South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
Article name change... from clickbait to boring
Here fishy....Despite my better judgement, I'll take the bait:
- None of the comments in this thread or Disqus caused the headline change.
What caused the name change?
“I discovered a breach” is far better than “I hacked” if you didn’t actually hack... unless he did and he’s not telling?
Technically giving out all info in a public directory is a security breach. It's no more hacking than me forgetting that my password is in the clipboard and accidentally pasting it to a website would be.
But at some point they must have, else how was it indexed? Or they posted it somewhere else.It's not like they posted the creds onto their website, though.
Anyway... I'm not here to argue semantics. I posted a question and you gave an answer — thanks!
A contractor for the Russian Federal Security Service (FSB) has been hacked and secret projects that were being developed for the intelligence agency were leaked to Russian Media. These projects detail Russia's attempt to de-anonymize users on the Tor network, collect data from social networks, and how to isolate the Russian portion of the Internet from the rest of the world.
On July 13th, 2019, a contactor for the Russia FSB named "Sytech" was claimed to be hacked by a hacking group named 0v1ru$. As part of this hack, the group defaced the contactor's site to show an image of "Yoba-face", which they posted an image of on their Twitter feed.
A botnet is currently scanning the internet in search of poorly protected Windows machines with Remote Desktop Protocol (RDP) connection enabled.
Called GoldBrute, of the malware compiled a list of over 1.5 million unique systems and systematically tests access on them with brute-force or credential stuffing attacks.
Over the weekend, StockX announced that their sneaker and streetwear buying platform had been hacked and an unauthorized user was able to gain access to customer data. This hack was what led to the password reset emails being sent out to all customers last week.
Data belonging to 32 million customers of SKY Brasil has been exposed online long enough to make their theft very likely, an independent security researcher discovered.
Fábio Castro found that the data cache could be reached by anyone that knew where to look on the internet.
An unsecured database has exposed the personal information of 8 million people from the U.S. who participated in online surveys, sweepstakes, and requests for free product samples.
The way these types of sites work is you are offered free product samples, a chance to enter a sweepstake, or a prize for filling out a survey. In order to take advantage of these offers, though, you will be required to provide your personal information, which will then be used in later marketing campaigns or for lead generation.
Sanyam Jain, an independent security researcher and member of the GDI Foundation, discovered an unsecured Elasticsearch database that exposed the personal information of 8 million people who submitted entries to these types of sites.
18 MongoDB databases with information generated by accounts on several online social services in China have been sitting on the web ready for plucking by anyone knowing where to look.
It appears that they are part of a country-wide surveillance program that collects profile-related data (names, ID numbers, and photos) along with GPS locations, network info, public and private conversations, and file exchanges.
Huge amounts of profile data processed daily
According to Victor Gevers, a security researcher for the non-profit GDI Foundation, the program vacuums into one large database the account information from six social platforms in China and links it to a real person or ID.
But at some point they must have, else how was it indexed? Or they posted it somewhere else.

Approve of new title
...
"Hack"
...
vs
...
"Expose"
A lot of Google Dorking comes down to exploiting configuration errors. In this case, the directory on the web server was probably exposed as a basic website.
Here's an example: https://azaforum.com/download/
View attachment 705223
To get results like this you would search something like `allintitle:index of`.
Nowadays you'll usually make sure that any access that doesn't result in a web page being served instead redirects to a Forbidden page.
For the kind of Google Dorking that Bright was talking about here, you would use search queries like `allintext:username filetype:txt`.
For those interested in reading more about Google Dorking, this page was pretty useful: https://securitytrails.com/blog/google-hacking-techniques
He found passwords, using a technique that isn't new, been around since 2002, Johnny Long's book was published in 2004. That's over 17 years old.
If you find a coin on the street, can you claim to have robbed a bank?
Indeed,there is a bit of a grey area,but i'd say the spirit of it is where information is stumbled upon in the open (relatively low hanging fruit) i'd rather have the title highlight that,than the more original nomenclature of a "hacker" - being one who intrudes beyond the public domain. Once you cross that perimeter intentionally you've earned the stripes (Disregarding the original division between hackers/crackers/phreakers which is pretty dead these days)Thanks for the input. Also love Bleeping Computer.
I would argue that this lies somewhere in the middle of that spectrum. While this was the similar kind of carelessness that causes millions of people's private data to be exposed when a database is left unsecured, the story is not the exposed data itself. It's about what that exposed data gave the hacker access to.
In this case it wasn't personal data being exposed, it was corporate credentials that a hacker was able to use to log into MultiChoice's VPN.
From a different perspective: I can leave a passwords.txt on a websever somewhere, but it doesn't mean you'll know what to do with those creds if you find them. Some level of knowledge on the part of the hacker is needed to actually exploit the credentials they find.
Great, I certainly don't.That's a disingenuous argument and you know it. You don't have to invent a novel technique to say you've hacked someone.
He found passwords *and* knew what they were for.
I accept that some people won't consider that hacking, but there's no need to strawman this.
Indeed,there is a bit of a grey area,but i'd say the spirit of it is where information is stumbled upon in the open (relatively low hanging fruit) i'd rather have the title highlight that,than the more original nomenclature of a "hacker" - being one who intrudes beyond the public domain.
Once you cross that perimeter intentionally you've earned the stripes (Disregarding the original division between hackers/crackers/phreakers which is pretty dead these days)
This guy accidentally got the keys to the castle,using no more advanced tools than a browser and some syntax. Some skill and nuance sure,but not beyond what could be (as he did) stumbled upon by accident.
I've been involved with plenty of opsec incidents in my lifetime,where some spaz left info exposed somewhere that could do damage in the wrong hands. It happens
This to me is the criteria. If there's a window and I insert a wire to hook the clip to open it I'd be breaking and entering. But not if someone left the window open with the keys to the house on the sill even if I went looking for such a house. That to me is the closest real world analogy one could get.Indeed,there is a bit of a grey area,but i'd say the spirit of it is where information is stumbled upon in the open (relatively low hanging fruit) i'd rather have the title highlight that,than the more original nomenclature of a "hacker" - being one who intrudes beyond the public domain. Once you cross that perimeter intentionally you've earned the stripes (Disregarding the original division between hackers/crackers/phreakers which is pretty dead these days)
This guy accidentally got the keys to the castle,using no more advanced tools than a browser and some syntax. Some skill and nuance sure,but not beyond what could be (as he did) stumbled upon by accident. Even researchers finding unprotected Databases or data blobs in cloud storage are not coined to be "hacking",even if they used some skill or tools like Shodan to probe for these types of issues
Again,it's cool he found stuff,and I enjoyed the read,but the original thread title left me dreading if it'd be more affectionately termed "Clickbait" - ooooh scary hacker guy,oh,he found a notepad with passwords,um I guess thats cool man
I've been involved with plenty of opsec incidents in my lifetime,where some spaz left info exposed somewhere that could do damage in the wrong hands. It happens
This to me is the criteria. If there's a window and I insert a wire to hook the clip to open it I'd be breaking and entering. But not if someone left the window open with the keys to the house on the sill even if I went looking for such a house. That to me is the closest real world analogy one could get.
On mobile so not snipping now apologiesThat's a useful (and interesting) perspective, thanks.
Something I just want to make clear: Bright is the real deal. Just because the first time we've interviewed him in a context like this happens to be a "soft" hack shouldn't reflect on his skills at all.
I didn't want to spend a paragraph or more blowing smoke up his ass, but in hindisght, maybe that is necessary when I'm introducing y'all to someone new.
He's a professional, and highly qualified on top of that. He's also been arrested by Interpol, but I almost don't want to mention that because that was in his script-kiddie days.
Heh, this got a chuckle out me. As if it weren't enough of a problem that people will leave stuff on a webserver, let alone a poorly configured one, now there are improperly configured S3 buckets to contend with as well.
Why? All it takes is knowing there are people who leave the keys out in the open. That doesn't mean I committed grand theft if I find such a place. It's the difference between having a specific target and looking for weak points and throwing a hand full of darts hoping one would stick.These analogies are strawmen, though. This is more like the keys being hidden in an obscure location, but they've got some kind of magical beacon attached that can be searched for if you know how. This beacon also gives some hints as to where to look for a gate or door that might fit the key,
Then after you find the keys, you recognise the shape of it and know which kinds of gates they generally fit, so that's what you try first.