PDA

View Full Version : Beware takke precautions. Major Major leaks from the biggest node



chestrockharder
09-11-2013, 03:28 PM
***************For the record, I contacted the people who run it, they wrote back


"We have it under control, thanks for the tip, now go away your banned for intrusion."

WTF!!!! I wrote back that the clients should be warned and the end users of those clients,

"How does 5 grand sound to shut the **** up and go aaway and forget this"

Yes they tried to ****ing pay me to keep quite.

My Reply:

"I make more than enough money yearly to take your 5 grand bribe. Hell satscams would give me 30grand but they can **** off to I tried nicely, now i''ll let the people who count on you to be airtight ruin your business. NODE=0"

.


Regarding Boricuafta and how myself and a few others discovered multiple vunerabilities and the Admin of that servers pure disregard for user saftey and privacy. I wrote that post.

Now I write to warn all hobbiests that this time its seriously bad, makes Boricuaftas leaks l;ook like a fly buzzing around you, while its annoying, its dealt with easily... So take it seriously when I say this time it is a ****ing stampeed of giant tigers comming at you.

I am a security networking consultant with a masters in network administration with an emphasis data administration, who alos loves the hobby. I am going to warn all users, in every forum I can about a very large server, who leases nodes to 90% of all iks servers there are.

It is and has been vulnerable of data leaks using simple tequniues, that I will not publish. For perspective I'll say this.
NFPS, FIsh, Rocket, +++++++++ alll the little guys. Thats about 1/10 of this datacenter for lack of a word(s) clients.

They will survive if you know who scans them next week, they are not in the states; users will not!

I was able to download the whole sql backend database and had root ssh, ftp, and sql within 20 minutes of trying, and I was hardly using tools I would at work. I.E. pro exploit toolkits. Simply using ********** tequine I found that due to a softwware update they or thier the host did they where exposed for a few days, still are. . Upon further and in depth examination I found out that as of 2 days ago they had over 100,000 node connections, thats 1 node connection = 1 person, they where sending CW's in such volume it would look like alexa top 10 in traffic, lol... But not to be funny, thats huge. So the hobby's members need to know, just as they did when it was only less than 1,000 on Boricuaftas.

I can promise all members, if they are using any IKS server out rigt now. Dish will have em dead to rigfhts soon. Dish does a bi-weekly audit of these servers. I know that 110% for certain, how I cannot tell everyone, as it would reveal who I am I will not post the name of this central server as many do not know it exists, further while I know dish does I certainely am not going to make thier network exploitation teams job easy. Last I knew for certain Dish knows of 5 big ones, and all the resellers down the ine, so while they know some, they know not all.

So..... Clocks ticking.

They edited it, removed links and a lot of info.. I hop you do not do that to this warning, they did for financial reason. Not saftey, I place it here in rumors as I know all you will be sceptical, all Iam saying is for the next few days go dark on those recivers,.,

JCO
09-11-2013, 04:58 PM
Are you saying that the master server cache has weak security and that all users are exposed..???

thunder bird
09-11-2013, 05:20 PM
If it smells like it

bigbadbrother
09-11-2013, 07:58 PM
I see dishuser hasn't seen this yet.

thunder bird
09-11-2013, 08:04 PM
Give us a break,BS BS:grr:

Anubis
09-11-2013, 08:23 PM
Ahhhhh something new to get members riled up other than demand letters.:tehe:

bkr™
09-11-2013, 08:28 PM
I see dishuser hasn't seen this yet.

We are all waiting...:hehe:

dishuser
09-11-2013, 09:10 PM
what an idiot
only the server connects to cache server not the user
get your head out of your azz

niceguy
09-11-2013, 09:32 PM
thanks for info

Nostradamus
09-11-2013, 09:47 PM
what an idiot
only the server connects to cache server not the user
get your head out of your azz

I think the problem is he has a taste of sour grapes because his server is not allowed to connect to the car cache any more :)

sodusme
09-11-2013, 10:47 PM
I been waiting for a good juicy rumor, been a while.

lobsterpot
09-11-2013, 10:55 PM
Ah just another page in the books at satfix.

surfinisfun
09-11-2013, 10:59 PM
I been waiting for a good juicy rumor, been a while.

Sorry bud, i think you'll have to keep waiting......this aint that juicy.lol

sodusme
09-12-2013, 02:35 AM
Sorry bud, i think you'll have to keep waiting......this aint that juicy.lol

No but it definitely is a rumor...LOL.

I have to admit the "credentials" sound impressive: network security consultant with a masters in networking administration with an emphasis on data administration? Hmm sounds very important. Although I am pretty sure that the actual title is "network security consultant"....not "security networking consultant". I could be wrong but I rarely am. So with that said I'm sure it was just a typo though and this gentleman is fully aware of his own credentials and simply typed it wrong....right? :innocent:

Nostradamus
09-12-2013, 03:02 AM
I think gyproc mudder would be a better job title

bauzzoo
09-12-2013, 03:08 AM
i hope he is wrong

anyonomus
09-12-2013, 04:15 AM
I think gyproc mudder would be a better job title

Only if the wall is mudded with BS..

JCO
09-12-2013, 03:05 PM
what an idiot
only the server connects to cache server not the user
get your head out of your azz

Ahh finaly, we were all waiting for DU's words of wisdom...

thunder bird
09-12-2013, 04:19 PM
The sky is falling,but some how I am still alive:tehe:

Anubis
09-12-2013, 04:36 PM
The sky is falling,but some how I am still alive:tehe:

You're fine so long as you have your tin foil hat on.

bigbadbrother
09-12-2013, 08:22 PM
I got mine

http://blog.ecofoil.com/files/2013/07/tin-foil-hat.jpg

chestrockharder
10-27-2013, 06:35 PM
Beleive me if you want, I do not care. But know this I was the one who warned all of you about boricufta. The ones here who know about that will attest that I was not lying to ryle up a coule thousand on this forum the mods will also know that I poseted proof pics, logs, etc.. They edit it for protrection, but I needed to get it acroos that I was not bull****ing then and I wasnt now. That post I made saved pewople from demand letters, and made the serves admins tighten **** up, otheers would have sold it to nagravision.

Now as for cache server connections move along, let me know when you have even been into a nodes backend and admin panels, and a degree in network security minoring in Database securiity, hell let me know when you further mulitple have certifications from windows to redhat and more. At that time we will chat. Hell i would give you a job

sodusme
10-27-2013, 10:07 PM
Beleive me if you want, I do not care. But know this I was the one who warned all of you about boricufta. The ones here who know about that will attest that I was not lying to ryle up a coule thousand on this forum the mods will also know that I poseted proof pics, logs, etc.. They edit it for protrection, but I needed to get it acroos that I was not bull****ing then and I wasnt now. That post I made saved pewople from demand letters, and made the serves admins tighten **** up, otheers would have sold it to nagravision.

Now as for cache server connections move along, let me know when you have even been into a nodes backend and admin panels, and a degree in network security minoring in Database securiity, hell let me know when you further mulitple have certifications from windows to redhat and more. At that time we will chat. Hell i would give you a job

Hook me up than I'd love to chat. I'm about finished with an Associates in Network Administration with a CCNA certification and my "degree" in Network Security consists of me being able to crack any site out there from VB boards, to newspaper sites, to any VPN site I want. Most on these forums know of my "skills" and there is none better not even on the cracking boards I frequent:
http://crackingforum.com/
http://teamxpc.com/
http://golden-joint.com/ and
http://www.the-collective.us/forum.php Notice I underlined "any" because I AM that good. ;)

I just found it humorous that you mislabeled your Masters degree title in the first post. Sorry but when you do something like that it opens you up to scrutiny. Oh btw you can look me up on any of those forums I use the same username. ;)

nobody
10-28-2013, 05:53 AM
***************For the record, I contacted the people who run it, they wrote back


"We have it under control, thanks for the tip, now go away your banned for intrusion."

WTF!!!! I wrote back that the clients should be warned and the end users of those clients,

"How does 5 grand sound to shut the **** up and go aaway and forget this"

Yes they tried to ****ing pay me to keep quite.

My Reply:

"I make more than enough money yearly to take your 5 grand bribe. Hell satscams would give me 30grand but they can **** off to I tried nicely, now i''ll let the people who count on you to be airtight ruin your business. NODE=0"

.


Regarding Boricuafta and how myself and a few others discovered multiple vunerabilities and the Admin of that servers pure disregard for user saftey and privacy. I wrote that post.

Now I write to warn all hobbiests that this time its seriously bad, makes Boricuaftas leaks l;ook like a fly buzzing around you, while its annoying, its dealt with easily... So take it seriously when I say this time it is a ****ing stampeed of giant tigers comming at you.

I am a security networking consultant with a masters in network administration with an emphasis data administration, who alos loves the hobby. I am going to warn all users, in every forum I can about a very large server, who leases nodes to 90% of all iks servers there are.

It is and has been vulnerable of data leaks using simple tequniues, that I will not publish. For perspective I'll say this.
NFPS, FIsh, Rocket, +++++++++ alll the little guys. Thats about 1/10 of this datacenter for lack of a word(s) clients.

They will survive if you know who scans them next week, they are not in the states; users will not!

I was able to download the whole sql backend database and had root ssh, ftp, and sql within 20 minutes of trying, and I was hardly using tools I would at work. I.E. pro exploit toolkits. Simply using ********** tequine I found that due to a softwware update they or thier the host did they where exposed for a few days, still are. . Upon further and in depth examination I found out that as of 2 days ago they had over 100,000 node connections, thats 1 node connection = 1 person, they where sending CW's in such volume it would look like alexa top 10 in traffic, lol... But not to be funny, thats huge. So the hobby's members need to know, just as they did when it was only less than 1,000 on Boricuaftas.

I can promise all members, if they are using any IKS server out rigt now. Dish will have em dead to rigfhts soon. Dish does a bi-weekly audit of these servers. I know that 110% for certain, how I cannot tell everyone, as it would reveal who I am I will not post the name of this central server as many do not know it exists, further while I know dish does I certainely am not going to make thier network exploitation teams job easy. Last I knew for certain Dish knows of 5 big ones, and all the resellers down the ine, so while they know some, they know not all.

So..... Clocks ticking.

They edited it, removed links and a lot of info.. I hop you do not do that to this warning, they did for financial reason. Not saftey, I place it here in rumors as I know all you will be sceptical, all Iam saying is for the next few days go dark on those recivers,.,

just a friendly warning from a " nobody " please don't trash talk my home-site ..........you will get DOXED if i see this bs posted anywhere else ............. enjoy the view ;D ;D ;D

ps: i am pretty sure everyone in this FTA community ............ would just LOVE what gifts i DO & HAVE already given .......... pick a site pull a number & enjoy LMFAO ;D

Terryl
10-28-2013, 05:59 AM
OK kids this has gone far enough, no more "lookie what I can do" or open threats on our site....We don't care.....


This is closed.