Advertisement
RexMundi

Rex Mundi Hoststar.ch Hack

Jun 29th, 2013
5,611
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.44 KB | None | 0 0
  1. Twitter: RexMundi_Anon
  2.  
  3. Our name is Rex Mundi. We previously hacked the Web servers of various European and American companies.
  4.  
  5. Last week, we hacked into the back-end server of Swiss Web hosting company Hoststar (hoststar.ch).
  6.  
  7. We gained access to their customer database as well as the various login/passes used by their customers to connect to the control panels.
  8.  
  9. Unfortunately, Hoststar doesn't seem to particularly value their customers' privacy since they refused to pay us in exchange for the non-disclosure of this data.
  10.  
  11. Therefore, we will publish their customers' data on the Internet on July 3rd unless someone ( a competitor, a mischievous individual ) steps in and decides to purchase this data from us. You can send your offers to [email protected]
  12.  
  13. Here is some of the sample data we collected from the Hoststar servers:
  14.  
  15. SAMPLE DATA:
  16.  
  17. Databases:
  18. admintool_dev
  19. confixx
  20. horde
  21. information_schema
  22. mysql
  23. usr_teb6_5
  24. usr_web1_1
  25. usr_web1_10
  26. usr_web1_12
  27. usr_web1_13
  28. usr_web1_14
  29. usr_web1_15
  30. usr_web1_2
  31. usr_web1_3
  32. usr_web1_4
  33. usr_web1_5
  34. usr_web1_6
  35. usr_web1_7
  36. usr_web1_8
  37. usr_web1_9
  38. usr_web3_1
  39. usr_web4_1
  40. usr_web6_1
  41. usr_web6_2
  42. usr_web6_3
  43. usr_web6_4
  44. usr_web6_6
  45. usr_web6_7
  46. usr_web6_8
  47. usr_web7_1
  48. -----------------------
  49. DB Users:
  50. 'web4'@'127.0.0.1'
  51. 'cja'@'%'
  52. 'confixx'@'localhost'
  53. 'horde'@'%'
  54. 'horde'@'localhost'
  55. 'pma'@'localhost'
  56. 'reverse'@'localhost'
  57. 'root'@'127.0.0.1'
  58. 'root'@'localhost'
  59. 'root'@'tuxapps'
  60. 'web1'@'%'
  61. 'web1'@'localhost'
  62. 'web3'@'127.0.0.1'
  63. 'web4'@'localhost'
  64. 'web6'@'%'
  65. 'web6'@'localhost'
  66. 'web7'@'127.0.0.1'
  67. 'web7'@'localhost'
  68. -----------------------
  69. List of tables in the admindev_tool DB:
  70.  
  71. +---------------------------------+
  72. | `tbl^payback_open_type` |
  73. | `tbl_verre`hnung_zusatz` |
  74. | countries |
  75. | hack_helper |
  76. | marketing |
  77. | tbl_abotyp |
  78. | tbl_aktionen |
  79. | tbl_anrede |
  80. | tbl_apipool |
  81. | tbl_ausnahmen |
  82. | tbl_bestellop |
  83. | tbl_bestellung |
  84. | tbl_bestellung_ssl |
  85. | tbl_bestellung_zusatzdienst |
  86. | tbl_boerse |
  87. | tbl_countries |
  88. | tbl_domain |
  89. | tbl_domaintransfers |
  90. | tbl_email_abo |
  91. | tbl_email_diverses |
  92. | tbl_email_domainmonitoring |
  93. | tbl_email_mahnung_abo |
  94. | tbl_email_mahnung_ssl |
  95. | tbl_email_mahnung_xu@atzdom |
  96. | tbl_email_rueckerstattung |
  97. | tbl_email_ssl |
  98. | tbl_email_zugang |
  99. | tbl_email_zusatzdienst |
  100. | tbl_email_zusatzdomain |
  101. | tbl_kondition |
  102. | tbl_kostenpfl_domain |
  103. | tbl_kunde |
  104. | tbl_kundendaten_aenderungen |
  105. | tbl_mwst |
  106. | tbl_newslette |
  107. | tbl_ordermon |
  108. | tbl_payback |
  109. | tbl_payback_payment |
  110. | tbl_payback_reason |
  111. | tbl_payback_reason_second |
  112. | tbl_payback_type |
  113. | tbl_preise |
  114. | tbl_protokoll |
  115. | tbl_protokoll_watchpoints |
  116. | tbl_rechnungsdaten |
  117. | tbl_registrar |
  118. | tbl_seitenmonitoring |
  119. | tbl_server |
  120. | tbl_server_ip |
  121. | tbl_server_resetlog |
  122. | tbl_server_resetlog_grund |
  123. | tbl_server_resetlog_mitarbeiter |
  124. | tbl_servermonitoring |
  125. | tbl_sperrgrund |
  126. | tbl_sperrung |
  127. | tbl_ssl |
  128. | tbl_status_domain |
  129. | tbl_status_domainaction |
  130. | tbl_status_email |
  131. | tbl_status_installation |
  132. | tbl_status_rechnung |
  133. | tbl_temp |
  134. | tbl_tld |
  135. | tbl_tld_waehrung |
  136. | tbl_tldnewsletter |
  137. | tbl_umfrage_antworten |
  138. | tbl_umfrage_fragen |
  139. | tbl_umfrage_ip |
  140. | tbl_umfrage_teilnehmer |
  141. | tbl_verrechnung |
  142. | tbl_verrechnung_automatisierung |
  143. | tbl_verrechnung_ssl |
  144. | tbl_whois_relay |
  145. | tbl_whois_results |
  146. | tbl_zahlungsart |
  147. | tbl_zusatzdienste |
  148. | tbl_zusatzdomain |
  149. +---------------------------------+
  150.  
  151. --------------
  152.  
  153. Sample data from tbl_payback (bank, bank_nr, iban):
  154.  
  155. Migrosbank, 16970103607, CH73 0840 1016 9701 0360 7
  156. Schwyzer Kantonalbank, 404896-0630, CH9700777004048960630
  157. CREDIT SUISSE, 229701-60, CH82 0483 5022 9701 6000 0
  158. Berner Kantonalbank, 42 3760 0344 2, CH14 0079 0042 3760 0344 2
  159. St. Galler Kantonalbank, 0204.2577.2000, CH81 0078 1020 4257 7200 0
  160. UBS AG, 202-Q8724642.0,
  161. ZKB, 1155-0208.379, CH6000700115500208379
  162. Credit Suisse, 111084-41, CH76 0483 5011 1084 4100 0
  163. Bank CIC Swiss, 64681.1, CH5308710000000646811
  164. UBS AG, 230-409409.40R,
  165.  
  166. -------------
  167.  
  168. Sample customer data:
  169.  
  170.  
  171. 420/476/ d77ea3334bceb132a884e4490e8d9454 MD5: 655118
  172.  
  173. First name Emanuel
  174. Last name Kunz
  175. Firm
  176. Email [email protected] (IMPORTANT: This contact address is used for
  177. informative messages and invoicing!)
  178. Alternative email (this address can be given optionally and serves as a
  179. safety backup for making contact.)
  180. Address Tösswiesenstrasse 35
  181. Postcode / Zip code 8413
  182. Location Neftenbach
  183. Country Switzerland
  184. Language German
  185. Telephone 1 078 748 30 36
  186. Telephone 2 (This number can be given optionally.)
  187. Fax
  188.  
  189.  
  190. 418/474/ 38c9f504869ce3c57260bfde6723323b MD5: 893410
  191.  
  192. Title Herr
  193. First name Murali
  194. Last name Sitaraman
  195. Firm
  196. Email [email protected] (IMPORTANT: This contact address is used for
  197. informative messages and invoicing!)
  198. Alternative email (this address can be given optionally and serves as a
  199. safety backup for making contact.)
  200. Address Eigerplatz 10
  201. Postcode / Zip code 3007
  202. Location Bern
  203. Country Switzerland
  204. Language German
  205. Telephone 1 +41 79 329 37 45
  206. Telephone 2 (This number can be given optionally.)
  207. Fax
  208.  
  209.  
  210. 398/454/ 4ebb7c232cc8d69b1d435a6e679d470a MD5: jazzyhost
  211.  
  212. Title Herr
  213. First name Philippe
  214. Last name Mooser
  215. Firm
  216. Email [email protected] (IMPORTANT: This contact address is used for
  217. informative messages and invoicing!)
  218. Alternative email (this address can be given optionally and serves as a
  219. safety backup for making contact.)
  220. Address Wiestibodenweg 19
  221. Postcode / Zip code 3920
  222. Location Zermatt
  223. Country Switzerland
  224. Language German
  225. Telephone 1 0792252571
  226. Telephone 2 (This number can be given optionally.)
  227. Fax
  228.  
  229. 69847/73337/ d4bc5e475905fd6b54c6e821bedf76aa
  230.  
  231. Title Firma
  232. First name Euridice
  233. Last name Imfeld-Maclean
  234. Firm Solostyle Dance
  235. Email [email protected] (IMPORTANT: This contact address is
  236. used for informative messages and invoicing!)
  237. Alternative email [email protected] (this address can be given
  238. optionally and serves as a safety backup for making contact.)
  239. Address St. Niklausenstrasse 102
  240. Postcode / Zip code 6047
  241. Location Kastanienbaum
  242. Country Switzerland
  243. Language German
  244. Telephone 1 079 2099313
  245. Telephone 2 079 2099313 (This number can be given optionally.)
  246. Fax
  247.  
  248. Sample customer invoice:
  249.  
  250. Solostyle Dance
  251. Euridice Imfeld−Maclean
  252. St. Niklausenstrasse 102
  253. 6047 Kastanienbaum
  254. Fraubrunnen, 21. Juni 2013
  255. Rechnungsdatum: 21.06.2013
  256. Ihre Bestellung vom: 21.06.2013
  257. UID Nummer: CHE−112.417.413 MWST
  258. Seite 1/1
  259. Rechnung: 990073337
  260. Sehr geehrte Damen und Herren
  261. Diese Rechnung wurde von Ihnen am 24.06.2013 einbezahlt und gilt daher nur
  262. als Beleg.
  263. Auftragsnummer
  264. Bezeichnung
  265. Anzahl
  266. Einzelpreis
  267. Betrag CHF
  268. 990073337
  269. Webhosting:
  270. StarEntry
  271. 12
  272. 5.90
  273. 70.80
  274. 30'000 MB, 20 Domains
  275. Domainname:
  276. solostyledance.ch
  277. 0.00
  278. Aboperiode:
  279. 21.06.2013 − 20.06.2014
  280. Zwischensumme inkl. MWSt.
  281. 70.80
  282. Zwischensumme exkl. MWSt.
  283. 65.55
  284. MWSt. 8%
  285. 5.25
  286. Rechnungstotal inkl. MWSt. in CHF
  287. 70.80
  288. Zahlungskondition: Diese Rechnung wurde bereits bezahlt.
  289. Besten Dank für Ihren Auftrag
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement