The hacker defaced two of the site's subdomains to post protest messages

Apr 23, 2012 06:58 GMT  ·  By

Companies which claim that their websites are safe and highly secure are often targeted by hackers who want to prove them wrong. Such is the case of Navia Markets Ltd. India, considered to be one of the safest trading platforms in India.

Hitcher, the Pakistani hacker that defaced a number of 500 websites over the weekend, took a shot at the site of Navia, a reputable financial services company from India that specializes in the trade of stocks, currencies and commodities.

The hacker found that two of the subdomains hosted on naviamarkets were vulnerable and, to demonstrate the flaws, he altered their index webpages and set them up so that they displayed a “free Kashmir and Palestine” protest message.

Hitcher also made a video in which he showed that he managed to gain access to the databases hosted on the affected subdomains, research.naviamarkets.com and amil.naviamarkets.com.

Besides the presentation of the defaced pages and the files hosted on the affected sites, the video also contains portions of an interview given by Navia’s CEO S.K. Hozefa and its Chairman, Jawahar Vadivelu, when the firm’s online portal was launched.

In the interview, the organization's representatives highlight the fact that Navia is one of the safest trading platforms in India.

“Is this the security they provide to their users? Hope they will patch it up,” the hacker said.

Hitcher, who is part of the Pakistani Cyber Force, is known for breaching and defacing websites to post protest messages, mostly against India. However, it seems that he doesn’t want to cause any serious damage to the sites he breaches.

In this particular scenario, he didn’t provide any details regarding the vulnerability which he leveraged to gain access. Also, there is no trace of a data dump, which is a hint that he’s playing it safe.

At the time this article was written, the two subdomains were still defaced.

Here is the video published by the hacker: