sri Lanka. As they point out :

  • Both ZTE and Huawei have signed contracts worth tens of millions of US dollars with governments in Central Asia, not known for their democratic credentials.
  • The telecoms products (like USB dongles) and possibly even services  (including underlying network technologies and infrastructure) aid espionage.
  • Major telecom providers in Sri Lanka have multi-million dollar contracts with ZTE and Huawei.
  • In fact, the overwhelming majority of mobile broadband internet access devices sold in Sri Lanka by Mobitel, Dialog Axiata, Etisalat and Airtel are made by either ZTE or Huawei. Even I am using a Huwawei device which I bought from a Mobitel outlet.
  • In June  2011, it was reported that “Sri Lanka Telecom (SLT) has awarded a long-awaited LKR3 billion (USD 27 million) fibre-optic network rollout contract to China’s ZTE Corp as part of the national ‘i-Sri Lanka’ project”.
  • Mobitel signed an agreement (May 2011) with the country’s Board of Investment for equipment import duty exemption on its LTE network deployment in partnership with another Chinese vendor, ZTE.
  • Huawei maintains a 33% sector share of existing infrastructure maintenance.
This classified cable from the US embassy that was released on Wikileaks show how ZTE and Huwawei are expanding in Sri Lanka :

Chinese firms continue to make inroads into the Sri Lankan market, including into areas such as telecommunications infrastructure.  The Sri Lankan telecommunications market has expanded rapidly, and telephone companies plan to expand into the newly freed conflict areas of the North and East.  Huawei Telecommunications, a Chinese owned corporation, has worked diligently to corner the telecommunications infrastructure market in Sri Lanka.

Huawei maintains a 33% sector share of existing infrastructure maintenance.  Alcatel-Lucent and Ericcson are the two other major competitors, and each has a 33% sector share of existing infrastructure maintenance.  Another Chinese company ZTE has a tiny 2% marker share.  Huawei Sri Lanka is expanding aggressively into the new infrastructure market in the North and East, where they own more then 75% market share.  Alcatel-Lucent and Ericcson are not major players in the new infrastructure market, and they seem disinterested in increasing their market share.

Yes, it’s acceptable that because we don’t make our own devices like USA, we don’t have any other option other than go for the cheap Chinese products, however it’s a scary that from the device we use to access the internet and the technology in the country is provided by Chinese companies that are famous for spying and aiding Chinese government hacking attacks.
Some experts say ZTE and Huwawei is worse than Stuxnet and according to some there are direct connections between Chinese companies like ZTE and Huawei with Chinese hacking attacks on US companies like US defense contractors and US military officials.
When it’s not only the devices but the whole internet structure in the country has been built by Huawei and ZTE there’s almost no escape, they might be spying on us even this very moment. Although I don’t agree with what Groundviews say most of the time, I have to appreciate them for giving these stats that most people don’t know. If you are worried about a Chinese invasion, they are already here.

Sri Lankan ISPs Block Access To Piratebay and Pastebin.

Looks like Sri Lankan Internet Service Providers are blocking access to popular torrent tacking website The Pirate Bay (thepiratebay) and popular code sharing website

The Sri Lanka Telecon has blocked access to Pastebin and The Pirate Bay for two days/ The Indian ISP AirTel has blocked access to torrent websites like The Pirate Bay and for few weeks now.

It’s not sure why Sri Lanka Telecom is blocking access to patebin, however looks like not all Sri Lanka Telecom subscribers are affected, according to some pastbin is still accessible and takes a very long time for the page to come up. Pastebin is a website designed for code sharing, however now it’s widely being used by the Anonymous hackers  as a place to post their hacked data. So is Sri Lanka Telecom blocking access to pastebin because Anonymous hackers posting hacked information? There is no any other reason than that to block pastebin.

Looks like The Pirate Bay is also being blocked by Sri Lanka Telecom, the real reason for this is still unknown, there has been no press release or anything like that. Sri Lankan Telecom might be blocking Piratebay because of piracy issues, and people must not forget that Piratebay is also a place where Anonymous hackers release their hacked information.

@CrazyNalin @RukshanR @tpb TPB is banned from Airtel too. torrents . eu and some more too. Many people are having difficulties in accessing
— Madhu (@ipv10) May 20, 2012

However for non Sri Lankan Telecom subscribers pastebin and The Pirate Bay (for non AriTel subscribers) is still freely accessible.

Did Sri Lankan Telecom block patebin because of Anonymous hackers? I’ll update this post as I find more information.

However, if you know the ways it’s pretty much easy to bypass these blocks by using proxies, VPN, or my favorite TOR. Meanwhile in Pakistan Twitter has been blocked by the Pakistani Telecommunication Authority, looks like today is a sad day for freedom on the internet.

Jester, More Questions Unanswered Than Answered.

After all the drama and series of posts about AnonymousLK, I decided to write a post that I was thinking to write for a long time, a post about “The Jester” (th3j35t3r).

Basically Jester is a “patriotic” hacker that launches denial of service attacks on Jihad terrorist websites. If you are someone wondering who’s jester, the wikileaks page about Jester and this blog post about jester gives all the information you need to know about jester’s history from the beginning.

Before writing the post I have to say, I’m not a supporter of jester, nor I’m against him, I’m just an observer on the internet and looking online drama eating pop corn. However I am against Anonymous.

The thing I’m happy about jester is going after the Jihadi websites and taking them down with his DoS tool XerXes, according to Sam Bowne XerXes is most likely a modified SlowLoris tool. Well I’m not going to talk about Jester’s history and what’s he doing, I thought of writing this post after seeing what’s happening with Jester recently.

Jester’s famous quote is,

There is an unequal amount of good and bad in most things, the thing is to figure out the ratio and act accordingly.

I think same can be said about Jester, there is an unequal amount of good and bad in him. Jester has a good side and a bad side, the bad side of him is making people leave Jester and made me write this post.

Some of his former IRC channel ops and some of former Jester fans have now formed a separate movement called ReaperSec that’s heavily criticizing Jester. You can read their blog at

First of all Jester lies more than he should, and takes credit for what he has not done, as reapersec points out on their blog post :

  • Modified LOIC to expose users IP – Never happened, unknowing users where exposed by default.
  • Infected distributed to Anonymous – Never happend, AnonymousDown found the file, th3j35t3r asked Tyrkoil to write his blog post claiming that he (th3j35t3r) had modified the file.
  • Anonops Anope Services dump – Didn’t directly take credit, but did refuse to give credit to individual who performed the hack. Originally performed by HackThePlanet if I recall.
  • DoS’d LulzSec’s Server – Again, never happened, this was later confirmed by Matthew Prince, CEO of Cloudflare, during Defcon 19.
  • Tripoli Post hack – Used a known vulnerability as XSS (Cross-site scripting) to inject a photo that looked similar to an actual article. (Target Site | Image Source | XSS Effect) This will only work if you use the link he provided. No, he didn’t actually hack into the Tripoli Post web servers.

This also includes the TeamPoison arrests. Yes, Jester went on a exchange of words with Trick of Team Poison, but it was actually LeRes that did the important part in identifying the members of Team Poison, however it was jester that really took credit for what LeRes has done.

The QR code hack of Jester :

Yes, when I first read the post about the QR code hack I was like OMG (yes I have to admit that I didn’t went through the code until people started questioning about it), and soon after that many people started to question about the QR code hack, even the people within the jester’s IRC channel still are in doubt about the hack for many reasons,

  • How did jester use an exploit  in webkit to hack in to Android and iOS devices that was patched back in 2010?
  • You need two shell codes for Android and iOS devices, Jester’s code lacked platform detection, and how he used a single shell to hack both iOS and Android devices is still a big problem.
  • The data that jester said he got after the QR code hack which he said he’s going to publish was never published.
  • Some of the people that said who scanned the QR code has actually never scanned the QR code.

Although the Wikipedia page about Jester say that he released an encrypted version of the data from the QR code hack I talked with someone from the jester’s IRC and I couldn’t find anyone who has actually seen the data (from the people I talked at his IRC and people elsewhere on the internet), and although Jester said that he sent the data to the FBI, according to people at his own IRC it’s another big lie.

You can read a more technical explanation about why the whole QR code hack is a fake from these two explanations by ReaperSec:

Where is Saladin :

If you don’t know Saladin is the new mysterious tool by jester that is capable of vanishing websites in to thin air, actually as far as most people believe a tool like that cannot exist. I even talked about this with Sam Bowne, the problem is taking a website down is possible like a mass defacement, however even if you take the website down the administrators of the site should be about to use the domain name of the website because there is no problem with the domain names. This is a question that nobody is capable of answering.

The only best explanation came from ReaperSec itself where they showed that all the domain names have been expired and the owners haven’t renewed it, and jester just made the story up about a mysterious tool called Saladin to take credit.

Duck and run when the going gets hot?

These are so many questions that are yet to be answered by the Jester, however looking at the recent happenings rather than answering the questions look like Jester is more interested in playing a Duck and run game when the going gets hot.

For example when the jester posted about the QR code hack in March, people started questioning him, rather than answering he started a fight with TeamPoison and then everybody took notice about TeamPoison and what they did, and after TeamPoison went down, everybody forgot the QR code hack and Jester didn’t answer the questions made.

Even when people started talking about Saladin, same thing happened, Jester said he was going to post a full disclosure about Saladin, but then mysteriously went dark on the day where he said he’s going to publish the post. Then came some drama from the @cubespherical twitter account saying he knows jester’s identity, people came up with different opinions of jester going dark. Jester came up few days later, bashed @cubespherical. Never answered the questions any question, the post about Saladin full disclosure never saw the light of day.

Most of my friends now believe that @cubespherical and Jester are the same, and Jester put on this online drama to cover up about Saladin.

Why is Jester strong?

I think jester is influential because of his loyal fan base, some of them are following him blindly, and although some are followers of him, they still have doubts about Jester and his capabilities and don’t believe what he’s saying about Saladin.

It’s because of these followers that help Jester in fight what’s coming at him, if it wasn’t for LeRes Jester wouldn’t have released information about TeamPoison members. Jester didn’t even properly dox Sabu.

Final conclusion?

In my opinion I think Jester is just another “grey hat hacker”  who is overly hyped on his DoS  attacks on websites, if you have the knowledge you can DoS, DoS attacks happen everyday on the web, so what’s the fuzz about Jester’s DoS? Yes, DoS attacks on Jihad websites is a good thing, apart from that what is he good at?

I think now most people are starting to realize that Jester is another DoSer that’s getting too much attention, and Jester likes getting attention, I think he enjoys getting attention. I think that’s why he’s taking credit for things he didn’t do. And put online dramas, so people will know about him. After all what has he done apart from doing DoS attacks? He’s like a thug surrounded by trolls that support him, without his fans he’s just no body.

I might be wrong in this opinion, but still I hope Jester will at least give his disclosure of Saladin, so we can see he’s telling the truth.

Action speaks louder than words but not nearly as often. – Mark Twain

Who Is This Anonymous ZonTa? ZonTa Unmasked.

Never stop your enemy while he is making a mistake

I had a different post dedicated for ZonTa which I was thinking publishing first, however I decided to rewrite the post because as the time went on more and more evidence came up about it. When I first published my post Rooting the Anonymous, ZonTa came to my blog commentingabout the post, actually he was the first to comment on the post.

ZonTa accepts Sameera is among AnonymousLK

This comment makes some interesting points, let me give it to you one by one.

  • ZonTa admits Sameera De Alwis tweets from AnonymousLK.
  • ZonTa says Sameera tweeted about the IRC channel that has no connection to them, although the chat records and screen shots clearly shows that the people in the IRC channel #srilankanz talk about AnonymousLK activities.
  • If you look at the comment made by ZonTa even a child can understand that this comment is made by the real ZonTa defending the IRC channel and to show that he has no connection with Sameera, did I anywhere in the post about Sameera have mentioned about the IRC channel? NO, so why is ZonTa panicking so much about the IRC channel?
  • And why no reply from ZonTa after us proving that people #srilankanz channel at irc.evilzone.orgadmitting that they are AnonymousLK?
  • If this is not the real ZonTa how can he say the #srilankanz channel was created 2-3 years ago?
Anyone can access the IRC channel and talk with ZonTa via : (if ZonTa is there)

So ZonTa has no connection with AnonymousLK? I’ll let you decide after this post. But before that let me give you a small story that dates back before AnonymousLK. After the filed browser xAurora, hackerzmafia got together with ZonTa who was arrested same year, and ZeroThunder to from which was another epic fail as xAurora. Remember this for now, I’ll come to this point tater.

I have to say that it’s not just their Tweet that had the irc link to the #Srilankan channel, even in the Facebook profile picture from their begging they had the irc link to the #srilankanz channel. So if ZonTa say his irc channel #srilankanz has no connection with AnonymousLK why is AnonymousLK show a link to the irc for nearly one year?

Click to see the large photo

AnonymousLK tweet their IRC

So if we go to the AnonymousLK irc channel #srilankanz at, a simple irc command is all you need to see who created the IRC channel, /msg chanserv info #srilankanz. Which gives a result like this,

ZonTa created the #srilankanz channel

This clearly shows that the IRC channel #srilankanz was created by a person named ZonTa back in 2010, which exactly mach the dates of the comment. Coincidence? You decide 😉

As you saw in the post with the chat records, we’ve been to their AnonymousLK IRC channel, and when you see the “whois” information of ZonTa (“/whois zonta” if he is online), the whois information for ZonTa is,

Whois information for ZonTa

As you can see there is a domain name associated with ZonTa, was hacking forum that was run by ZonTa until 2011, every domain name has a registration information that the person owning the domain name has to give before buying a domain name, you can hide this information if you want, which unfortunately ZonTa didn’t or forgot to hide.

Whois information for :

So we have a name and an address belonging to ZonTa, which the name is Shalika Ranatunga, and an address leading to Mirigama area. If you are familiar with the hacking incidents in Sri Lanka, the most famous hacking incident was the hacking of the Western Provincial Council Website which was back in 2009, which was done by a hacker naming ZonTa, he didn’t hide his IP and got arrested.

News article about ZonTa’s arrest :,

There is a small typing mistake in the article where the name should be Shalika Gayeshan, not Shantha Gayesha.

A student who is alleged to have hacked into the Western Provincial Council website was produced in courts today and given bail of Rs. one million by Colombo Chief Magistrate, Nishantha Hapuarachchi.

Shantha Gayesha Ranatunga from a leading school in Mirigama is alleged to have distorted facts between the Chief Minister and the Governor of the Western Province and in the process disturbed the functions of the site, the court was informed.

So is this coincident, both the WPC hacking ZonTa and IRC channel creator of ZonTa both having the same name and address, coincidence? 😉 you decide.

More articles showing ZonTa did the hack on WPC website :

Hacker Busted in Sri Lanka ( Real Story ) – ElaKiri

Community Lokuma Boruwa … ( Sri Lankan Hacker ) – ElaKiri Community

So now that we have a name on ZonTa, Shalika Gayeshan Ranatunga, googling the name will give all the information for everyone to see who’s ZonTa. I’m not going to post his social networking profiles, because I don’t think it’s not a good thing for him, he was convicted before and getting caught for hacking for second time means there is no way out for him except jail.

And I won’t put where he’s working, because I don’t like to see him lose his job, I’m not the bad guy like they’re so hard trying to be, ZonTa aka Shalika Ranatunga is responsible the of network security in a leading Sri Lankan mobile company.

However I’m going to give one profile of Shalika Ranatunga, his linked in profile. This nails the coffin on the mysterious ZonTa and shows the connection with ZonTa and Sameera.

ZonTa’s (Shalika Ranatunga’s LinkedIn Profile) :

Go to the LinkedIn profile and see what’s the “Business Website” of Shalika, guess what it’s, which is owned by the Sameera De Alwis as we’ve shown the person who create AnonymousLK, ZonTa, Zer0Tunder and Sameera started, can’t believe it? Check out the video below.

ZonTa also has a Fiverr profile which he uses the username BugFree, where he shows off his black hat capabilities to make money, he used to tweet all these things on Twitter, after we published the first post about Sameera, ZonTa was quick to delete all the tweets, but he didn’t delete his “Fiverr gigs”.

In an epic fail today, AnonymousLK tweeted this, admitting that ZonTa is their IRC friend, actually he’s not just a friend but the guy who created your IRC channel.

Anonymous admits ZonTa is their friend

That put a wrap to this mystery about who is ZonTa and completes the whole picture about AnonymousLK, anymore things I need to prove?

It’s epic that someone has commented on the Elakiri article about your arrest,

If you’re a good hacker everybody knows about you, if you are a great hacker nobody knows about you.

What now AnonymousLK, more denial? more running from truth? more screwed up theories with no facts? Still say ZonTa is not your friend?

Don’t say ZonTa and everyone are in my team, I don’t work with black hats. Hope this post refresh your memory ZonTa. Tango Down.

When are you going to hack my email Shalika? 😉 

Personal note :

Me and ipv10 were talking about ZonTa last night, most Sri Lankan hackers think that ZonTa is the best hacker in the country, which he is not. He thinks he is a good hacker which he is not, obviously he’s no more than a n00bs. Our guess was that he never expected someone from Sri Lanka will out smart them. Me and ipv10 has been in the infosec field more than you ZonTa, G2kev just stated his infosec work but is younger than you can’t even imagine.

And I’m not a hacker, I’m just a guy who does infosec work as a hobby. I’m Razor or anyone you say I am. So no more hiding ZonTa, no more false tweets. Admit it, we gotcha 😉

I think Shalika has some addiction for hacking, or else who else continue this work even after being arrested?


Update 1 :

Due to misunderstanding of some people i need explain that @g2kev is not G2 Gayan and has no connection with G2Labs of G2 Gayan. It just happens to be @g2kev‘s twitter username begins with G2, everything in this op was done by me, ipv10 and g2kev with no support from external sources. I hope this clears things out if people have any doubts. More posts to come, all in good times.

Update 2 : 

We found the deleted tweets of ZonTa asking to check website security on Fiverr, all these tweets were deleted after we posted the first post about Sameera.

Full set of tweets here : 


After a series of posts about AnonymousLK hackers their Twitter account has become private.