Google News fooled and spammed by a hacked Telangana govt’s website

John Xavier John Xavier | 11-08 16:20

Google News algorithm was fooled and spammed on Friday (November 8, 2024) by a hacked Telangana government website. The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSSB) website, ‘hyderabadwater.gov.in.’ The website is used by Hyderabad residents to pay their water bills online.

It is unclear when the hack itself happened, but promotional links on betting, online rummy, and casinos began trending up on Google News under the latest news tab in the technology section earlier today. With an exception of one sub-section that highlighted Garena Free Fire MAX redeem codes, most other links were from HMWSSB, promoting gambling. The links were redirecting users to an online betting platform, betwww20.com.

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code | Photo Credit: Google News

The hack reveals the vulnerability in both HMWSSB’s website and Google News’s algorithm. While the method of the attack could not be verified, it looks like a Structured Query Language Injection (SQLi) attack -- a common website hacking technique.

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code into web forms, URL parameters, or other input fields. This is possible when the website fails to properly validate or sanitise user input before using it in SQL queries.

The spam links were redirecting users to an online betting platform, betwww20.com. | Photo Credit: Google News

SQLi can be used to delete or modify information in the database, or to extract sensitive data like usernames, passwords, and credit card details. Attackers could also inject malicious code to further compromise the website or server.

Hackers often use automated tools to scan and attack large numbers of websites. These tools can try different variations of SQL injection payloads on forms, URLs, and other input fields until they find one that works.

Published - November 08, 2024 11:52 am IST

Disclaimer: The copyright of this article belongs to the original author. Reposting this article is solely for the purpose of information dissemination and does not constitute any investment advice. If there is any infringement, please contact us immediately. We will make corrections or deletions as necessary. Thank you.


ALSO READ

LG Energy Solution secures 5-year deal to supply EV batteries to Rivian

LGES said its 4695 cylindrical battery cells are gaining popularity thanks to their larger capacityS...

GM ending production of Cadillac XT4 SUV as it shifts to electric vehicles

GM plans to end production of its Chevrolet Malibu this month.General Motors said on Thursday it wil...

Ashok Leyland reports 37% PAT growth in Q2 FY25, driven by strong domestic and export performance

Ashok Leyland's export volumes for the second quarter reached 3,310 units, marking a 14% increase. A...

What is fuelling M&M’s growth even as the auto sector is slowing down? Anish Shah explains

Mahindra Group CEO and MD Anish ShahAnish Shah, Group CEO & MD, Mahindra Group, says what is hel...

IIT-I's innovative thermal management solution for EVs

Prof Sahu said that the impact of this innovation reaches far beyond EVs.IIT Indore has developed a ...

China's car sales jump in October as automakers rush to meet annual goals

The biggest Chinese rival to Tesla has achieved 81% of its revised sales target for this yearChina's...