Run a free scan to test your PC's performance now.
 

Department of Islamic Development Malaysia is hosting PayPal Phishing Site?!

Filed in: Malaysia, Security — October 7th, 2006

advertisement

I was shocked when I discovered a PayPal phishing site is hosting under Department of Islamic Development Malaysia(Jabatan Kemajuan Islam Malaysia) website. :shock:

The website: Islam.gov.my

Jabatan Kemajuan Islam Malaysia

Department of Islamic Development Malaysia site is officially developed by Malaysia government since 1996. It is using a Malaysia top-level domains — gov.my, which is exclusively for Malaysian government organizations.

The PayPal phishing site

The PayPal phishing site is hosting under http://www.islam.gov.my/online/cgi/.

Alert: DO NOT log in your PayPal account there!

PayPal Phishing site in Jabatan Kemajuan Islam Malaysia website
Screenshot: PayPal phishing site hosting under Jabatan Kemajuan Islam Malaysia website. [full screenshot]

Here are the list of phishing pages discovered:

  • http://www.islam.gov.my /online /cgi /webscr_cmd=_login-run/
  • http://www.islam.gov.my/ online /cgi /webscr_cmd=_login-run /primapagina.htm
  • http://www.islam.gov.my/online /cgi /webscr_cmd=_login-run /sysdll.php
Alert: DO NOT log in your PayPal account there!

Info: What is PHISHING?

My two cents

Since the website of Department of Islamic Development Malaysia is using exclusive domain name, chances are the website has been hacked or a webmaster build the phishing site…

I have send this to the webmaster and administrative contact. Hopefully, they will clear the phishing site as soon as possible. It is a bad reputation that Malaysia government website is hosting a phishing site…

Update: Both email delivery to webmaster and administrative contact are failed! This is bad. :(
Update: It has been fixed. Thanks to everyone who notified the related parties.

Bookmark and Share

Read also:

What do you think? 38 Responses to “Department of Islamic Development Malaysia is hosting PayPal Phishing Site?!”

Comments Feed | TrackBack URL
  1. #1
    e-tech Says:

    Now that’s strange!

  2. #2
    CypherHackz Says:

    i think gov should always be aware about this.

  3. #3
    Ady Says:

    What do you think, CF? My first hypothesis is that either:

    1. The server has been hacked
    2. A staff is doing something bad

    After all they are just another government office! I shall help by trying to inform them as well.

  4. #4
    Zealios[dot]Net Says:

    I think some hack thier server. So this remind us to be careful next time :)

  5. #5
    Palmdoc Says:

    Err… is phishing haram? :P

  6. #6
    romantika.name Says:

    [...] I visited liewcf.com today and read a fresh post about JAKIM site hosting a Paypal Phishing site. [...]

  7. #7
    Ady Says:

    @Palmdoc:

    Yes, you can say that it is haram. Especially when your intention is to steal people’s login information. Why else would you want other people’s login if not to steal money at the end.

    In conclusion, steal login is to steal money. Stealing money is a sin, and haram.

    I think we are going to have a hard time explaining phishing to these people, though. :-(

  8. #8
    Paypal Phishing Site - Hosted by JAKIM?? - WebSpeek Blog Says:

    [...] October sagech07:54 pmAdd comment I’ve just came across a post by LiewCF about (The Department of Islamic Development of Malaysia) hosting a phishing site! [...]

  9. #9
    colbert Says:

    liewcf. did you at least inform Police or MCMC?

  10. #10
    Abhinav Says:

    Strange and really surprising…to me

  11. #11
    huZmid Says:

    good work Liew

  12. #12
    zamri Says:

    I think maybe someone try to use the JAKIM website to cheating people. Someone can access to hosting probably???… I don’t know… just guesst it…. hehehe.. but for paypal user … please be carefull…..

  13. #13
    newsiness Says:

    I think this site is being hacked…and i dont think the islamic site owner will do this…

  14. #14
    uner Says:

    OMGosh, this has shock me out really..

  15. #15
    Diana Says:

    You can complain to esapa@icugov.my This email is taken from page N3 of the Star dated 7th October 2006. Though this email is to complain on late payment due for government contractors, I am sure this will get someone’s attention of what’s going on.

  16. #16
    Diana Says:

    There is a mistake in the newspaper. It should be esapa@icu.gov.my (note the dot in between icu and gov). I have sent them an email on this matter.

  17. #17
    LcF Says:

    Thanks. Let’s see how many days it take for them to delete the folder (only a few mouse clicks or keystrokes)

  18. #18
    Nicholas Says:

    what is phishing? according to my firefox 2, it says that side use to trick us to key in our personal information

  19. #19
    LcF Says:

    Read http://en.wikipedia.org/wiki/Phishing for phishing info.

  20. #20
    shah Says:

    I think that the person who has acces to jakim website is doing this. F**k la. It shame to Malaysia when we has website admin like that. Its goverment website you know.

  21. #21
    Malaysia Property Says:

    wahaha….the webmaster trying to cheat

    don’t they know is a sin to do that….DOSAAA!!!

  22. #22
    Buaya Says:

    Kene hack lar. Sila rujuk http://72.14.203.104/search?q=cache:Z8LWjlkq6EEJ:www.islam.gov.my/+&hl=en&gl=my&ct=clnk&cd=1

  23. #23
    Italia SW » Archivio » Il peggior sito di Physhing Says:

    [...] Ho appreso dal blog di LiewCF un nuovo tentativo di Physhing, questa volta ai danni di PayPal. Il sito preso di mira è niente un pò di meno che il Department of Islamic Development Malaysia ed il tentativo di Physhing è ancora in atto !! Dopo aver visitato il sito posso riportare che si tratta del peggior tentativo di Physhing visto dal sottoscritto: [...]

  24. #24
    mypapit Says:

    Shah, I don’t think that is the work of the webmaster, I think the webserver is vulnerable to crackers. And they put on the phishing site

  25. #25
    newsiness Says:

    Even Google Blog site also got hacked….
    http://googleblog.blogspot.com/2006/10/about-that-fake-post.html

  26. #26
    aku Says:

    “is phishing haram?”
    is this a real question? smells like something wrong…

    lcf, did you visit JAKIM website to learn about Islam, or did you there just for the sake of making fool of the webmaster and the gov?

    anyway, thanks for the info.

  27. #27
    cjcm Says:

    Ishhh…Fasting month also want to fish…errr…phish…

  28. #28
    Ady Says:

    I received a respond from JAKIM today, with a link to a website. I don’t want to post a link here that might cause akismet to see my comment as spam, so those who are interested you are welcomed to my blog.

  29. #29
    Lela Iskandar Says:

    I had been able to report this to JAKIM. The page is no longer accessible.

  30. #30
    aku Says:

    Refer to comment #26

    No Update From You. This is bad. :(

  31. #31
    LcF Says:

    okay, the folder has been deleted. :)

  32. #32
    fish Says:

    Hmm this is bad.After all,this brings bad reputation to jakim.(hey they should hire more computer experts to protect their system,shouldnt they?)

  33. #33
    awan yang terbang : Wake Up Ambank! Do Something! Says:

    [...] Tapi bagimana kalau aku katakan yang laman web dengan nama domain JAKIM (www.islam.gov.my) juga terlibat di dalam kegiatan phishing ini. Tak percaya? Baik kau percayainya! [...]

  34. #34
    faizal Says:

    OMG, another scam. Has somebody check the iP for the dns. If it differ then it might be the MITM attack by third party on LAN or WAN. If LAN then it’s most probably insider. but as the picture says, it’s xsripting technique it’s seem posible the outsider too. But as far as i’m concerned, many mislead has come from malaysia also but it’s also possible from another country to, just a though, i might be wrong about it. For example, curi line telefon “phreaking” Not long ago. This is scary. This is no good news for technopreneur. Now - now, i want to make money online, and now we facing a dilemma. As i’ve seen, lot of education portal and some small company from government sectors are using CMS and this is so exposed with the xcripting technique. Alas…..

  35. #35
    tqm_z Says:

    This incident wasn’t supprised me, JAKIM’s website has been reported defaced two month ago… no wonder somebody succes fully upload the files there…

  36. #36
    nurshafie Says:

    base on my experience, we aslo can creat a programme (c++ or Java) to use another domain and declare is as ours.

  37. #37
    Poobalan Says:

    well, at least JAKIM got first place in the most visited Govt website ! refer today’s (1/12/06) Star or Sun papers.

  38. #38
    ركيبكم يالمزاغيب Says:

    ( . )( . )
    ) (
    ( Y )

    WOW !! o_O

Comments are closed. Submit your comment here