posted Sun, 12/02/2018 - 09:46
4763
Dangerous sources customer data / order data leakage
ad
Hello,
just wanted to open a thread, about dangerous sources,
sources which are not able to check the fundamental security of there customers.
The first dangerous source is
Post in their SI not here. Pale
- Bookmark
- 0
- 0
You're not doing a public service here! If you really want to help then talk to the sources themselves.
Mr Hardneck it is interesting that you act so altruistically, you seem truly to want to help people.
The problem is I just do not buy it, how ever you came across this email list, you did not do it honestly. What is your purpose here, I have been all over the world and know one acts truly altruistically , know one just shows up giving out free wisdom, that is a snake oil sales men pitch.
-You are either a source or customer out for revenge or your being paid to do this , or your extorting said sources.
-The more likely in my eyes, your a Fed or a snitch of some sort.
Who cares what you buy or not.
I pmed BFG, he will have the last word, it is not necessary that we further discuss about this, because you all seem to lack the knowledge of the simplest SQL injection, because i posted in the beginning the full path or if you like tutorial on how to exploit this vulnerability, that the owner of the source is lying streigth into your faces is not my problem and i give a shit about him. There was a reason why i have called him the first fucked up source. So wait until BFG says if me is a talker or not ;)
And stick your fucking snitch and fed into your ass where they belong to.
I'm still waiting for a PM from you.
Also would like a public explanation as to why those who should be on the list are not, and some of those who are not customers of the source are.
You make me smile Sir, how could i explain you something i don t know? I am not the source i am the one who extracted the data from his database. Nothing more. With all respect, you simply don t understand what was happening here. So i contacted the admin. But let me ask you something, is it true when a website has a database error, for example error 1064 which is very common, that it is possible on this site to extract all data from this website? Please tell me yes or no Sir.,
Correct answer, now PM me your work to verify whos DB you were hacking.
You are so arrogant ... Your pseudo knowledge is shit, it is based on a program you haven't developed yourself on samples you got everywhere from the internet. You are just reusing things and acting like a kid who thinks is god with a new toy.
So you're a hacker, ........
Haven't we seen a hacker try and extortion a source a while ago??
bingo.
Dude is obviously not a BB, My guess is he thinks a bunch of gym rats are an easy target for extortion and trickery. Mr.Hardneck you are not the first to try , you think some hacker tools you dug up on 4chan are gonna get you any where?
Anyone with half a brain knows there info is vulnerable, we are not exactly shopping on amazon around here bro. So ill ask again what exactly are you trying to accomplish?
I wanted to warn and show vulns in diffrent shops, and show how easily it is to get infos of some shops because they give a shit on security or are not able to update there shops. That was my idea in the first place.
Get to fuck twigglett
I saw the email list you posted on a file share link. So what? email lists are sold, and resold by every corporation, political organization, and spammer since the days of, "You got mail".
Great, you stumbled upon a tool and figured out how to use it. So you come on here, (and probably elsewhere), and decide to advertise it. Smart? kind of like placing a loaded unlocked pistol on the craft table at a daycare.
If you wanted to help. if there is/are "dangerous sources" here on eroids, as pale mentioned post the warning on their SI page. Work in PM and email with the source to let them know how you were able to "hack" their site and got the info you found. Be a white hat.
Smart? Don t you think when everybody who stumbles across a hacking tool is able to hack a shop, that every agency in the world can do this whenever it wants to?
No really, i thought eroids is about showing trusted shops, which for me also means safe shops, and securing the people, which means us, and not advertizing shops which make load of bugs and take a shit on us and holding everything in secret. Do you really mean it is all about a fucking hacking tool?
Sorry Greg, but you have no clue about this things, you are far away from beeing a tech guy, maybe back in the days of comodore but this time is gone. You also did not answer my PM, instead of doing it right like you are writing here, your aim is to blame me instead to help.
And you know what? i even don t want to help anymore, instead of accepting the problems and seeing it the real way, i get blamed from all sides to show this things. I have better things to do than beeing the bad guy on eroids.
But when time will come, and it will come some day, that people will got raided by cops or blackmailed by some assholes, than stfu and work on PM because nobody wants to here this kind of things here on eroids!
When you posted this I'm sure you expected people to ask questions. While this is a very serious topic it's not the first time something like this has happened. If you think your right stick to your guns. If your going to disappear on the first questions your on the wrong site. This site is real, nothings sugar coated. We've all been grilled at some point.
Dude ! I hope redactedlabs.com isn't on that list . It would be the end of eroids for sure. Id have to start shoping at censoredlabs
I accepted your friend request and you have not sent me a message. You have been on this site all day stalking my replies to you...
I understand the tools are out there for anyone to use. It is not smart to make it easy for anyone to access such a tool that is so simple even you can make it work.
Eroids is about finding trusted shops, that is true. But it is aimed more at the character of the source and the quality of their gear than the security of their websites. That being said, I'm not about to go and try and hack every website for code vulnerabilities. Heck, many of these sites are not even using secured servers.
There is a right way of going about this and a wrong way. You have chosen the wrong way. Now that you're recanting on your effort to help, even working with me in PM, you are now becoming suspect.
I am still the only one on your friends list.
You have not friended any other source.
You have not sent me a PM
You have not shared any list other than an innocuous email list
You have not provided evidence where the list came from
The list contains hundreds of emails that are not on the sources client list.
You have not posted on any of the other 10 sources SI page to call them out
I cautioned you on your actions by revealing your methods. You talk about safety but find no issue with ginning up hundreds of curious wanna be's into hacking sources for their own gain? Potentially extorting the source and other members they have a beef with? You want to come after me as having picked on you?
Do you want to put your mouth where your money is? PM me the screenshot of the code that generated that email list. If I don't see that, I'll have to conclude you are a troll.
just answer my question if it is possible.
Yes, if errors are not turned off. So now answer my questions and prove your email list came from this one particular source.
Your problem is you're taking everything as an affront. If your intentions are good, you'd want to help good sources to become better. You'd want to protect members and the source.
Instead, you are trying to pit the members against a good source. You are assisting others in "hacking" that source.
jayiskemail me @
[email protected]
didnt notice my name on your brilliant email list.
Piss off already.
Seems odd its during a promo. Honestly I'd be surprised if many on that list are actually useing there real email. I dont. Theres also a dozen Sam's on there. Anybody needs me just hit up Peter North on FB. No homo..got a gig at the nursing home later so I'll be out today. That's show buisness..
Peter North Huh. Well meet JENNA JAMESON
I'm only here for the dick pills ...nohomo : )
Same here, encrypted or not, there are so many ways to open an email account without verifying your true identity. Couple that with being on hundreds of "marketing" email lists which are compiled and sold to anybody. Even if your email was on the list, it does not prove anything.
A friend here confirmed his email adress is on this list, so this guy is definitely telling the truth...
It's good to be careful and switch it up but a couple years ago the former 1 source had a hack. Nothing came of it. I'm curious to hear who the other 9 are. We have a brand new acct who isn't new. Hes posting on the right forum headings. Knows his way around the site. I'm sure hes telling the truth but I dont think that's the whole story...
I totally agree, mate. Don't know if he just wants to help or making his own business or working together with another source, everything is possible. But to be honest, I don't care too much about his motive. He reminded us to be careful as fuck and I wouldn't order from a source which can be hacked easily...
I try to be careful but the truth is any source on here can be hacked. That's just the reality of modern day life. Some may be harder than others but even our voting system has been hacked. What amazes me are the guys on here that use there names and are on FB. Lol I've seen one with a picture of his gym buddy who is the guy in his pictures. To pathetic to even call the cat out on it...everybody gives him karma and praise on his pics. I get a kick out of it everytime.
Lol... that's really paltry
Never heard of this source “Post in their SI not here”, must be a new one lol
PcushionHey man maybe I came off a little harsh but for me on my end this is the large and small of the situation. We all know what we do. We all know why we are here. That said when one is breaking the law or living in the grey margin of legal and not you have to know there are certain risks. You also have to know how to minimize your risk. I am new to eroids but I have been getting gear from around the globe since 2007. I have received the dreaded customs letter that states “Hey we have your shit. If you want it come get it, be best not to come get it” that’s the shortened to the point version of it at least. I have gotten this little customs love note more than once. I used a great source for years they got shut down right before a package I ordered got shipped. You best believe whoever shut them down got every customers info the had on file. Out of these situations I just said well shit and kept on moving. Lucky for me even if my email does show on a list somewhere, the country I reside in wouldn’t waste their time. It’s just not worth it to them. Every order I have ever placed was nothing more than personal use and nothing that makes me look like a person of interest or a “supplier” if you will. I rest easy at night knowing even if my email or any record I have ever done online dealing trying to acquire gear there was some who purchased ALOT more than my three or four pieces of my hormonal edge . The beauty of it is that depending on how you conduct yourself you can easily blend in with the e-commerce world. That’s what I have done and will always do. That’s what so recommend everyone do. I am sure that someone here will greatly appreciate what your doing and that’s cool. For me I just accept the fact of what I am doing. To be completely honest even if I am on a database somewhere I still wouldn’t stop.
I didn’t look at the link the first go round but maybe someone more tech savvy then I could speak up to the validity of this. Pale pointed out that Greg was the tech guy so I wouldn’t mind hearing his opinion on this ether. Typically I dismiss this type of thing right off but I’m curious to how you acquired this list?
REDACTED a tool that runs on Linux and developed for this purpose.
I got an Idea, let's pave the road and supply everyone easy access to "hacker tools".
Wouldn’t be surprised if this was true but I wouldn’t be surprised if it was all rubbish. Either way it’s another lesson that we should all be protecting ourselves as much as we can.. using untraceable email accounts, addresses other than you’re home, fake names, etc etc.
I've taken the time to compare the email addys from his link with some usernames and it seems, that he could tell the truth...
Sorry, double post
Thank you, yes of course i do tell the truth. And if somebody of the Mods or eroids team wants to know more, please send me a pm. I even don t know whom to write a PM. I know and can show with proof complete databases of at least 10 shops just right now. And if not interested, once again sorry for bothering you all with this.
Like Pale told, talk to Greg. Hit him a fr, then you can send him message. Furthermore I've sent a pm to a guy, whose email addy seems to be listed in your link. I wait for his answer, if it's really his. I give you the advice not to post anymore sources names in open forums, cause it's against the rules. But you can bring it to their si pages, like you did with the last one. If this all comes out as legit, it could be very helpful to talk about it on the right places.
https://www.eroids.com/users/greg
@Pcushion i have done my homework and wanted to warn people, you don t want this kind of info and know how to check a shop for vuln, then sorry.
@tattoofreak what is weird on warning users? Maybe nothing you see every day but nothing weird.
@Protein4breakfast you are wrong it is evidence, but for people like you, which are not that much into IT like me, this kind of thread was intended. But hey, you don t want it, ok so sorry.
@KMC nr.4 yes, one of the endless possibilities ...... You want evidence and me to publish sensible data in here? Bro that was what i was going to protect you from. But if no one with knowledge of how to use CENSORED is in here, i can send a Mod or Admin the full email list of all the customers they have. I have no problem with that. But simply because somebody wants to do something positive for the people, does not mean your version 1, 2, 3 or anything bad.
But ok, if you don t like this kind of information i will not publish them anymore. But i can tell you that i know more shops where this is leaking and some shops even with orders dating back to 2012 with full ip adress name dob and so on. But cares, i better shut up. So sorry one more time
Publish away but dont bother if you cant provide proof. Nobodys gonna take your word for it. Time to put up or shut up. That's only fair...
If it is the way to go then here, all customers please find your mail https://pastebin.com/XMVYjzUU
Ok... I don't say I believe everything here, cause your a new guy and I'm always sceptical. But to be honest, it seems that this is an issue which should be checked out. Maybe you should contact the mods and discuss this via pm.
Thank you. Ok i will contact them.
Greg is the one to talk to. He is the tech guy. I just can't have you mentioning the source in the main forums. Feel free to point it out to them in their SI.
PcushionMan do your homework. If you can’t look into who your ordering from you shouldn’t be using gear to start with.
Registered 3 days ago, no friendships here and then a post like this? It's weird...
From what you posted there doesn’t appear to be any evedence of what you have accused them of so I’m not sure what you were trying to do here
This^^^
1) A reverse scammer.
2) Somebody is butthurt over losing their allowance because they used a friends address and said friends father is NOW getting swollen.
3) A TROLL.
4) other endless possibilities.