Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- FULL CONVERSATION OF STEVEN V (InfinitySN CEO) on AUG 29th prior to the hacks, being warned. He was told exactly what was wrong and disregarded. Read and share.
- AUG 29th 2017
- Steven Vulich
- Hi John Doe
- I would like to see what you have found in your Vegas files and anything else you have as you are the one giving them their information. ??
- Steven Vulich
- Everything you are passing as true, is in fact false. It's not on a live server yet so all you have shown is your email confirmation of signing up. Is this your proof? If so, you are totally wrong, also, if you are trying to hack our system you will be prosecuted to the fullest extent of the law. You are welcome to sign up and check us out legally when we are on a live server. Once again I will ask that you refrain from hacking tactics and passing bad information about ISN to others.
- 11:25AM
- Steven Vulich
- Hello?
- Steven Vulich
- Steven
- You missed a call from Steven.
- 11:44am
- Call Back
- Steven Vulich
- Steven
- You missed a call from Steven.
- 12:23pm
- Call Back
- You accepted Steven's request.
- John Doe
- Steven
- ?? you know you are full of shit. it is live its hiding behind a bootstrap page.
- Steven Vulich
- If you have concern then let's talk about it
- John Doe
- lets
- Steven Vulich
- Steven
- You missed a call from Steven.
- 12:41pm
- Call Back
- Steven Vulich
- Trying to call
- John Doe
- we will talk over text so everything is recorded. though text
- Steven Vulich
- Easier than getting things mixed up on text
- Robert
- it wont.
- Steven Vulich
- Why are you attacking ISN?
- John Doe
- so i was tossed your link from an anon contact asking me to see if it was safe to use. the 1st thing i did. was register.
- wait
- Steven Vulich
- I woke up to this stuff.
- John Doe
- wait
- Steven Vulich
- It's not live
- John Doe
- it's active
- Steven Vulich
- You cannot fully register
- John Doe
- and i registerd
- Steven Vulich
- The sign up works but not fully, and was redeveloped. Once live all that will go away
- John Doe
- well its live for me. lets just say this even if you don't think it is. where did you purchase this script.
- because i know you did not write it.
- Steven Vulich
- I won't discuss certain things here for security reasons. I'm sure you understand
- John
- Steven Vulich
- Which script
- John Doe
- your social network script.
- Steven Vulich
- I'm not a coder. I have a full staff for that
- I only dab in code
- Steven Vulich
- John Doe
- your full staff is dicking you. sorry to say.
- Steven Vulich
- How so?
- John Doe
- your clients passwords should be salted and they are not. they are only MD5
- Steven Vulich
- Don't know what MD5 is
- If you have identified something then let me know and I can forward it to my staff
- ??
- I would hope you want to help
- Not bash it to people.
- It's not on a live server, so you are looking at old code
- When it's live all of that is changing.
- John Doe
- hold on had a lagg.
- Steven Vulich
- Yup
- John Doe
- ok so when you go into your sql the actual database in Mysql your going to find this
- users` (id, username, password, status, created_on, `updated_on
- Steven Vulich
- I hope you understand that because you are using this for record I can only say so much.
- John Doe
- under password you will find
- username id user password
- Steven Vulich
- Your not hacking the site are you?
- John Doe
- the password is MD5 crypted.
- not Salt,MD5
- any liberal asshole with a brain can crack it using crack station. and to answer no i am not.
- Steven Vulich
- Ok
- John Doe
- i poked because someone has some concerns about the legitimacy of it.
- Steven Vulich
- So come to me with a solution to this and I will pass it to my staff. ??
- So let's help and not bash
- John Doe
- Scrap the project. there are over 700 sql injections. go buy like Social Fox
- SocialFox is a great script.
- and i would back it
- Steven Vulich
- I'm a good guy that will be attacked and that's fine, but let's have a solution instead of doing it your way. It's not cool.
- Scrap the network?
- Seriously? That will never happen.
- John Doe
- no not the network the Script.
- Steven Vulich
- What do you mean the script
- John Doe
- the php script
- Steven Vulich
- Php is common language
- John Doe
- no
- Steven Vulich
- That I know
- John Doe
- i said the php script
- everything from database to /home/public_html/ files
- Steven Vulich
- If I had your info I would pass it along to my staff
- John Doe
- https://www.phpfox.com/
- go there and check that out
- do you live in commieforna?
- Steven Vulich
- I understand you are a coder possibly, but I do not understand the language on code. These guys work for a major establishment and should know what they're doing.
- John Doe
- if they did why would i be adamant about your security problems. i hope your not paying them. and i hope you did not get them off of like any php coder website.......
- Steven Vulich
- What do you think of Facebooks script?
- Not at all, they are reputable
- John Doe
- i can say that it does not leak user information, like database user information.
- Steven Vulich
- They didn't use any open source for our data base
- John Doe
- you dont have to.
- Steven Vulich
- What's the solution
- And I will pass it along
- John Doe
- if you dont mind me asking who are you going though to build this. i admire your idea its why i am asking but you cannot just toss a script and say hay its safe join... with out actually doing the pentesting yourself.
- Steven Vulich
- Testing has been performed on the current database
- I can't say until I can confirm who you are. I'm sure you understand.
- John Doe
- no no no i mean on the website its self.
- Steven Vulich
- Yes
- Testing on security?
- This would be easier on the phone. Lol
- John Doe
- what do you mean who i am. i am the one who is telling you that your script has over 700 flaws.
- over 700 bugs
- if you will
- Steven Vulich
- Call?
- John Doe
- no.
- Steven Vulich
- If I will
- ?
- John Doe
- no mic no camera this is a desktop pc
- Steven Vulich
- No phone?
- John Doe
- i have a phone but i am not going to give you the opportunity to grab my ip though VOIP.
- Steven Vulich
- I'm sure I could put a program on Facebook and identify a billion flaws. I need to know more. And appreciate you trying to help.
- Why would I want your ip?
- I'm not like that
- John Doe
- because i do not know if you are a Libscum trying to track me. i dont know if you are going to try to cause me harm do to finding flaws in your site i dont know you at all.
- Steven Vulich
- Look, I'm a veteran and served my country, a prior police officer for good intent of society. I have no hidden intent to do anything like that.
- And a family man
- I am kind of offended by the assumption of that, but understand you do not know me personally
- John Doe
- lol do you know how many times i have heard that? and come to pass that it was a fed.. and i cut communication with them.
- John Doe
- look i am not out here to bash your idea but if you are what i think you are. then its not a good idea to just publish a website and have people join with out testing it 1st i tested for my own security i wanted to know if it was true did you put the google ads up on that if you did they are causing lag. i had to use AdBlocker just to get the site not to lagg. if you want suggestions i have given them to you. PHPFox is one of the best social network scripts out there use it also buy SSL for your website and get it off of ubuntu.
- John Doe
- the Apache PHP is outdated. - you may only have 2 ports open but they are not locked down. 80,22 change your SSH port to something like 1000 or something 22 is to common.
- Steven Vulich
- It lags because it's not fully live.
- From what I understand
- Once live it will be smooth
- John Doe
- no its going to lag worse when its live and you have over 300 people accessing it at one time. how much bandwidth do you currentlly have per month?
- no it wont. i promise you on this.
- Steven Vulich
- Do you know Bob or Vincent? If you do then I don't need to say their last names.
- John Doe
- nope
- Steven Vulich
- If not no worries
- Steven Vulich
- Hmm, ok. So what do you think I should do from here?
- And because I don't know you or your past, why should I scrap the script at you telling me to? Curious
- If you said that to mark zuckerberg he would laugh in your face
- Just curious
- John Doe
- i am just looking out for innocent people trying to make a difference in the world. tell people that the date is going to be moved up. go look in to phpFox, and start adding security via. .HTaccess and .STaccess files blocking proxys and scanners
- Steven Vulich
- From my point of view. Why should I do something that drastic because you so to do it? I'm sure you understand me asking that
- Robert
- thats a 1st part. buy a SSL Cert for https:// and then come back and ask me to poke it.
- Steven Vulich
- Moving a launch date is huge, I can't just because a stranger that I don't know says do it.
- Ok
- We have an ssl
- John Doe
- you do not have to take my word but when your website is compromised by some lib scumbag trying to cause hell for patriots thats 100% on you.
- its not installed then.
- my browser would inform me on that.
- Steven Vulich
- How can you help protect it?
- John Doe
- thats not a relative question. as i am not part of your staff.
- the question is how Can I Secure my website.
- do you run Cpanel?
- i never looked
- Steven Vulich
- I caution you to not hack into our systems
- If that's what s your referencing
- John Doe
- im not hacking anything.
- i was not hired to hack anything bud,
- i was requested - to see if the site was secure and safe to use.
- my 1st advice would be. go on google and find out how to hide open directory's. maybe add index.html files with redirects to main page or 404 not found pages.
- i am watching one of your videos. on your page you seem like a legit guy trying to do something legit. but you need to fix fix fix.
- if you want my advice! just give me the go ahead to pen test further. and i can report back to you what i find. - call it humanitarian work. but i am not blasting it i actually thing its a great idea. but if its not tight you will run in to large groups of problems.
- Think*
- Steven Vulich
- I really do appreciate that and I will forward that to my team to see if maybe they overlooked something. They are doing security checks for the last couple days and are just about done. I will have them go through with a finer tooth comb to ensure everything is protected. ??????
- I really am a legit guy and doing this for everyone and have only best intent with it all. ??????
- More and more people will see that as time passes and will hopefully have a trusted community. ????????
- I do appreciate your feedback and having the ability to address this concern Robert. ?? I am always willing to take in help when it's with good intent.
- Let me have my team go through and recheck as they move forward. If you are as good as I think you may be I may have a job for ya down the road. ????. Not sure if your open to that but I will always be in need of great developers and security staff. ????
- John Doe
- do you? because i just seen some concerning things on your fb page. kinda made me feel as if you have double standards! when it comes to people expressing something other then what you want to hear.... but it could be me.
- Steven Vulich
- Which part? Might be a misunderstanding
- John Doe
- blocking people and making everyone you know block them to. so they cannot see what they have to say.
- Steven Vulich
- I go on the fly on my videos
- Only when it's false information. Not censoring on opinions
- John Doe
- you do know haters are your biggest fans right... this is what i have learned over the past 15 years ??
- Steven Vulich
- There is no censoring
- John Doe
- they spread the word faster then normal users.
- then the haters register to see whats up.
- you need to block bots. your going to get a ton of them.
- you should let people hate. ?? and spread false narratives to the people it will bring in more.
- but fix your security. and i will be back in about a month to scan again. if i manage to get access to sensitive parts. i will let you know block and secure. trust me. i have 8 vulnerability they are only on 1 page. ?? Register.php ?? but thats a false positive. i put it there.
- also in blog post Turn off Source, because there is script that can be posted to bypass hp sanitation.
- PHP Sanitation.
- go though your php.ini file have them lock it down. and update GD Librarys apache & php.
- Steven Vulich
- I can never agree with anyone to spread hate. Morally that is wrong. I can't be about that.
- John Doe
- hate? no they have an opinion on your website. you should let them voice it.
- you even said it here Disappointing times in Social Media?? InfinitySN is going live at the end of the month! NO CENSORING?? FREEDOM OF SPEECH IS ALWAYS PROTECTED?? See you soon!! Get ready to connect with Like-Minded People on a new Social Network??????????????
- you know people are going to come cause some shit.
- lol
- i just hope you lock down anything you need to lock down before hand i have seen this happen time and time again. its why i made a non bias website! its not even a social network its a money making website lol. no chat i removed it do to people causing problems.
Advertisement
Add Comment
Please, Sign In to add comment