Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- //// ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ $$$$$ * !XBLS.NiNJA BUG BOUNTY! * $$$$$ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ \\\\
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ UPDATED: JUNE 2019 - BIG REWARDS! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- Calling all penetration testers, whitehats, bl4ckh4t h4ck3rz, and script kiddies!
- Anyone who finds a vulnerability on either of my servers will be eligible to win a bounty after privately disclosing and demonstrating an attack.
- Email PoC or proof of successful attack to [email protected] or join https://chat.xbl.ninja and message an owner
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ REWARDS FOR EACH CATEGORY ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- * shell running as root or user "ninja" on VPS #1: $4000 AND 2 x *free* lifetime on NiNJA (any two consoles, $1450/ea) - combined $6900 value!
- * shell running as root on VPS #2: $4000 AND 2 x *free* lifetime on NiNJA (any two consoles, $1450/ea) - combined $6900 value!
- * SQL injection on VPS #1: $2000 (full WRITE access to sensitive columns/tables)
- * SQL injection on VPS #1: $1000 (full read access to sensitive columns/tables)
- * SQL injection on VPS #2: $1750 (full WRITE access to sensitive columns/tables)
- * SQL injection on VPS #2: $750 (full read access to sensitive columns/tables)
- * Write access to local files (either VPS): $1750 (sensitive source code or password hashes)
- * Remote file inclusion (either VPS): $1600 (shell or perl/python/php/c bot execution)
- * Local file inclusion (either VPS): $1600 (sensitive source code or password hashes)
- * Cross-site scripting (either VPS): $500 (must be harmful in some way, message boxes/dumb shit don't count, redirection DOES COUNT!)
- * DoS/DDoS: LOL DON'T MAKE ME LAUGH YOU SAD SCRIPT KIDDIES
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FAQ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- Q: What kind of CDN/WAF are you running?
- A: The main NiNJA website (VPS #2) is behind Cloudflare CDN+Sucuri CDN/WAF. VPS #1 is behind Cloudflare CDN.
- Q: What kind of DDoS protection do you have?
- A: Both servers are on a USA-based port mirror of Voxility, and both have it's full DDoS mitigation capacity (~1000gbps).
- Q: Do I get anything for DoS/DDoS?
- A: See above. LOLNO.
- Q: So what appliations/services do you have running? What version are they?
- A: Check below!
- Q: Giving us so much information takes the fun out of it/might be fake/seems stupid. Why?
- A: Providing all this information is giving you a higher chance of success. I want to find and fix any bugs. The info is real.
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- VPS #1 (primary.xbls.ninja // tcp socket listener, http listener, and administration panel):
- Kernel: 4.19.0-5-amd64-grsec-xbls.ninja-is.too.1337-weed.is.tight.420.blaze.it SMP Sat Jan 12 15:35:51 MDT 2019 x86_64 GNU/Linux
- Software versions:
- * OpenSSH_7.9p1 Debian-10
- * OpenSSL 1.1.1b 26 Feb 2019
- * nginx/1.14.2
- * PHP 7.0.33-0+deb9u3 (fpm-fcgi) (built: Mar 8 2019 10:01:24)
- * Exim version 4.92 #5 built 10-May-2019 15:37:36
- * mysqld Ver 5.7.22 for Linux on x86_64 (MySQL Community Server (GPL))
- * Python 2.7.16-2
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- VPS #2 (www.xbls.ninja // website, rocketchat, rocketchat-server):
- Kernel: 4.19.0-5-amd64-grsec-xbls.ninja-is.too.1337-weed.is.tight.420.blaze.it SMP Sat Jan 12 14:25:17 MDT 2019 x86_64 GNU/Linux
- Software versions:
- * OpenSSH_7.9p1 Debian-10
- * OpenSSL 1.1.1b 26 Feb 2019
- * nginx/1.14.2
- * PHP 7.0.33-0+deb9u3 (fpm-fcgi) (built: Mar 8 2019 10:01:24)
- * Exim version 4.92 #5 built 10-May-2019 15:37:36
- * mysqld Ver 5.7.22 for Linux on x86_64 (MySQL Community Server (GPL))
- * WordPress 5.2.x
- * WooCommerce 3.6.x
- * Other WP plugins: lol find out yourself, bozo
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- VPS #3 (api.xbls.ninja // internal, internet-isolated api calculation server):
- Kernel & software version info = 2spooky4u
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement