List of Hacker.org members online
List of Hacker.org members online
Hello everyone!
I just found a website on the internet where all members of Hacker.org are listed with their nickname and email address. It's freely accessible. No password or anything. So everyone can look at it.
You'll be able to find it if you google your email address.
W1zard
I just found a website on the internet where all members of Hacker.org are listed with their nickname and email address. It's freely accessible. No password or anything. So everyone can look at it.
You'll be able to find it if you google your email address.
W1zard
- Yharaskrik
- Posts: 31
- Joined: Wed Nov 05, 2008 11:44 am
- Location: Germany
Looks like some of the easier passwords have already been cracked. Especially at the top of the list. I wasn't sure what the stuff behind the md5 hash was until I checked it with an md5-generator.
So all passwords have to be changed!
The list seems also to have been noticed by others. I suddenly get a hell lot of spam mails. Up to now my address was relatively "secure" in that way. That's how I noticed the problem in the first place. So I started doing some research.
W1zard
So all passwords have to be changed!
The list seems also to have been noticed by others. I suddenly get a hell lot of spam mails. Up to now my address was relatively "secure" in that way. That's how I noticed the problem in the first place. So I started doing some research.
W1zard
Last edited by W1zard on Wed Mar 04, 2009 4:35 pm, edited 2 times in total.
my 9 char password was strong enough aswell, yay for non-word-passwords, proof to dictionaries
so, to the admins: where was there a SQL injection possible, and more important: is it fixed?
not nice, but well, the site was not proof enough.hacker.org - prove your skill. k, another hacking challenge site not that different from any of the others except the name makes it fun
to fuck with. sooo if you are going to offer hacking challenges why not make sure your shit just a tad secure? sounds logical to me but maybe i'm
just throwed off a bit. tbh this isn't even worth a zine entry but hacker.org getting hacked is pure hilarity.
so, to the admins: where was there a SQL injection possible, and more important: is it fixed?
The newsletter is new. It's possible that the defacement wasn't part of the initial attack, given that this was published a week ago - plenty of chance for readers to put the information to use.
I noticed tails's username changed to Helios last Thursday or something, shortly before the attack, which is pretty pointless if your next step is to totally take the site down.
I noticed tails's username changed to Helios last Thursday or something, shortly before the attack, which is pretty pointless if your next step is to totally take the site down.