Defacement of the Philippine Coast Guard Personnel Database and Reporting System
Expect no more details. We’ve decided to keep our methods in the shadows, how we get in is for us to know and for them to find out. Future…
Defacement of the Philippine Coast Guard Personnel Database and Reporting System

Defacement Alert Post by Deep Web Konek
Expect no more details. We’ve decided to keep our methods in the shadows, how we get in is for us to know and for them to find out. Future posts will document the things we saw inside, not the exploit. While we may or may not disclose specific vulnerabilities in the future, I have decided to say what vulnerability I exploited on this one.
I have exploited an unrestricted file upload vulnerability and gained initial access to the web server. I could have leaked some files, but I decided not to. Following the initial entry, a deep dive into the server’s file system revealed several critical items.
First, I was able to access the public key located at /ww [redacted] ata. This represents a highly risky vulnerability, approaching a “game over” scenario if fully exploited. Fortunately for them, I was only able to retrieve the contents of public_key. However, the same data directory also contains private_key, server_key, and several other critical files.
-----BEGIN PUBLIC KEY-----
MIIBIjANBgk [ ------- redacted ------- ] QEAyjgDSeGySFf+Z8FTsxj2
xZHzIKw0JgWbEJzs/ybx4kJg [ ------- redacted ------- ] kcMDuz0W2G
XNTsVV9cqTljyL [ ------- redacted ------- ] CY1+oN3QEhXKyeigsqAN
/m7m [ ------- redacted ------- ] uktQj7oJPMG1oiuIG1UKGH2QXOB+Fz
0ivvgvxP8eDxbuthnA [ ------- redacted ------- ] UsqoGyKb8gLbYGmp
B4iJ3UEq [ ------- redacted ------- ] ZNgzy44PcZ/8YyTc9LTXk8OrvR
rwIDAQAB
-----END PUBLIC KEY-----
Second is the contents of /etc/passwd:
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
[redacted]:x:4:65534:[redacted]:/bin:/bin/sync
[redacted]:x:5:60:[redacted]:/usr/games:/usr/sbin/nologin
[redacted]:x:6:12:[redacted]:/var/cache/man:/usr/sbin/nologin
[redacted]:x:7:7:[redacted]:/var/spool/lpd:/usr/sbin/nologin
[redacted]:x:8:8:[redacted]:/var/mail:/usr/sbin/nologin
[redacted]:x:9:9:[redacted]:/var/spool/news:/usr/sbin/nologin
[redacted]:x:10:10:[redacted]:/var/spool/uucp:/usr/sbin/nologin
[redacted]:x:13:13:[redacted]:/bin:/usr/sbin/nologin
[redacted]:x:33:33:[redacted]:/var/www:/usr/sbin/nologin
[redacted]:x:34:34:[redacted]:/var/backups:/usr/sbin/nologin
[redacted]:x:38:38:[redacted]:/var/list:/usr/sbin/nologin
[redacted]:x:39:39:[redacted]:/run/ircd:/usr/sbin/nologin
[redacted]:x:41:41:[redacted](admin):/var/lib/gnats:/usr/sbin/nologin
[redacted]:x:65534:65534:[redacted]:/nonexistent:/usr/sbin/nologin
[redacted]:x:100:102::[redacted]:/usr/sbin/nologin
[redacted]:x:101:103::[redacted]:/usr/sbin/nologin
[redacted]:x:102:109::[redacted]:/usr/sbin/nologin
[redacted]:x:103:65534::[redacted]:/usr/sbin/nologin
[redacted]:x:104:65534::[redacted]:/usr/sbin/nologin
[redacted]:x:105:113:[redacted]:/run/systemd:/usr/sbin/nologin
[redacted]:x:106:114:[redacted]:/run/systemd:/usr/sbin/nologin
[redacted]:x:107:115:[redacted]:/run/systemd:/usr/sbin/nologin
[redacted]:x:108:116:[redacted]:/usr/sbin/nologin
[redacted]:x:109:117:[redacted]:/usr/sbin/nologin
[redacted]:x:1000:1000:[redacted]:/bin/bash
[redacted]:x:1001:1001:[redacted]:/sbin/nologin
[redacted]:x:999:999:[redacted]:/usr/sbin/nologin
[redacted]:x:1002:1002:[redacted]:/sbin/nologin
[redacted]:x:110:118:[redacted]:/usr/lib/dovecot:/usr/sbin/nologin
[redacted]:x:111:119:[redacted]:/nonexistent:/usr/sbin/nologin
[redacted]:x:112:120:[redacted]:/var/lib/rspamd:/usr/sbin/nologin
The third is the contents of /etc/group:
[redacted]:x:0:
[redacted]:x:1:
[redacted]:x:2:
[redacted]:x:3:
[redacted]:x:4:[redacted]
[redacted]:x:5:
[redacted]:x:6:
[redacted]:x:7:
[redacted]:x:8:
[redacted]:x:9:
[redacted]:x:10:
[redacted]:x:12:
[redacted]:x:13:
[redacted]:x:15:
[redacted]:x:20:
[redacted]:x:21:
[redacted]:x:22:
[redacted]:x:24:
[redacted]:x:25:
[redacted]:x:26:
[redacted]:x:27:[redacted]
[redacted]:x:29:
[redacted]:x:30:
[redacted]:x:33:
[redacted]:x:34:
[redacted]:x:37:
[redacted]:x:38:
[redacted]:x:39:
[redacted]:x:40:
[redacted]:x:41:
[redacted]:x:42:
[redacted]:x:43:
[redacted]:x:44:
[redacted]:x:45:
[redacted]:x:46:
[redacted]:x:50:
[redacted]:x:60:
[redacted]:x:100:
[redacted]:x:65534:
[redacted]:x:101:
[redacted]:x:102:
[redacted]:x:103:
[redacted]:x:104:
[redacted]:x:105:
[redacted]:x:106:
[redacted]:x:107:
[redacted]:x:108:
[redacted]:x:109:
[redacted]:x:110:
[redacted]:x:111:
[redacted]:x:112:
[redacted]:x:113:
[redacted]:x:114:
[redacted]:x:115:
[redacted]:x:116:
[redacted]:x:117:
[redacted]:x:1000:
[redacted]:x:1001:
[redacted]:x:999:
[redacted]:x:1002:
[redacted]:x:118:
[redacted]:x:119:
[redacted]:x:120:
[redacted]:x:1003:
I decided not to fully disclose everything I found inside. Rest assured that I did not cause any serious harm to the government website of the Philippine coastguard.
Another significant finding was that I was able to view certain configuration files within the website. In particular, I managed to access and retrieve the contents of the loaded PHP configuration file, php.ini. This file is critical to the server’s operation because it defines how PHP behaves on the system, including security settings, file handling, execution limits, and other runtime configurations.
I also discovered that I had the ability to modify the website’s .htaccess file. This is particularly critical because .htaccess controls important server-level behaviors such as access restrictions, redirects, request handling, and security rules. With write access to this file, it would be possible to alter how the web server processes requests and manages permissions.
This level of access could potentially allow an attacker to introduce persistent access mechanisms or other unauthorized modifications to the server’s behavior. Because of the control .htaccess provides over the web server environment, the ability to edit it represents a serious security vulnerability. Despite confirming that this access was possible, I did not carry out any actions that would compromise the integrity of the system or cause harm to the website.
메타데이터
- post_id
- c09e5d6d83cf
- slug
- defacement-of-the-philippine-coast-guard-personnel-database-and-reporting-system-c09e5d6d83cf
- url
- https://medium.com/@honksecurity/defacement-of-the-philippine-coast-guard-personnel-database-and-reporting-system-c09e5d6d83cf
- canonical_url
- https://medium.com/@honksecurity/defacement-of-the-philippine-coast-guard-personnel-database-and-reporting-system-c09e5d6d83cf
- author_url
- https://medium.com/@honksecurity
- status
- ok
- fetched_at
- 2026-06-21 15:33:18