Advertisement
Guest User

Untitled

a guest
Nov 19th, 2016
1,472
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.95 KB | None | 0 0
  1. The Hacking of ProjectPokemon
  2. #############################
  3.  
  4. We were the ones who hacked Project Pokemon. What we did was for nothing more than entertainment.
  5.  
  6. "I blame Team Skull. They knew we could arm an army of young trainers with hacked Pokemon, so they launched a preemptive strike." <- We have nothing to do with "Team Skull" and neither do we care for Pokemon.
  7.  
  8. Message history with the individual who initially exploited the site, several months ago:
  9. #########################################################################################
  10.  
  11. Savior: You should give em a write up. Why the fuck not.
  12. Savior: You can give them my name
  13. Savior: Savior
  14. Savior: idc
  15. Savior: Just tell them the truth.
  16. Savior: How it was hacked..
  17. Savior: Every site I hack
  18. Savior: I document.
  19. Savior: phpinfo
  20. Me: Show me.
  21. Savior: SQL db info
  22. Savior: Screenshot shit
  23. Me: Show me and I'll consider making a post on GBATemp about it
  24. Savior: Quote this
  25. Savior: "This was not a targetted attack"
  26. Savior: "Simply dorked by google"
  27. Savior: This was done with the forumrunner exploit
  28. Savior: We got the admin hash:salt from SQLi within forumrunner.
  29. Savior: once cracked
  30. Savior: You can log into the admin control panel and add new plugin
  31. Savior: ajax
  32. Savior: Which would give you RCE on ajax.php
  33. Savior: That would allow you to futherly shell the server and posssibly even root.
  34. Savior: Also
  35. Savior: Since it was time based blind
  36. Savior: SQL injection
  37. Savior: We just sql shelled
  38. Savior: `SELECT username, password, salt FROM pporg_forums WHERE usergroupid = 6;`
  39. Savior: `SELECT username, password, salt FROM pporg_forums WHERE displaygroupid = 6;`
  40. Savior: Since it's vB.
  41. Savior: usergroupid of admins is 6
  42. Savior: Meaning only the admin entries have to be dumped.
  43. Savior: Since it's Time Based Blind you don't want to have to dump much using the SQLi.
  44.  
  45. After gaining initial access, we installed a backdoor and was able to execute commands remotely and attempted to gain elevated access, which is why ProjectPokemon.org suffered from a kernel panic several days prior to writing this. This is when the site first went offline. After the reboot, we replaced the forum link to one that redirects to a docking photo, which was quite amusing to our sick minds.
  46.  
  47. Once that was fixed, we still had command execution and realized that we were restrained by new file permissions, so we took our final laugh and ran `rm -Rf /*`, which deleted anything we had permission to and ultimately broke projectpokemon.
  48.  
  49. Let this be a lesson to those running a website: Quit being a lazy fuck and patch your system. The exploits we used were out for several months yet no one bothered to do anything about it, leaving them vulnerable to attack.
  50.  
  51. Part of the SQL database, proving that we are not bullshitting:
  52. ###############################################################
  53.  
  54. SCV:scv@projectpokemon.org::fe74a220a561ed279743d6453276f008:mbzR^?~5gAm0}|x=Fs<C}b\TJ-x\*v
  55. fenzo666:fenzo666@gmail.com:74.14.6.89:207effe41f45f3cd9ccd6f0245cf70b2:>xeo~
  56. Sabresite:Sabresite@projectpokemon.org:69.230.87.86:cc14a4c1b4a40cd098af4232186edc27:<IZ?VM@G*)Fs/h9M\P+L(2'IpmE2[j
  57. coolbho3000:coolbho3000@gmail.com:68.40.197.26:c33b0dfa174d5dee980f17d712ad863d:u4af!?"zJ!KV./#BYV4|qYq2_MRhx0
  58. Poryhack:poryhack@poryhack.com:97.86.228.167:3db5fb8a970d1ba27da57535e71bde1b:lXfgP=?!p'e1WY/\*N7W!aA00:t5.x
  59. Soldjermon:MarioBrothers708@msn.com:98.202.155.76:174c89fe7e32d3c752499917ff68265c:Cdlaljm2-\vC%_Zqp7x@N3r?e$W8TS
  60. Greencat:greencat@projectpokemon.org:63.110.16.2:9916a38fd14c73d2073e5efb06b551f5:?WHvpbn#u90SkzQ681(gM\OFb2B@nW
  61. Protokoll:adamwn@gmail.com:66.31.63.205:7c0694b10eccc253990f5cb09d1960ca:\OVB*
  62.  
  63. I had wanted to take this personally to GBATemp and explain it better, but I am far too impatient to be waiting for an account verification by the Administrator. The owners of ProjectPokemon deserve the truth, so there it is.
  64.  
  65. By the way, I found some Anime in pokesplash's account, named "Panty and Stockings with Garterbelt". LOL.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement