Leak of confidential information

Kapustkiy Calls for Commitment from the Capital District Government’s Website

On January 14, 2017, Kapustkiy, a contributor to New World Hackers, claimed to have compromised www.gdc.gob.ve via an LFI vulnerability and to have published data on Pastebin. Security Affairs and Hackmageddon mention the domain gdc.gob.ve; other reports from the same date cover a separate list of three .gob.ve domains, so this record is separated as its own set of evidence.

Overview

Missing evidence

official confirmationIndependent forensic validation

Impact details

Security Affairs reports that Kapustkiy exploited an LFI vulnerability on www.gdc.gob.ve and that data was leaked on Pastebin. The article confirms the public report and the reference to the leak, but no official Venezuelan source has been found to confirm this.

system filesData dump on Pastebinpublic websitegovernment portalWeb server files

Classification & severity

Category
Information content security
Subtype
Leak of confidential information
Confidence
High

Security Affairs reports on a claim by Kapustkiy regarding the presence of LFI on the Capital District Government’s website and a leak on Pastebin; there has been no official confirmation from Venezuela.

Severity assessment

Medium
Functional impact
None
Information impact
Government-sensitive
Affected scope
Single system
Critical service
None
Public confidence
Limited
Recoverability
Regular

A report of a breach or data leak involving a government website has been publicly disclosed, including LFI evidence and a reference to Pastebin; however, no service disruption has been reported, and there is no official confirmation.

Data exfiltration· Confirmed Confidentiality

Timeline

Claim

Kapustkiy Calls for Commitment from the Capital District Government’s Website

Evidence & sources

2 sources