DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Imageshack, Symantec hacked & ZPanel 0 day by HTP ( Hack The Planet )

Posted on November 5, 2012 by Lee J

hack-the-planet**Updated: **first edit i made a mistake and stated that paypal was the victim of the 0 day when it was infact ZPanel. Sorry for any inconvenience or misleading information. Earlier today a well known hacker group, Hack the planet had released a Zine which contains breached information on 2 well known website image service Imageshack and anti virus giant Symantec and a 0 day exploit has been released for payment gateway giant Paypal  ZPanel Hosting control panel systems. Even though the leak is clearly marked as being done by HTP other media has been reporting these two attacks as part of Anonymous #Nov5 attacks which have started today. The leaked data was uploaded to various places, and contains a heap of information from the Imageshack server as well as all the exploits or vulnerabilities they had found and a reason behind the attack  "Well, we like a challenge, so we decided to find out what changes were made. ". imageshack Insight to the image shack attack from HTP

Heres a list of criteria we found that evidenced the hardened security on all of ImageShack’s equipment: – Run all MySQL instances as root – Ensure all kernels are 2008 or earlier – Routers compromisable via /level/16/exec/-/show/run – Hardcode database passwords into as many files as possible (though we do give them credit, the root MySQL pass ‘mutaborius’ was never cracked by hashcat.) – Implement a firewall that allows outgoing backconnects – Add tasks to root’s crontab that regularly run files owned by the www user – Run outdated Nginx – Enable register_globals – Use one $1 shadow hash for everything Protip, if your security sucks this much, your incoming firewall rules and your keyauth won’t save you. That being said, ImageShack has been completely owned, from the ground up. We have had root and physical control of every server and router they own. For years.

This message is followed by a extremely large amount of server information such as shells, file permission listings, source codes and much more. Towards the end of the Imageshack section is a bit of commentary from HTP that claim that @Le_Researcher ratted on them when the attack was going on and the admin attempted to stop this but failed to do so.

Recently, one specific brownhat (see Pwned Lineup/LeReS) alerted Jack, so of course Jack opened up his logs, and reimaged his boxes, and saved the fucking planet. Unfortunately, our zines have a strict no-bullshit policy. Thanks for keeping UDP open for us, Jack.

OH SHIT, HE SET UP A HACK DETECTOR. GAME OVER MAN. GAME OVER. # cat /home/image/svn/setup/misc/detect.php

logo_symantec As stated above antivirus giant Symantec was also breached and as a result it has had its complete database dumped as well as 4000+ user accounts many of which appear to be Symantec employees or related companies. https://ozdc.net/archives.php?aid=3941zpanel   The paypal ZPanel part of the attack is a 0 day exploit.

We have a Zero Bug attacking all the login and overlay files. Run anti-virus. Give me a systems display! * The systems display comes up. Red flashes everywhere, signifying new attacks. * PLAGUE presses a key. Die, dickweeds! The rabbit is in the administration system.

The zine also contains a heap of personal information that is claimed to belong to some people that are close to the infosec and anonymous scene. Possibly more information to come on this once i get a chance to properly go over all the details line by line. https://pastebin.com/jhLt7s83

Category: Breach Incidents

Post navigation

← FL: Bay County Sheriff’s Office Busts Identity Thief in Possession of Thousands of Tax Returns from Unnamed Preparer
LG Smart World Hacked 11,316 Accounts Leaked →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.