• Guest
HabraHabr
  • Main
  • Users

  • Development
    • Programming
    • Information Security
    • Website development
    • JavaScript
    • Game development
    • Open source
    • Developed for Android
    • Machine learning
    • Abnormal programming
    • Java
    • Python
    • Development of mobile applications
    • Analysis and design of systems
    • .NET
    • Mathematics
    • Algorithms
    • C#
    • System Programming
    • C++
    • C
    • Go
    • PHP
    • Reverse engineering
    • Assembler
    • Development under Linux
    • Big Data
    • Rust
    • Cryptography
    • Entertaining problems
    • Testing of IT systems
    • Testing Web Services
    • HTML
    • Programming microcontrollers
    • API
    • High performance
    • Developed for iOS
    • CSS
    • Industrial Programming
    • Development under Windows
    • Image processing
    • Compilers
    • FPGA
    • Professional literature
    • OpenStreetMap
    • Google Chrome
    • Data Mining
    • PostgreSQL
    • Development of robotics
    • Visualization of data
    • Angular
    • ReactJS
    • Search technologies
    • Debugging
    • Test mobile applications
    • Browsers
    • Designing and refactoring
    • IT Standards
    • Solidity
    • Node.JS
    • Git
    • LaTeX
    • SQL
    • Haskell
    • Unreal Engine
    • Unity3D
    • Development for the Internet of things
    • Functional Programming
    • Amazon Web Services
    • Google Cloud Platform
    • Development under AR and VR
    • Assembly systems
    • Version control systems
    • Kotlin
    • R
    • CAD/CAM
    • Customer Optimization
    • Development of communication systems
    • Microsoft Azure
    • Perfect code
    • Atlassian
    • Visual Studio
    • NoSQL
    • Yii
    • Mono и Moonlight
    • Parallel Programming
    • Asterisk
    • Yandex API
    • WordPress
    • Sports programming
    • Lua
    • Microsoft SQL Server
    • Payment systems
    • TypeScript
    • Scala
    • Google API
    • Development of data transmission systems
    • XML
    • Regular expressions
    • Development under Tizen
    • Swift
    • MySQL
    • Geoinformation services
    • Global Positioning Systems
    • Qt
    • Dart
    • Django
    • Development for Office 365
    • Erlang/OTP
    • GPGPU
    • Eclipse
    • Maps API
    • Testing games
    • Browser Extensions
    • 1C-Bitrix
    • Development under e-commerce
    • Xamarin
    • Xcode
    • Development under Windows Phone
    • Semantics
    • CMS
    • VueJS
    • GitHub
    • Open data
    • Sphinx
    • Ruby on Rails
    • Ruby
    • Symfony
    • Drupal
    • Messaging Systems
    • CTF
    • SaaS / S+S
    • SharePoint
    • jQuery
    • Puppet
    • Firefox
    • Elm
    • MODX
    • Billing systems
    • Graphical shells
    • Kodobred
    • MongoDB
    • SCADA
    • Hadoop
    • Gradle
    • Clojure
    • F#
    • CoffeeScript
    • Matlab
    • Phalcon
    • Development under Sailfish OS
    • Magento
    • Elixir/Phoenix
    • Microsoft Edge
    • Layout of letters
    • Development for OS X
    • Forth
    • Smalltalk
    • Julia
    • Laravel
    • WebGL
    • Meteor.JS
    • Firebird/Interbase
    • SQLite
    • D
    • Mesh-networks
    • I2P
    • Derby.js
    • Emacs
    • Development under Bada
    • Mercurial
    • UML Design
    • Objective C
    • Fortran
    • Cocoa
    • Cobol
    • Apache Flex
    • Action Script
    • Joomla
    • IIS
    • Twitter API
    • Vkontakte API
    • Facebook API
    • Microsoft Access
    • PDF
    • Prolog
    • GTK+
    • LabVIEW
    • Brainfuck
    • Cubrid
    • Canvas
    • Doctrine ORM
    • Google App Engine
    • Twisted
    • XSLT
    • TDD
    • Small Basic
    • Kohana
    • Development for Java ME
    • LiveStreet
    • MooTools
    • Adobe Flash
    • GreaseMonkey
    • INFOLUST
    • Groovy & Grails
    • Lisp
    • Delphi
    • Zend Framework
    • ExtJS / Sencha Library
    • Internet Explorer
    • CodeIgniter
    • Silverlight
    • Google Web Toolkit
    • CakePHP
    • Safari
    • Opera
    • Microformats
    • Ajax
    • VIM
  • Administration
    • System administration
    • IT Infrastructure
    • *nix
    • Network technologies
    • DevOps
    • Server Administration
    • Cloud computing
    • Configuring Linux
    • Wireless technologies
    • Virtualization
    • Hosting
    • Data storage
    • Decentralized networks
    • Database Administration
    • Data Warehousing
    • Communication standards
    • PowerShell
    • Backup
    • Cisco
    • Nginx
    • Antivirus protection
    • DNS
    • Server Optimization
    • Data recovery
    • Apache
    • Spam and antispam
    • Data Compression
    • SAN
    • IPv6
    • Fidonet
    • IPTV
    • Shells
    • Administering domain names
  • Design
    • Interfaces
    • Web design
    • Working with sound
    • Usability
    • Graphic design
    • Design Games
    • Mobile App Design
    • Working with 3D-graphics
    • Typography
    • Working with video
    • Work with vector graphics
    • Accessibility
    • Prototyping
    • CGI (graphics)
    • Computer Animation
    • Working with icons
  • Control
    • Careers in the IT industry
    • Project management
    • Development Management
    • Personnel Management
    • Product Management
    • Start-up development
    • Managing the community
    • Service Desk
    • GTD
    • IT Terminology
    • Agile
    • Business Models
    • Legislation and IT-business
    • Sales management
    • CRM-systems
    • Product localization
    • ECM / EDS
    • Freelance
    • Venture investments
    • ERP-systems
    • Help Desk Software
    • Media management
    • Patenting
    • E-commerce management
    • Creative Commons
  • Marketing
    • Conferences
    • Promotion of games
    • Internet Marketing
    • Search Engine Optimization
    • Web Analytics
    • Monetize Web services
    • Content marketing
    • Monetization of IT systems
    • Monetize mobile apps
    • Mobile App Analytics
    • Growth Hacking
    • Branding
    • Monetize Games
    • Display ads
    • Contextual advertising
    • Increase Conversion Rate
  • Sundry
    • Reading room
    • Educational process in IT
    • Research and forecasts in IT
    • Finance in IT
    • Hakatonas
    • IT emigration
    • Education abroad
    • Lumber room
    • I'm on my way

The story of a little hacking, or an adequate bugBaunty local Internet provider

3r3116. Introduction of 3r3117. 3r3122.  
Good day, friends. This small hacking story happened to me in the middle of August of this 18th year. The story began in a small town in the Krasnodar Territory, with a tyrnet bad, there is 4g, but this is all wrong, here in the country one could only dream of wires. And just recently this miracle happened, wires were sent to my area, and I immediately ran to connect 100 Mbps over fiber, 8k for connecting with the tariff. 3r3122.  
3r3122.  
3r3116. Curiosity
3r3122.  
Joy full pants, good tyrnet, a small local provider, it has the status of a local provider, out of curiosity, I rummaged around on the lux, looked at what subdomains there were, and I found a subdomain 3r31616. admin.domain_provider.com/3r317. which immediately threw on the login.php authorization form, F1? opened it looked what was loaded there, looked js, there were interesting links in ajax requests "/? user_id =" + id, just copying the link and typing a random number, I threw out the user data in table: 3r3122.  
3r3122.  
Passport number /number
 
Issued by 3r3122.  
Issue date 3r3122.  
FULL NAME
 
address of residence 3r3122.  
phone number 3r3122.  
Login (from tyrnet)
3r3122.  
“Oh, I can't be,” I stuck the library into head jq, spent 5 minutes writing ajax request in a loop and spitting it out into the body of the page, outputting 2?000 entries. 3r3122.  
3r3122.  
Quickly ctrl + f, drove his name, and yes I was there. My surprise, i.e. freely available hung user data. I looked at the rest of the links in ajax requests, there was a lot of everything, for some control of switches, for some reloads of something, because it spat out it was difficult to understand what was responsible for what, it was not so interesting to me. 3r3122.  
3r3122.  
It was already late, I thought, “I’ve developed fools,” and went to bed. 3r3122.  
3r3122.  
On the trail. I started to think about the day, it’s like no joke, and I can be held criminally liable for it, but in our country they put up reposts. It was worth noting that I didn’t plan to do anything of this kind, otherwise I would have secured myself with vpn /proxy. And on the other hand, if they leave such holes, they are unlikely to look at the logs. And on the third hand, it is better if I tell them what they will find my tracks, and then they will not talk to me for sure. 3r3122.  
3r3122.  
3r3116. Point played 3r3117. 3r3122.  
I google on Habré the name of the organization, I find the organization, with a few turnips, there is nothing interesting in them, I’m looking at who is in this organization, I google again, I find the developers in VK. I am writing: “Hello, and why are 2?000 users registered with all their data publicly available?”. He writes that he informed the head. Ok, I think I did my job. 3r3122.  
3r3122.  
3r3116. Payback for curiosity
3r3122.  
I woke up at about 10 o'clock in the morning, I have to work, I am front-facing. Knocking at the gate, looking out the window, looking at the little red machine, 3 people, I recognize one of the developers from the pics, I think that's all, 3r380. and I saved all the records, just as a html page on the desktop, quickly shift + del> confirm [/s] , I take a cigarette, I take a snout, I go, I think, now it will be fun, I smoke, I go out. 3r3122.  
3r3122.  
- Hello 3r3122.  
- Hello 3r3122.  
- I understand you understand where we come from
 
- Yes, I already understood - 3r380. I pull smoke [/s] 3r3122.  
- I want to pond you (shows the phone) conversation, I record
 
- Good 3r3122.  
- You yesterday downloaded our database
 
- No, I did not download, I found a vulnerability, and informed you. 3r3122.  
- Our IT specialists have data that you downloaded this database
 
- This is impossible, you can only see that I watched her
 
- We are determined to solve it quietly, peacefully, our IT people can make sure that you have not saved it? 3r3122.  
- In principle, yes, do you want to go pick up a sistemnik or do I have everything to check in my house? 3r3122.  
IT professional says:
 
- It is better if we take a sistemnik and check in the office 3r3-3122.  
- Good 3r3122.  
3r3122.  
Here you can argue with my decision, on the one hand, you are such people, I haven’t downloaded anything, go for a walk, I will not give my systemist, you prove to me what you can do to me, on the other hand it’s dangerous, I’ll be better talk to them than to the police. You can understand them, they are crap from the sesyurity, they have the right to make sure. I made the decision to talk to them better. 3r3122.  
3r3122.  
We go home with them, cut down a sistemnik, pull jeans, sneakers, go to the office, get out of the car, go all together to the director. Different questions, why did you do it, why, how did you do it, I said that their base was in the public domain, and anyone could do it. We talked, we are going to check the sistemnik, these specialists looked at everything on the tin, the cart, downloaded the prog, searched for the keywords on the tin, I tell them, and will you check the phone? I could save on the phone, and the clouds? I could save in Google Drive. In general, they looked purely for a tick, I watched and hoped that they would not guess to download some kind of data recovery prog, and see what was removed. (The question is in the comments, and with ssd the data is also easily recovered as from the hard one?) 3r3122.  
3r3122.  
3r3116. Epilogue
3r3122.  
I sat for 2 hours watching their attempts. I took the sistemnik, went with the lawyer to the director, suggested that I sign an agreement on which I was allegedly hired retroactively, to search for vulnerabilities in their system, they say but we will not pay you, I read the agreement before signing (but ask for a copy guessed), they say we will give you a year of free internet as payment, ok. They took me home. 3r3122.  
3r3122.  
As my colleague noted later, it’s good that the year of free Internet and not a year is conditional. 1500 is worth a month of unlimited, multiply by 1? so much I had in my account in lx when I returned home. 3r33130.
! function (e) {function t (t, n) {if (! (n in e)) {for (var r, a = e.document, i = a.scripts, o = i.length; o-- ;) if (-1! == i[o].src.indexOf (t)) {r = i[o]; break} if (! r) {r = a.createElement ("script"), r.type = "text /jаvascript", r.async =! ? r.defer =! ? r.src = t, r.charset = "UTF-8"; var d = function () {var e = a.getElementsByTagName ("script")[0]; e. ): d ()}}} t ("//mediator.mail.ru/script/2820404/"""_mediator") () (); 3r3128.
3r33130.

It may be interesting

  • Comments
  • About article
  • Similar news
This publication has no comments.

weber

Author

6-11-2018, 04:19

Publication Date

Development / Programming

Category
  • Comments: 0
  • Views: 286
Bad advice to a contract electronics
Monitoring Windows servers on pure MS
I, Python and from the work groan
Translation of Andrew Un’s Passion for
Causes of failure of hosters when added
Upgrade the matrix of the TN-> IPS
Write a comment
Name:*
E-Mail:


Comments
your content ideas are supported by UK discount codes team
Today, 11:20

davidphilp

I would ask to share a translated version also.


Really thanks and appreciated by
Singapore Immigration Consultant
Today, 10:59

davidphilp

Visit Our website If You Need Custom thanksgiving couple shirts, Shirts For Your Company, Family Or Friends & We’ll Cook Something Special for you!
Yesterday, 21:10

raymond weber

Inursing test bank was very pleased  to find this site.I wanted to thank you for this great read!! I definitely  enjoying every little bit of it and I have you bookmarked to check out new  stuff you post.  
Yesterday, 18:20

taxiseo2

You completed certain  reliable points there. I did a search on the subject and found nearly all  persons will agree with your blog.  
nursing test bank
Yesterday, 18:04

taxiseo2

Adv
Website for web developers. New scripts, best ideas, programming tips. How to write a script for you here, we have a lot of information about various programming languages. You are a webmaster or a beginner programmer, it does not matter, useful articles will help to make your favorite business faster.

Login

Registration Forgot password