DataBreaches.net

DataBreaches.net

The Office of Inadequate Security

Menu
  • Breach Laws
  • About
  • Donate
  • Contact
  • Privacy
  • Transparency Reports
Menu

Australia Zoo Breached

Posted on July 24, 2018 by Lee J

Australia Zoo, home of the croc hunter otherwise known as Steve Irwin is one of Queensland’s leading tourist attractions. It also attracted the attention of a pentester who has provided CyberWarNews with evidence that the main website for the zoo has been compromised.

The pentester, a Pakistani penetration tester named Touseef Gul, has previously made headlines for bypassing Sucuri. He was also called a vigilante cybersecurity expert after reporting a bug on the Irish website citypost.ie which resulted in the website being offline for many days while they checked the security of the system.

With respect to the Australia Zoo, the bug discovered is a SQL injection via POST. Touseef was able to provide CyberWarNews with a list of the tables and columns from the database. From the data provided to this site, it appears that all staff, users, campaigns, bookings, events and a huge amount of internal information would be accessible via SQL injection.

Touseef has claimed that he contacted the zoo on July 19, 2018 but got no response and saw no evidence that the vulnerability was being addressed. That is when Touseef contacted CyberWarNews, who also reached out to the Zoo’s IT department. As of the time of publication, this site had received no response from the zoo and there is no evidence that they have secured the site.

Touseef also shared various other findings, including a similar one that impacts a Sydney restaurant, and one that impacts a Nigerian university. CyberWarNews is not naming those entities at this time, even though Touseef provided proof, because this site has not yet attempted to notify them so that they can secure their data.

Related Posts:

  • Playing catch-up in Australia
  • Australia Post in online privacy breach (updated)
  • Another australian government website hacked and…
  • ABC Australia confirms data breach, target was old…
  • 600+ accounts leaked from unijobs.com.au by @BlackHatGhosts

Post navigation

← Follow-up: More than 1200 people could receive settlements after Flowers Hospital data breach
Central New York Cardiology notifies 824 patients after appointment records recovered by USPS from mail receptacle →

Sponsored or Paid Posts

This site doesn’t accept sponsored posts and doesn’t respond to requests about them.

Have a News Tip?

Email:

Breaches[at]Protonmail.ch
Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Telegram: @DissentDoe

Browse by News Section

Latest Posts

  • Proliance Surgeons notifying 437,392 patients after ransomware attack earlier this year
  • After $50 Million Breach, KyberSwap Faces Hacker’s Shocking Demands
  • Hendersonville city employees target of cybersecurity breach
  • Ukrainian gets 8-year sentence for running marketplace for Americans’ data
  • Some city data was stolen during cyber breach; full scope remains unknown, Long Beach says
  • More than 1 million Michiganders affected by Welltok cyberattack
  • Line operator says 440,000 personal records leaked in data breach
  • Ransomware group ‘Black Basta’ has raked in more than $100 million -researchers

Please Donate

If you can, please donate XMR to our Monero wallet because the entities whose breaches we expose are definitely not supporting our work and are generally trying to chill our speech!

Donate- Scan QR Code   Donate!

Social Media

Find me on Infosec.Exchange.

I am also on Telegram @DissentDoe.

RSS

Grab the RSS Feed

Copyright

© 2009 – 2023, DataBreaches.net and DataBreaches LLC. All rights reserved.

HIGH PRAISE, INDEED!

“You translate “Nerd” into understandable “English” — Victor Gevers of GDI Foundation, talking about DataBreaches.net

©2023 DataBreaches.net