Inside Scoop Breaking News Video Blog Index Participate Humor
Home Bullet Points Philippines' health department website hacked
+ Follow Me

Bullet Points

Tonyo Cruz

Location: Manila, Philippines

My Posts | My RSS feed


Philippines' health department website hacked

Philippines' health department website hacked
+ enlarge
Dec. 19 2009 - 12:01 am
View comments (74)

1

16


[UPDATED] The website of the Philippines' Department of Health was hacked last night, with the offender naughtily placing penises on a photo of the country's health chief where he supposedly demonstrates that paper horns are better and safer than firecrackers to herald the new year.

The photo supposedly shows Health Secretary Francisco Duque III blowing a paper horn which was replaced by a bunch of penises.

There appeared to be no signature or note left by the hacker.

The hacked page was made to look like this:

DOH website hacked

The page contains a press release on Duque's reminder to the public to stay away from firecrackers which kill and injure hundreds each time Filipinos welcome New Year's Day. Duque also recommends a ban on dangerous firecrackers.

The hacked page was also visible in the frontpage of the department's website.

Front page of hacked DOH website

Minutes after this report was published, administrators took down the hacked photo and replaced it with the original:

This was not the first time hackers penetrated Philippine government websites.

Last January 3, 2008, hackers redirected three government websites to the website of theme park Enchanted Kingdom.

These were the Department of Justice, the Philippine National Police Criminal Investigation and Detection Group, and Information Technology and Electronic Commerce Council.

Ironically, the DOJ and the PNP CIDG are major parts of the Philippines' criminal justice system. Although then-Justice Secretary Raul Gonzalez ordered an investigation, nothing was heard on the outcome of the probe.

The 2008 incident apparently poked fun at a speech by President Arroyo where she enjoined Filipinos to join her in traveling to Enchanted Kingdom or a First World Philippines in 20 years.

Thanks to @tjmanotoc on Twitter for the heads up.



  Comment It |     |    Email it    Print it   


Related Stories


TIM pulls out from SMARTMATIC, endangers Philippines first automated elections in 2010 (story by Pinoy Buzz)
Philippines mudslides, floods kill estimated 100 people (story by Breaking News)
Storm drifts away from Philippines (story by Breaking News)
Online uproar exposes Philippines relief aid fiasco (story by Bullet Points)
Suspected Korean gangsters killed in the Philippines (story by Flying Yangban)
Pacquiao Watch: Money versus money (story by Chronicles from Mindanao by a Mindanao Journalist)


Comments



by Vincent Isles
on 12/18/2009 04:52 pm

Just for the record, the DOJ website was not hacked in January 2008; it was a simple misconfiguration. I've informed the DOJ admin of the problem as early as Nov. 2007, but there was no action.


by Bruce Lee
on 12/26/2009 05:52 pm

anong di naHack? LoL......baket kailangan mo inform? pabayaan mo sila ng magising gising sila pag na homepage defacement sila ulet


by Peter
on 12/27/2009 03:20 am

panibagong ad campaign nila ni "Dick" Gordon


by The Dreamer...
on 12/28/2009 01:41 pm

Does anyone knows who did the click?.... lols I know one...


by Peter
on 12/28/2009 08:07 pm

meron pa din

www doh gov ph /bosesngmasa


by stupid IT
on 12/29/2009 04:28 pm

Wtf backdoor???? daw sabi ng IT? obyus naman na login yan....ang stupid naman kasi kung sino man yung user nila na "password" nya ay "password"


by md5_sha1
on 12/29/2009 05:00 pm

bwahahahaha!!
that IT sucks!
don't they know how to check the exploits and vulnerability of their site....




by {e_e}
on 12/29/2009 06:11 pm

kung babaguhin man yung page bat ilalagay pa banner ng DOH at kung ano anong abubot.....LoL nakakahiya IT nila


by Tambay
on 12/29/2009 07:16 pm

Sa tingin nyo ba IT ba talaga ang nag papatakbo nyan? Baka naman Family business ni secretary ang nag papatakbo nyan, na wala naman talagang experience sa larangan ng IT.

^,.,^


by DoctorED
on 12/30/2009 09:24 am

ang tanong....yung hacker baka taga DOH mantakin mo twice na


by nerd
on 12/30/2009 03:11 pm

ang alam ko di naman talaga IT ang mga nasa web nila, kawawa naman. hehe


by DoctorED
on 12/31/2009 06:15 pm

Kung di IT mas nakakahiya...hahaha


by capo
on 01/01/2010 04:14 am

http://websecurebycapo.blogspot.com/



by N. "payroll jobs" Reeves
on 01/05/2010 06:53 pm

The cyber-security in Philippine government offices is outrageous.


by Anonymous
on 01/05/2010 07:56 pm

parang ibig sabihin d2 ng hacker na madaling pasukin ang inyong system... paki inform i2 sa it head nyo... para ayusin


by Anonymous
on 01/05/2010 08:24 pm

Mga bobo ang mga taga gobyerno...


by vin
on 01/05/2010 08:32 pm

LOL! yun lang masasabe ko, jusko naman 2006 pa ren yung footer nila hangang ngayon... :-l Lax kasi masyado web security mga government website eh yan tama yan para matauhan sila na mag update


by LoL! Guyz
on 01/05/2010 09:45 pm

Gawa din ng IT nyo yan, namali lng ng file name nung picture na na post. Pinalabas na nahack. LoL!


by passer_by
on 01/06/2010 12:28 am

bka school project lng yang website na yan at gnwa ng official website ng doh..tipid, lol..kahiya nman...


by Anonymous
on 01/06/2010 08:16 am

puro kasi low budget mga website ng gobyerno kasi binubulsa nla!!sana ang hinahack nla ang sa BIR! hahaha LOL..i think Drupal CMS gamit nla sa DOH website.


by Anonymous
on 01/06/2010 08:46 am

tama lng sa knila ksi kung sino sinong mga kamaganak lng ang ina appoint para maging it.....hahahaha



by suPotmAdnEsS
on 01/06/2010 09:21 am

Francisco Duque III deserves this kind of treatment. One of the wannabe in our government. Always showing his freaking face pretending to inform us about health issues like viruses, stopping the use of fireworks but at the other side of it, he's just campaigning himself. It's like hitting two birds in one stone.


by reiluke
on 01/06/2010 02:13 pm

dude ang luma bulok websites nyo, halos lhat .gov sites eh sqli vulnerable, xss infested, noobs nyo wag na kayo mag tayo nang websites

basta pinas bulok


by nytsmasher76
on 01/06/2010 05:20 pm

Hmmm,

Better hosting for our national websites PLEASE... This might also be a "dress rehearsal" for a massive online attack this coming May... to foul-up election results...

Take a pick among the circulating "failure of elections" scenarios, anyone?


by Anonymous
on 01/06/2010 09:34 pm

galit siguro kay duque yung hacker. mapapel kasi itong si duque. kung napanood nyo sa tv yung mga sinusunog na baboy na tinamaan ng ebola virus sa bulacan, si duque ang nakaharap sa media at nagpapa-cute sa halip na ipaubaya na nya dapat yung interview sa mga kasama nya dun sa site na mga doktor sa hayop na taga bureau of animal industry na sila mismo ang nakakaalam ng tungkol sa kahayupan at sila mismo ang aktwal na nagtatrabaho sa pag-euthanize. kulang ba o sobra sa pansin si sec. duque?


by Anonymous
on 01/06/2010 10:30 pm

mahina IT ng mga government site ...
kesa kasi mga class A na IT ang kukunin ...
eh mga fresh grad na kaya lang nilang utuin ...
less budget ... more personal kaban ng cash ...


by DoctorEd
on 01/06/2010 11:56 pm

Hahaha alam nyo ba na di lang pala twice nahack DOH 3 times nung December pinagtitripan nalang ata mga admin nila, nabasa ko sa newzaroundus . com


by Anonymous
on 01/07/2010 09:36 am

Masyadong kumpante ang goverment.Ang hilig kasi gumamit ng common na password kaya dali mapasok.No brainner na yan kahit newbie kaya ng pasukin yan.Puro ftp lang upload niyan.Sobrang katamaran kasi yan.


by Dr Doh!
on 01/07/2010 11:20 am

Napansin kong ang mga na-hack na websites ay gumagamit ng Drupal at Joomla CMS. Alaeh! Dali palang i-hack ang mga to.


by Comsci Student
on 01/07/2010 11:24 am

for me ang pag kakaalam ko hini naman po kase pinag 22onan ng pansin ng goverment natin ang mga IT hindi naman po talagang mga pro ang kinukuha nila....

nag try na me mag OJT sa goverment isa lang napatunayan ko mas magaling pa ang student kase sa IT nila


and "failure of elections" malabo po yan khit palit palitan man nila ang website iba pa din yng WEBSITE sa database



by ezekiel tuando
on 01/07/2010 12:16 pm

look likes need a help.. I am the hacker


by Anonymous
on 01/07/2010 01:56 pm

E pano naman kasi ang mga IT usually ng gobyerno eh accounting ang tinapos or commerce or totally unrelated sa IT. Ampf!


by
on 01/07/2010 04:09 pm

whoa....kaw po ezekiel nanghack sa DoH?


by Felix
on 01/07/2010 09:25 pm

I don't believe na nahack ang DOH. Tingin ko inside job yan. Isa pong paraan lamang siguro to para i-kondisyon ang tao na there's a possibility that systems can be hacked in the government. Who confirmed and made the findings na nahack nga? NCC ba o doctor ng DOH? :) I think matetrace nila to because of the log files kung sino ang pinakalast na nag-access and nagmade changes sa site nila kung hindi ano yun wala silang tauhan na competent to manage this.

Hindi ganito tumira ang mga hacker. Masyado kasing personal ang tira and timing malapit pa ang election.


by Anonymous
on 01/08/2010 09:41 am

Sir Felix yun nga masama eh mukhang na-edit pati log files kung makikita nyo sa newzaroundus halatang hanggang sa server may access yung hacker


by Rayes
on 01/09/2010 04:54 pm

Malamang nag lalagay ang mga powerful guys ng takot sa mga tao which is gagamit ng mga machines for the up coming automated elections. Likodkwaderno


by Tonyo Cruz
on 01/09/2010 11:14 pm

May mga tanong ako sa inyo:

1. May suggestions ba kayo sa gobyerno kung paano iimprove ang security ng kanilang websites?

2. Pwede tayong mag-apply ng kopya ng birth/marriage/death certificates, magpareserve ng business name, kumuha ng TIN, magpa-appointment para sa passport. Ano pang mga government transactions ang dapat gawin nang available online through government websites?

Sana makasagot kayo






by JB Burayag
on 01/10/2010 02:03 pm

Naku.. sobrang obvious personal yung tira... hindi ganyan mag hack un mga pro.. simple..papalitan yang buong homepage ng simpleng greetings ng grupo nila..walang ititira...dalawang posibilidad nkikita ko jan..

una, hindi yan papalitan basta basta lng kung hindi binayaran yan ng may personal n galit ky Duque pra i-upload yan photos n yan.

ikalawa, strategy yan lang pra maka-hingi ng budget para sa isang malaking IT security project, natural cut-kong n naman yan..


by hi-tech hate
on 01/11/2010 02:59 am

to improve security, stop venturing on cheap hosted services. instead, government should have their own data center where all government agencies systems are hosted.

in the case of DOH site, DOST should answer for it since the site is hosted in their system.


by JB Burayag
on 01/11/2010 02:20 pm

To create solid and strong IT infrastructure in our Government Institutions, not to mention reliable security with E-commerce services, they must hire Certified IT Professionals, who is competent in each of their respective field.

This is also a wakeup call to all our fellows in the same pool that we must update ourselves to current and latest technologies, proven with certificates, so to speak.


by Dj Jade
on 01/11/2010 06:48 pm

Felix, fyi lang, kahit mga IT ng NCC mga pulpol. Kung gusto mong makahanap ng matinong IT, wala na sila sa gubyerno.


by BaneElement666
on 01/11/2010 07:48 pm

Bakit ito nangyayari:

1st: maraming security flaws sa government site.
2nd: hindi nkakasabay ang pilipinas sa latest trends in website security. halos hindi updated ang mga website.

kahit mga script kiddie kayang i-hack mga website sa pilipinas. Ang ginamit sa DSWD is a simple sql injection.
katulad rin ng flaws sa national bookstore. Ateneo de Zamboanga is also a sql vulnerable site. there are lots of website nah vulnerable d2.

sa DOJ nman is a xxs attack, it is redirected to Enchanted Kingdom.

Ang masasabi ko lang tamad lang ang mga IT ng gobyerno kya nangyari ito. they can do some penetration on the sites they create, then improved its security kapag may nkita silang vulnerabilities.







by Pinkautumn13
on 01/11/2010 09:42 pm

... haha dpt lng un sa kanila... at mlking posibilidad nga na taga DOH ang mga hackers or mga pinatalsik nila dahil alam na ang kanilang mga kabulastugang ginagawa sa pamahalaan.


by shigishigihosto
on 01/11/2010 11:06 pm

shet! hardcore.. tingin ko, partly me point din yung hackers e.. i mean they voiced out some of our country's problems.. no offense.. and i'm not being biased.. i hope na kahit pano, makita din ng government point nila..


by Anonymous
on 01/12/2010 07:49 am

Bulok na ang teknolohiya dito....
Patapon na nga ginagamit pa kaya na-hack...


by Anonymous
on 01/12/2010 07:56 am

Babayaran siguro ng mga corrupt na pulitiko yung mga hacker para manipulahin ang resulta ng automated election....

Ma-uuso ang "poll-automated-hacking" hindi na "run-balota-run"


by Andrew
on 01/12/2010 08:01 am

@Tonyo Cruz

Kung ang flaw ay sa Content Management Sysmte (CMS), ang maisa-suggest ko ay Plone or Drupal. Medyo pareho ang implementation nila sa security but mas secure talaga ang Plone. Our government should invest on these open source technologies.

Visually and Usability wise, para maganda ang next launch ng mga na-hacked na site or any Government website, yung magde-design should go into the process of Information Architecture.




by Anonymous
on 01/12/2010 09:25 am

im also a webmaster on a government site but LGU...nagtitipid talaga ang mga nasa pwesto for IT matters...di nla alam IT ang nagpapatakbo ng mga income generated na systems di lng ang tao mismo...and suggest ko sa CICT na may dedicated na sana cla na host for government web apps and sites only para one line lng...den level999 ang security dapat...malayo pa talaga tayo sa ibang bansa in terms of technology. puro mukhang pera kasi ang nasa pwesto. dapat development ang pagtuonan ng pansin.


by Anonymous
on 01/12/2010 01:08 pm

tama malayo pa tau sa ibang bansa in terms of security..

Pero ang mahirap ngaun, kahit gaano ka secure ang isang website, pede pa rin itong mpenetrate. Sa sobrang daming pagbabago d nkakasabay ang pilipinas.




by JB Burayag
on 01/12/2010 02:14 pm

so panu yan..akala ng marami, un 2012 phenomena ang inaabangan ng marami.

un pala un 2010 election.

for sure yan, ngaun palang naka handa n un mga hackers pra sa isang showdown.

whew!




Name:

E-mail:
(optional)
Comment:

Allowed HTML tags: <B></B>, <I></I>, <A></A>
Are you human? 




designed by Fusion