/>

Google News fooled and spammed by a hacked Telangana govt’s website

Promotional links on betting, online rummy, and casinos began trending up on Google News under the latest news tab in the technology section earlier today

Updated - November 08, 2024 01:30 pm IST

The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSS) website, ‘hyderabadwater.gov.in.’ [File]

The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSS) website, ‘hyderabadwater.gov.in.’ [File] | Photo Credit: Google News

Google News algorithm was fooled and spammed on Friday (November 8, 2024) by a hacked Telangana government website. The hackers seem to have exploited a vulnerability in the Hyderabad Metropolitan Water Supply and Sewerage Board (HMWSSB) website, ‘hyderabadwater.gov.in.’ The website is used by Hyderabad residents to pay their water bills online.

It is unclear when the hack itself happened, but promotional links on betting, online rummy, and casinos began trending up on Google News under the latest news tab in the technology section earlier today. With an exception of one sub-section that highlighted Garena Free Fire MAX redeem codes, most other links were from HMWSSB, promoting gambling. The links were redirecting users to an online betting platform, betwww20.com.

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code | Photo Credit: Google News

The hack reveals the vulnerability in both HMWSSB’s website and Google News’s algorithm. While the method of the attack could not be verified, it looks like a Structured Query Language Injection (SQLi) attack -- a common website hacking technique.

This type of attack occurs when a hacker exploits vulnerabilities in a website’s database query system by injecting malicious SQL code into web forms, URL parameters, or other input fields. This is possible when the website fails to properly validate or sanitise user input before using it in SQL queries.

The spam links were redirecting users to an online betting platform, betwww20.com.

The spam links were redirecting users to an online betting platform, betwww20.com. | Photo Credit: Google News

SQLi can be used to delete or modify information in the database, or to extract sensitive data like usernames, passwords, and credit card details. Attackers could also inject malicious code to further compromise the website or server.

Hackers often use automated tools to scan and attack large numbers of websites. These tools can try different variations of SQL injection payloads on forms, URLs, and other input fields until they find one that works.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.