Hacking Incident #372: Southeast Sulawesi Province (rsjpdo.sultraprov.go.id) Hacked by X7EXPLOIT

Incident Date: September 13th, 2024 20:59:28 (WIB)

The website of Southeast Sulawesi Province (rsjpdo.sultraprov.go.id) was hacked by X7EXPLOIT from the RISXPLOIT hacker group. The attack occurred on September 13th, 2024 at 20:59:28 WIB.

Hacker Details:
Hacker Name: X7EXPLOIT
Hacker Group: RISXPLOIT

Website Details:
URL: https://rsjpdo.sultraprov.go.id
System: Linux
Web Server: Nginx
IP: 103.94.11.34
Location: Indonesia

The hacker employed a brute force attack to compromise the website. Brute force attacks involve systematically guessing passwords or credentials until the correct combination is found. This method is commonly used to bypass authentication mechanisms when weak or easily guessable passwords are in place, allowing the attacker to gain unauthorized access.

The attack was politically motivated. The hacker may have targeted the website due to ideological differences, dissatisfaction with government policies, or to protest political issues related to the Southeast Sulawesi Province.

The hacker left a message addressing the corruption protest, which prominently featured references to specific constitutional laws. The message emphasized the importance of legal frameworks in combating corruption.

Included in the message were the following legislative documents:

‘Undang-Undang No. 31 Tahun 1999 Tentang Pemberantasan Tindak Pidana Korupsi’
(Law No. 31 of 1999 on the Eradication of Corruption Crimes)

‘Peraturan Pemerintah No. 71 Tahun 2000 Tentang Tata Cara Pelaksanaan Peran Serta Masyarakat dan Pemberian Penghargaan Dalam Pencegahan dan Pemberantasan Tindak Pidana Korupsi’
(Government Regulation No. 71 of 2000 on the Procedures for Public Participation and Awarding in the Prevention and Eradication of Corruption Crimes).

This highlighted the hacker’s focus on promoting legal and regulatory measures against corruption.

Archive Page: https://defacer.id/mirror/id/125473
Cyber Attack Report’s Page: https://defacer.id/cyber-attack-report/125473