Advertisement
<a href="http://abaca.com/free_trial.html"><img src="/a-ab/missing.gif" /></a>
  • About the Author
  • About this Blog

  • Carders.cc, Backtrack-linux.org and Exploit-db.org Hacked

    Carders.cc, a German security forum that specializes in trading stolen credit cards and other purloined data, has been hacked by security vigilantes for the second time this year. Also waking up to “you’ve been owned” calling cards this Christmas are exploit database exploit-db.org and backtrack-linux.org, the home of Backtrack, an open source “live CD” distribution of Linux.

    The hacks were detailed in the second edition of “Owned and Exposed,” an ezine whose first edition in May included the internal database and thousands of stolen credit card numbers and passwords from Carders.cc. The Christmas version of the ezine doesn’t feature credit card numbers, but it does list the user names and hashed passwords of the carders.cc forum administrators. The carders.cc forum itself appears to be down at the moment.

    Mati Aharoni, the main administrator for both exploit-db.org and backtrack-linux.org, confirmed that the hacks against his sites were legitimate. Shortly after my e-mail, Aharoni replied with a link to a short statement, noting that a hacking team called inj3ct0r initially took credit for the attack, only to find itself also targeted and shamed in this edition of Owned and Exposed.

    “There’s nothing like having your butt kicked Christmas morning, which is exactly what happened to us today. We were owned and exposed, in true fashion,” Aharoni wrote. “Initially, the inj3ct0r team took ‘creds’ for the hack, which quickly proved false as the original ezine showed up – and now inj3ct0r (their new site) is no longer online. As a wise Chinese man once said: ‘do not anger one who has shell on your server’. The zine also mentioned other sites, as well as the ettercap project being backdoored.”

    To his credit, Aharoni posted a link to the 2nd edition of Owned and Exposed.

    “The irony of posting your zine in our papers section is not lost on us,” Aharoni wrote.

    Update 10:40 p.m. ET: An earlier version of this blog post incorrectly identified one of the hacked domains as linux-exploit.org. The blog post above has been corrected. My apologies for the confusion.

    Bookmark and Share

    Related posts:

    1. Fraud Bazaar Carders.cc Hacked
    2. iPack Exploit Kit Bites Windows Users
    3. Java: A Gift to Exploit Pack Makers
    4. Revisiting the Eleonore Exploit Kit
    5. Unpatched Java Exploit Spotted In-the-Wild

    Tags: , , , ,

    29 comments

    1. >A list of sites on that same subnet is available here.

      Wrong link, Brian.

      Well-loved. Like or Dislike: Thumb up 5 Thumb down 1
      • Hidden due to low comment rating. Click here to see.

        Poorly-rated. Like or Dislike: Thumb up 4 Thumb down 11
        • Спасибо. Вас также.
          Вообще, я атеист и анархо-коммунист, как я уже здесь писал. Хотя и в меру толерантен.

          Hot debate. What do you think? Thumb up 9 Thumb down 10
          • Brian, you need a Christmas! ;)

            Well-loved. Like or Dislike: Thumb up 14 Thumb down 0
          • Hidden due to low comment rating. Click here to see.

            Poorly-rated. Like or Dislike: Thumb up 3 Thumb down 15
            • Hidden due to low comment rating. Click here to see.

              Poorly-rated. Like or Dislike: Thumb up 5 Thumb down 11
            • I think that in the East, Christmas is more of a religious holiday than in the West, where there is family celebration, feasting, and exchange of gifts on that day. The churches in the West struggle to remind people that there is a religious basis to Christmas. People who never attend church any other day of the year celebrate Christmas here.

              Hot debate. What do you think? Thumb up 6 Thumb down 3
          • Hidden due to low comment rating. Click here to see.

            Poorly-rated. Like or Dislike: Thumb up 2 Thumb down 9
      • Eh. Pastebin unreliable sometimes. I have replaced the link for a local text file.

        Like or Dislike: Thumb up 3 Thumb down 2
        • Thank you, Brian.
          Cool site carder.biz, thx.

          Like or Dislike: Thumb up 3 Thumb down 4
        • Hi Brian,
          You might want to reconsider your file format and go with plain text, tsv, csv, whatever – rtf invites ghosts of MS Word and is hell on your non-Windows readers. Have a happy holiday, though, now! :P

          PS: I think you may like them because they give you shouts…

          Like or Dislike: Thumb up 1 Thumb down 5
          • Evokes memories of Windows, eh? Funny…I created that file on a Mac. :)

            Well-loved. Like or Dislike: Thumb up 13 Thumb down 0
            • You can read an RTF file in a console on OSX? :P

              Like or Dislike: Thumb up 0 Thumb down 4
            • PS: By invites ghosts of it, I was referring to the fact that any of your readers who use Windows, if given that file to open, would have it open in Word or at least some sort of interpretive application — it just would not be seen as ‘text’, and is therefore a little bit misleading. Not to nitpick. Personally I use Linux and BSD and strings destroys formatting. :)

              Like or Dislike: Thumb up 0 Thumb down 3
          • Brian already replied to this, but I’ll point out further.

            .rtf is default format for Mac OS X’s basic text editor.

            Well-loved. Like or Dislike: Thumb up 6 Thumb down 1
          • RTF is fine. Its an old format from the 1980s that everything can read. It sure beats PDF when you need to copy and paste large parts or do editing.

            Like or Dislike: Thumb up 3 Thumb down 0
    2. ^_^ Nice info :) Thanks

      Like or Dislike: Thumb up 1 Thumb down 3
    3. BTW I think you forgot to change your hashtag along with the correction. :)

      I now return to lurking. Sorry for deluge.

      Like or Dislike: Thumb up 1 Thumb down 1
    4. Hidden due to low comment rating. Click here to see.

      Poorly-rated. Like or Dislike: Thumb up 0 Thumb down 15
    5. Hey Brian, Happy holidays to you and your family, and best wishes for the new year.

      Well-loved. Like or Dislike: Thumb up 6 Thumb down 2
    6. Who are “Owned and Exposed” ?

      Like or Dislike: Thumb up 4 Thumb down 2
    7. The Owned and Exposed crew just did everyone a favor by revealing the fact Inj3ct0r is indeed sharing credit card information… I hope the law enforcement folks are doing something about that.

      Well-loved. Like or Dislike: Thumb up 12 Thumb down 4
      • Thank you sir for the reply :)

        I just wanted to know how they are?
        Because it’s the first time that I hear about them and
        when I googled I found nothing about them.

        Like or Dislike: Thumb up 3 Thumb down 4
    8. Hidden due to low comment rating. Click here to see.

      Poorly-rated. Like or Dislike: Thumb up 0 Thumb down 7
    9. internetspecialist

      Hidden due to low comment rating. Click here to see.

      Poorly-rated. Like or Dislike: Thumb up 10 Thumb down 16
    10. We are ethical hackers and here to help not make money, we only charge because of the cost,time and effort involved in the services and products we offer.
      I Sell Many More Stuffs For Sell Here I Am Honest And Good In Deals Has Well In True,Be Patient I have Any Delays. I Do All So Fast How We Can. We Thank For Your Understanding.For Demo For Free And For Sample If You Want You Will Have 1 Cc For Test If Good ,Please Deal More Time I Dont Want See Ripper Or Scammer

      CONTACT ME:
      —————————————-
      Yahoo Mail: Bian_lien30

      Email: Bian_lien30@yahoo.com

      Icq: 568983850

      Like or Dislike: Thumb up 1 Thumb down 3
    11. wich You All the best
      We love read Your blog
      Bonne annee
      et bonne continuation

      Like or Dislike: Thumb up 1 Thumb down 0