Databases of Faculdade Faveni Hacked and Dumped Online, Exposing Information on +400 Students

Earlier today, December 11th 2018, “Ergo Hacker” of Pryzraky announced a hack of Faculdade Faveni, a post graduate university in Venda Nova do Imigrante, Brasil. The hack itself was carried out in conjunction with #OpEdu, a much broader hacking operation targeting international colleges and universities which as already seen the hack/leak of Baqai Medical University in Pakistan, l’académie de Grenoble in France, San Jose State University in the US and Academia Nacional De La Historia De La Republica Argentina – among many others.

In the press release provided below, Ergo explains how he was able to breach PHP 5.5.38 file systems attached to two MySQL 5.0 databases belonging to the hostname (sv251.faveni.edu.br). Presumably exploiting the back-end of the website via SQL Injection, Ergo then managed to uncover and extract approximately 128.27 KB of data pertaining to over 400 post-graduate students, including full names, emails, CPF, tuition rates, course enrollments and much more.

Website Effected: hxxp://posgraduacaofaveni.com.br/
Full Raw Leak: https://ghostbin.com/paste/2ovuf
Database Download (128.27 KB): https://anonfile.com/X5Z3vfn1b3/alunos_xlsx

https://twitter.com/ergo_hacker/status/1072588043222167554

Published by

Brian Dunn

Writer, Researcher Owner: Rogue Media Labs | Rogue Security Labs (929)-319-2570 BrianDunn@RogueSecurityLabs.Ltd

Leave a Reply

Your email address will not be published.