List of Hacker.org members online

Discussion about hacker.org's server
W1zard
Posts: 8
Joined: Sat Oct 25, 2008 6:29 pm

List of Hacker.org members online

Post by W1zard »

Hello everyone!
I just found a website on the internet where all members of Hacker.org are listed with their nickname and email address. It's freely accessible. No password or anything. So everyone can look at it.
You'll be able to find it if you google your email address.
W1zard
User avatar
S3th
Posts: 411
Joined: Thu Sep 11, 2008 8:35 am

Post by S3th »

Whoa. Thats..fucking amazing.....
Dude.. Theres like 7301 members.. Who cares?
See through the master
Become the master
User avatar
Yharaskrik
Posts: 31
Joined: Wed Nov 05, 2008 11:44 am
Location: Germany

Post by Yharaskrik »

Hi!
Thanks W1zard.
As there are also md5 hashes of our passwords, perhaps it's a good idea to change them.
osterlaus
Posts: 20
Joined: Sun Nov 02, 2008 6:04 pm

Post by osterlaus »

Hopefully have all the members not (!) taken the same PW on their mailservers...
W1zard
Posts: 8
Joined: Sat Oct 25, 2008 6:29 pm

Post by W1zard »

Looks like some of the easier passwords have already been cracked. Especially at the top of the list. I wasn't sure what the stuff behind the md5 hash was until I checked it with an md5-generator.
So all passwords have to be changed!
The list seems also to have been noticed by others. I suddenly get a hell lot of spam mails. Up to now my address was relatively "secure" in that way. That's how I noticed the problem in the first place. So I started doing some research.
W1zard
Last edited by W1zard on Wed Mar 04, 2009 4:35 pm, edited 2 times in total.
osterlaus
Posts: 20
Joined: Sun Nov 02, 2008 6:04 pm

Post by osterlaus »

osterlaus wrote:Hopefully have all the members not (!) taken the same PW on their mailservers...
Well, this was no posting of mine - so someone already used my account...
User avatar
S3th
Posts: 411
Joined: Thu Sep 11, 2008 8:35 am

Post by S3th »

I googled my email address.
Found nothing.
My password is custom encrypted too.
See through the master
Become the master
User avatar
m!nus
Posts: 202
Joined: Sat Jul 28, 2007 6:49 pm
Location: Germany

Post by m!nus »

it's on milw0rm since febuary 27
User avatar
efe
Posts: 45
Joined: Sun Oct 26, 2008 10:28 am
Location: germany

Post by efe »

Thanks W1zard!

Luckily my password was strong enough, and it hasn't been cracked :D
Now it is even more secure.

The passwords have been cracked for 3139 users.
And I got out more passwords (>100) by searching the md5 on google.
User avatar
m!nus
Posts: 202
Joined: Sat Jul 28, 2007 6:49 pm
Location: Germany

Post by m!nus »

my 9 char password was strong enough aswell, yay for non-word-passwords, proof to dictionaries
hacker.org - prove your skill. k, another hacking challenge site not that different from any of the others except the name makes it fun

to fuck with. sooo if you are going to offer hacking challenges why not make sure your shit just a tad secure? sounds logical to me but maybe i'm

just throwed off a bit. tbh this isn't even worth a zine entry but hacker.org getting hacked is pure hilarity.
not nice, but well, the site was not proof enough.

so, to the admins: where was there a SQL injection possible, and more important: is it fixed?
fridolin
Posts: 16
Joined: Sun Nov 30, 2008 9:15 am

Post by fridolin »

I'm wondering why my account doesn't show up in the list...

I could imagine the injection was made by phpBB as the defacement was visible on the main page and on the forum's main page.
plope0726
Posts: 826
Joined: Mon Dec 15, 2008 10:13 pm

Post by plope0726 »

Well a google search shows me nothing for my email address...Is there a link to this alleged page so that we can do some more research on it and possibly catch the perps??
plope0726
Posts: 826
Joined: Mon Dec 15, 2008 10:13 pm

Post by plope0726 »

The list on this page appears to be old since many users arent listed on it. It does'nt appear to be relevant to the most recent hijacking. Passwords should still be updated. (for email too if you happen to use the same password)
User avatar
Zaffron
Posts: 491
Joined: Thu Dec 18, 2008 12:18 am
Location: Invading a small country

Post by Zaffron »

Is this what the whole down for matinence thing was for?
gfoot
Posts: 269
Joined: Wed Sep 05, 2007 11:34 pm
Location: Brighton, UK

Post by gfoot »

The newsletter is new. It's possible that the defacement wasn't part of the initial attack, given that this was published a week ago - plenty of chance for readers to put the information to use.

I noticed tails's username changed to Helios last Thursday or something, shortly before the attack, which is pretty pointless if your next step is to totally take the site down.
Post Reply