Thursday, July 21, 2016

Wooyun,the most famous white-hat vulnerability disclosure website in China, forced to shut down

On July 20, Wooyun, the most famous white-hat vulnerability disclosure website in China cannot be accessed. Later in the day, the site posted a bizarre notice saying that Wooyun system is undergoing some update and that people should listen to Wooyun rather than rumors. 


As most Chinese know, system update or system maintenance very often times mean that the site is shut down temporarily or permanently by the government.  Rumors are the high level management of Wooyun were taken away by the police. Such rumors are censored on the sites such as Zhihu. 

But the reason for it is not clear and there are several guesses. 

Information analysis platform in the public security bureau 

On July 19, someone submitted a vulnerability regarding arbitrary code execution in the analysis platform of 公安部一所 (Ministry of Public Security research institute) 

The Baidu cache is reset by GFW indicating some possible government action

SQL Injection on the United Front Work Department

On July 18, someone submitted a vulnerability regarding SQL Injection of 中央统战部 (
the United Front Work Department.) 

This vulnerability disclosure page is not index by Baidu, indicating possible censorship.

SQL injection on Center for Disease Control and Prevention and hospitals in Beijing

On May 20, someone submitted a vulnerability regarding SQL injection of 北京疾控中心 (Center for Disease Control and Prevention and hospitals in Beijing). The hacker has obtained sensitive data on various hospitals as shown below.






Vulbox, another famous platform has stopped to receive new vulnerabilities. 







3 comments:

  1. This information is very impressive. I hope this can bring more information to the readers, including me. Thank you for your work Speciaali

    ReplyDelete
  2. You have done a great job. I will definitely dig it and personally recommend to my friends. I am confident they will be benefited from this site.
    Speciaali

    ReplyDelete