hardneck's picture
hardneck
  • 2
4763

Dangerous sources customer data / order data leakage

ad

Hello,

just wanted to open a thread, about dangerous sources,
sources which are not able to check the fundamental security of there customers.

The first dangerous source is

Post in their SI not here. Pale

johnmarshall12's picture

You're not doing a public service here! If you really want to help then talk to the sources themselves.

addicted.to.pain's picture

Mr Hardneck it is interesting that you act so altruistically, you seem truly to want to help people.

The problem is I just do not buy it, how ever you came across this email list, you did not do it honestly. What is your purpose here, I have been all over the world and know one acts truly altruistically , know one just shows up giving out free wisdom, that is a snake oil sales men pitch.

-You are either a source or customer out for revenge or your being paid to do this , or your extorting said sources.

-The more likely in my eyes, your a Fed or a snitch of some sort.

hardneck's picture

Who cares what you buy or not.
I pmed BFG, he will have the last word, it is not necessary that we further discuss about this, because you all seem to lack the knowledge of the simplest SQL injection, because i posted in the beginning the full path or if you like tutorial on how to exploit this vulnerability, that the owner of the source is lying streigth into your faces is not my problem and i give a shit about him. There was a reason why i have called him the first fucked up source. So wait until BFG says if me is a talker or not ;)

And stick your fucking snitch and fed into your ass where they belong to.

Greg's picture

I'm still waiting for a PM from you.

Also would like a public explanation as to why those who should be on the list are not, and some of those who are not customers of the source are.

hardneck's picture

You make me smile Sir, how could i explain you something i don t know? I am not the source i am the one who extracted the data from his database. Nothing more. With all respect, you simply don t understand what was happening here. So i contacted the admin. But let me ask you something, is it true when a website has a database error, for example error 1064 which is very common, that it is possible on this site to extract all data from this website? Please tell me yes or no Sir.,

Greg's picture

how could i explain you something i don t know? I am not the source i am the one who extracted the data from his database.

Correct answer, now PM me your work to verify whos DB you were hacking.

RVWolf's picture

You are so arrogant ... Your pseudo knowledge is shit, it is based on a program you haven't developed yourself on samples you got everywhere from the internet. You are just reusing things and acting like a kid who thinks is god with a new toy.

KMC's picture

i am the one who extracted the data from his database.

So you're a hacker, ........

Haven't we seen a hacker try and extortion a source a while ago??

Owes a Review × 1
addicted.to.pain's picture

bingo.

Dude is obviously not a BB, My guess is he thinks a bunch of gym rats are an easy target for extortion and trickery. Mr.Hardneck you are not the first to try , you think some hacker tools you dug up on 4chan are gonna get you any where?

addicted.to.pain's picture

Anyone with half a brain knows there info is vulnerable, we are not exactly shopping on amazon around here bro. So ill ask again what exactly are you trying to accomplish?

hardneck's picture

I wanted to warn and show vulns in diffrent shops, and show how easily it is to get infos of some shops because they give a shit on security or are not able to update there shops. That was my idea in the first place.

fusebox's picture

Get to fuck twigglett

Greg's picture

I saw the email list you posted on a file share link. So what? email lists are sold, and resold by every corporation, political organization, and spammer since the days of, "You got mail".

Great, you stumbled upon a tool and figured out how to use it. So you come on here, (and probably elsewhere), and decide to advertise it. Smart? kind of like placing a loaded unlocked pistol on the craft table at a daycare.

If you wanted to help. if there is/are "dangerous sources" here on eroids, as pale mentioned post the warning on their SI page. Work in PM and email with the source to let them know how you were able to "hack" their site and got the info you found. Be a white hat.

hardneck's picture

Smart? Don t you think when everybody who stumbles across a hacking tool is able to hack a shop, that every agency in the world can do this whenever it wants to?

No really, i thought eroids is about showing trusted shops, which for me also means safe shops, and securing the people, which means us, and not advertizing shops which make load of bugs and take a shit on us and holding everything in secret. Do you really mean it is all about a fucking hacking tool?

Sorry Greg, but you have no clue about this things, you are far away from beeing a tech guy, maybe back in the days of comodore but this time is gone. You also did not answer my PM, instead of doing it right like you are writing here, your aim is to blame me instead to help.

And you know what? i even don t want to help anymore, instead of accepting the problems and seeing it the real way, i get blamed from all sides to show this things. I have better things to do than beeing the bad guy on eroids.

But when time will come, and it will come some day, that people will got raided by cops or blackmailed by some assholes, than stfu and work on PM because nobody wants to here this kind of things here on eroids!

Sam I Am's picture

When you posted this I'm sure you expected people to ask questions. While this is a very serious topic it's not the first time something like this has happened. If you think your right stick to your guns. If your going to disappear on the first questions your on the wrong site. This site is real, nothings sugar coated. We've all been grilled at some point.

Owes a Review × 1
Bill G's picture

Dude ! I hope redactedlabs.com isn't on that list . It would be the end of eroids for sure. Id have to start shoping at censoredlabs

Greg's picture

I accepted your friend request and you have not sent me a message. You have been on this site all day stalking my replies to you...

I understand the tools are out there for anyone to use. It is not smart to make it easy for anyone to access such a tool that is so simple even you can make it work.

Eroids is about finding trusted shops, that is true. But it is aimed more at the character of the source and the quality of their gear than the security of their websites. That being said, I'm not about to go and try and hack every website for code vulnerabilities. Heck, many of these sites are not even using secured servers.

There is a right way of going about this and a wrong way. You have chosen the wrong way. Now that you're recanting on your effort to help, even working with me in PM, you are now becoming suspect.

I am still the only one on your friends list.
You have not friended any other source.
You have not sent me a PM
You have not shared any list other than an innocuous email list
You have not provided evidence where the list came from
The list contains hundreds of emails that are not on the sources client list.
You have not posted on any of the other 10 sources SI page to call them out

I cautioned you on your actions by revealing your methods. You talk about safety but find no issue with ginning up hundreds of curious wanna be's into hacking sources for their own gain? Potentially extorting the source and other members they have a beef with? You want to come after me as having picked on you?

Do you want to put your mouth where your money is? PM me the screenshot of the code that generated that email list. If I don't see that, I'll have to conclude you are a troll.

hardneck's picture

just answer my question if it is possible.

Greg's picture

Yes, if errors are not turned off. So now answer my questions and prove your email list came from this one particular source.

Your problem is you're taking everything as an affront. If your intentions are good, you'd want to help good sources to become better. You'd want to protect members and the source.

Instead, you are trying to pit the members against a good source. You are assisting others in "hacking" that source.

Sam I Am's picture

Seems odd its during a promo. Honestly I'd be surprised if many on that list are actually useing there real email. I dont. Theres also a dozen Sam's on there. Anybody needs me just hit up Peter North on FB. No homo..got a gig at the nursing home later so I'll be out today. That's show buisness..

Owes a Review × 1
wanted's picture

Peter North Huh. Well meet JENNA JAMESON

Sam I Am's picture

I'm only here for the dick pills ...nohomo : )

Owes a Review × 1
Greg's picture

I'd be surprised if many on that list are actually using their real email. I don't.

Same here, encrypted or not, there are so many ways to open an email account without verifying your true identity. Couple that with being on hundreds of "marketing" email lists which are compiled and sold to anybody. Even if your email was on the list, it does not prove anything.

tattoofreak's picture

A friend here confirmed his email adress is on this list, so this guy is definitely telling the truth...

Owes a Review × 1 In a promo × 1
Sam I Am's picture

It's good to be careful and switch it up but a couple years ago the former 1 source had a hack. Nothing came of it. I'm curious to hear who the other 9 are. We have a brand new acct who isn't new. Hes posting on the right forum headings. Knows his way around the site. I'm sure hes telling the truth but I dont think that's the whole story...

Owes a Review × 1
tattoofreak's picture

I totally agree, mate. Don't know if he just wants to help or making his own business or working together with another source, everything is possible. But to be honest, I don't care too much about his motive. He reminded us to be careful as fuck and I wouldn't order from a source which can be hacked easily...

Owes a Review × 1 In a promo × 1
Sam I Am's picture

I try to be careful but the truth is any source on here can be hacked. That's just the reality of modern day life. Some may be harder than others but even our voting system has been hacked. What amazes me are the guys on here that use there names and are on FB. Lol I've seen one with a picture of his gym buddy who is the guy in his pictures. To pathetic to even call the cat out on it...everybody gives him karma and praise on his pics. I get a kick out of it everytime.

Owes a Review × 1
tattoofreak's picture

Lol... that's really paltry

Owes a Review × 1 In a promo × 1
dextetherdog's picture

Never heard of this source “Post in their SI not here”, must be a new one lol

Protein4breakfast's picture

I didn’t look at the link the first go round but maybe someone more tech savvy then I could speak up to the validity of this. Pale pointed out that Greg was the tech guy so I wouldn’t mind hearing his opinion on this ether. Typically I dismiss this type of thing right off but I’m curious to how you acquired this list?

In a promo × 2
RVWolf's picture

REDACTED a tool that runs on Linux and developed for this purpose.

Greg's picture

I got an Idea, let's pave the road and supply everyone easy access to "hacker tools".

GrowMore's picture

Wouldn’t be surprised if this was true but I wouldn’t be surprised if it was all rubbish. Either way it’s another lesson that we should all be protecting ourselves as much as we can.. using untraceable email accounts, addresses other than you’re home, fake names, etc etc.

tattoofreak's picture

I've taken the time to compare the email addys from his link with some usernames and it seems, that he could tell the truth...

Owes a Review × 1 In a promo × 1
tattoofreak's picture

Sorry, double post

Owes a Review × 1 In a promo × 1
hardneck's picture

Thank you, yes of course i do tell the truth. And if somebody of the Mods or eroids team wants to know more, please send me a pm. I even don t know whom to write a PM. I know and can show with proof complete databases of at least 10 shops just right now. And if not interested, once again sorry for bothering you all with this.

tattoofreak's picture

Like Pale told, talk to Greg. Hit him a fr, then you can send him message. Furthermore I've sent a pm to a guy, whose email addy seems to be listed in your link. I wait for his answer, if it's really his. I give you the advice not to post anymore sources names in open forums, cause it's against the rules. But you can bring it to their si pages, like you did with the last one. If this all comes out as legit, it could be very helpful to talk about it on the right places.

https://www.eroids.com/users/greg

Owes a Review × 1 In a promo × 1
hardneck's picture

@Pcushion i have done my homework and wanted to warn people, you don t want this kind of info and know how to check a shop for vuln, then sorry.
@tattoofreak what is weird on warning users? Maybe nothing you see every day but nothing weird.
@Protein4breakfast you are wrong it is evidence, but for people like you, which are not that much into IT like me, this kind of thread was intended. But hey, you don t want it, ok so sorry.

@KMC nr.4 yes, one of the endless possibilities ...... You want evidence and me to publish sensible data in here? Bro that was what i was going to protect you from. But if no one with knowledge of how to use CENSORED is in here, i can send a Mod or Admin the full email list of all the customers they have. I have no problem with that. But simply because somebody wants to do something positive for the people, does not mean your version 1, 2, 3 or anything bad.

But ok, if you don t like this kind of information i will not publish them anymore. But i can tell you that i know more shops where this is leaking and some shops even with orders dating back to 2012 with full ip adress name dob and so on. But cares, i better shut up. So sorry one more time

Sam I Am's picture

Publish away but dont bother if you cant provide proof. Nobodys gonna take your word for it. Time to put up or shut up. That's only fair...

Owes a Review × 1
hardneck's picture

If it is the way to go then here, all customers please find your mail https://pastebin.com/XMVYjzUU

tattoofreak's picture

Ok... I don't say I believe everything here, cause your a new guy and I'm always sceptical. But to be honest, it seems that this is an issue which should be checked out. Maybe you should contact the mods and discuss this via pm.

Owes a Review × 1 In a promo × 1
hardneck's picture

Thank you. Ok i will contact them.

Pale's picture

Greg is the one to talk to. He is the tech guy. I just can't have you mentioning the source in the main forums. Feel free to point it out to them in their SI.

tattoofreak's picture

Registered 3 days ago, no friendships here and then a post like this? It's weird...

Owes a Review × 1 In a promo × 1
Protein4breakfast's picture

From what you posted there doesn’t appear to be any evedence of what you have accused them of so I’m not sure what you were trying to do here

In a promo × 2
Sam I Am's picture

This^^^

Owes a Review × 1
KMC's picture

so I’m not sure what you were trying to do here

1) A reverse scammer.
2) Somebody is butthurt over losing their allowance because they used a friends address and said friends father is NOW getting swollen.
3) A TROLL.
4) other endless possibilities.

Owes a Review × 1