Hosting hacked: 6500 Tor Hidden Services Wiped Out

Dec 6 11:09 [raw]

Hosting hacked: 6500 Tor Hidden Services Wiped Out On November 15th around 10:06 PM UTC the hosting server was logged in to via phpmyadmin and adminer with the correct hosting management password and deleted all accounts. Noteworthy, also the account "root" has been deleted, which was injected into the database at 10:53 PM UTC and deleted at 12:50 AM, shortly after remaining databases from the chat, link list and hit counter got deleted. Unfortunately it is not possible to find the root cause by log analysis as on 14th at 5:33 the database had already been accessed with this user and it is unknown for how long the hackers may have had access to the database due to rotating logs frequently. However the database password was last updated on October 20th, which indicates that the hack must have happened within the last month. To this day around 6500 Hidden Services were hosted on the server. There is no way to recover from this breach, all data is gone. The scripts are open source on github and anyone is welcome to take it as a base to build a new hosting service or help find the vulnerability. If you are the hacker or have any helpful information about how this could have been done, please get in contact with me Investigation is continuing. Not affected are the mail and XMPP service, as well as the static content and the short-link service, which were hosted on my Raspberry Pi 3. The chat is restored with a fresh installation and other services will be back up soon. I expect to get the hosting back up in December (NOT on December 1st). In the meantime, http://fhostingineiwjg6cppciac2bemu42nwsupvvisihnczinok362qfrqd.onion is a good alternative. To stay updated about the development, check here:

Dec 6 11:49 [raw]

Yikes! I had an email address there!

Dec 6 17:17 [raw]

danwin ... what a shitty hoster, dont even have backups > 6500 Tor Hidden Services Wiped Out no, actually just one, with a handful of onion domains

Dec 6 22:41 [raw]

I don't believe it ... the shit was hittin' the fan and he just found a quick way out

Dec 7 01:26 [raw]

I suspect he actually wasn't hacked. Maybe the hack story is a cover for something else.

Dec 7 01:32 [raw]

I was thinking the same thing. ALL of his data was lost, but not the email. How convenient.

Dec 7 01:39 [raw]

Please speculate and elaborate. This is worth extrapolating.

Dec 7 02:03 [raw]

> In the meantime, http://fhostingineiwjg6cppciac2bemu42nwsupvvisihnczinok362qfrqd.onion is a good alternative. cattle chute?

Dec 7 03:00 [raw]

I've always said Daniel was IMPRESSIVELY STUPID to do this orthonymously under his state identity. In doing so, he became the softest attack surface of the system, and as we know a system is only as strong as its weakest element. If indeed the damage was self-inflicted, as has been theorized by some, I wouldn't even hold it against Daniel. Maybe he wanted to finally remove the biggest vulnerability of the danwin system: Daniel Winzen. And since Silk Road has taught us that "business as usual under new management" doesn't really work against the current threats, the only honorable way forward was to hit the Reboot button. Not saying that this is what happened. Just saying that IF this was what happened, I wouldn't have a problem with it. Best of luck to Daniel in building a new reputation from scratch on top of a new, less vulnerable identity. PS: Watch out for cockmail hacks next.

Dec 7 23:17 [raw]

Meh. The whole shebang runs on a Raspberry Pi so maybe his SD card finally wore out.

Dec 14 16:21 [raw]

> PS: Watch out for cockmail hacks next. Aaaaand.. yeah. Thought so. :-( You heard it here first, folks. Winter is coming.

[chan] general

Subject Last Count
