![]() |
ADULTBLACKHAT: Comus gives away 13k webmaster emails
This post is related to http://www.gofuckyourself.com/showthread.php?t=636295 and is dedicated to sixzero?s friends from:
Russia, China, Australia, New Zealand, Italy, USA, Germany, Amsterdam, Turkey, Korea, Europe, Asia, North America, South America, the Pacific and AfricaLol. Now, if this guy wasn?t so cocky maybe I would?ve just keept my mouth shut. But since he has no clear intention of taking care of this heres how you can get 13k submitter email addresses from Comus. If you read the gfy thread you will see that Comus has problems protecting some files which have no reason to be available to public, and according to sixzero they have no usefull information. Well, you guess, I tend to disagree. EDITED BY VENDZILLA You only need a line to get the emails from the file: awk -F?:? ?print $2′ submitlog.txt|sort -u Wait theres more, see: http://xxxonfire.com/comussites.html thats the list of all sites using Comus which you can easily fetch and download all submitlog.txt files. At the end of it you?ll have 13k unique webmaster emails. If you ever wondered where all your emails are fetched from that could be one source. If you are a webmaster running comus place an .htaccess file in the ct/includes directory with the line: deny from all, till sixzero fixes his shit, if ever. Stay tuned for more tips and tricks :) Tune into http://www.adultblackhat.com for more things from the dark side. |
Ooooooh I mean whoa!
|
This is gonna be good.
|
Quote:
|
Well, that log format is pretty retarded, as is storing the md5 hash.
I've seen worse, though. It's not like you're allowed to directly input the computed MD5, and trying to find a key that matches for a hash collission would still take forever. Interesting post, regardless! |
Damn good thing I don't use it.
Gary |
well......fuck......
|
Drama :Oh crap :Oh crap :Oh crap
|
wow, craziness
|
Quote:
but you've just got 13k emails you can spam. |
I'd hit that.
In fact I think I will right now. LOL j/k |
Raven, Tony has been notified of the problem, He didn't give away those email address's, you did! Tony is working on a patch for that with the new release. It's not very professional to put up a thread with emails like that, you should have contacted Tony with that, or me!
|
Quote:
|
Quote:
Read the original thread. Tony was notified a shitload of time ago. He just needs to drop an .htaccess there no rocket sience. And you think I'm the only one that knows this shit ? You ever wondered were all the spam is comming from ? |
Thanks For The Email List!!! Awesome!@
|
Dammmmmmmmmmmmmmmmmmmmmmmm!!
|
Quote:
|
Lets put his retarted reply here so people know how much he cares.
Quote:
|
The email list can be found by signing up for www.weconvert.com
|
Quote:
:1orglaugh :1orglaugh |
Quote:
But the vulnerability is there for long time and Tony full of himself said its nothing. |
Quote:
|
Quote:
Actually I've been quite nice because I offered the webmasters and Tony the quick solution, wasn't I ? :) Just drop an .htaccess in there. |
Quote:
|
Quote:
|
Quote:
|
Raven Core whats your personal problem with comus and or tony?
im sure if you would have mailed us i would have caught that email too as i do read the support emails... So whats the problem, and whats your real nick? im sure the raven core is a nick you use to stir up shit...as it has 39 posts and is regged in sept 2006 :S |
he registered today, first post he said he was going to start some shit
|
Quote:
I call it full disclosure. |
Quote:
Second Tony's answer to the original thread looked like he doesn't diserve to be announced. Afterall he has all his friends from Russia, China, Australia, New Zealand, Italy, USA, Germany, Amsterdam, Turkey, Korea, Europe, Asia, North America, South America, the Pacific and Africa watching his back. |
Quote:
|
Quote:
Now fix that thing. |
holy shit, is this forreal?
|
I understand Vendzilla's point of view. However, I do not agree that people who used and/or paid for the software shouldn't know this.
I have no experience with Comus, have very limited experience in the adult webmaster world, but have been around the Internet since 9600bps modems. Based on the little information I know, it is unlikely that the people using Comus would have gotten an email from the scripters saying that this information has been exposed. The downside of exposing a hole like this is that you also let people who are going to use the information for bad purposes know about it too. If that's the price people have to pay for getting to know that they've been exposed, then so be it; but by no means should this issue have gone unoticed by the customers of Comus. I do see a clear intention of Raven Core to give Comus a bad name, but he's not lying about the main issue: Comus has a hole. That's a fact. Furthermore, readers should not be distracted by the whole "Comus sucks"-themed posts and they should look and focus on the real problem. Call me Master of the Obvious, but that's the way I see it. The fact that I got to see the links that were posted in the first post confirmed the seriousness of the issue. If I hadn't seen them, I'd be calling bullshit or at least have my doubts of how bad the problem is. :2 cents: |
How far away is the fix?
Bad juju... |
this always happens with full security disclosures, if the makers of the software were warned and hadn't done anything in a timely manner to fix the hole .... then I think you can't blame the guy for making this public.
|
Quote:
|
this hole has been there for a LONG fucking time, and sixzeros has talked about fixing it for the same amount of time....um...hello? when is enough enough? just fix the damn hole already, LOL, stop talking abut how you know it is there, and DO something about it!
|
Vendzilla, if you want to edit his post, you should maybe edit his site reference as the exploit is given there in full.
WG |
Quote:
|
Sig spot secured.
|
Quote:
Furthermore, based on the posts here, this has been around for quite some time and the spectacularization that Raven Core did about the entire thing make me think few people know about it. Again, I don't want to stir the waters more, I completely understand your point of view, but I do not agree that this should go unnoticed. I know that I if were a custmer, I'd like to know about it. |
Quote:
Furthermore, based on the posts here, this has been around for quite some time and the spectacularization that Raven Core did about the entire thing make me think few people know about it. Again, I don't want to stir the waters more, I completely understand your point of view, but I do not agree that this should go unnoticed. I know that I if were a custmer, I'd like to know about it. |
this is really serious!!!
|
Sheez... Typo, "custmer" should read "customer". I'm not that illiterate.
|
o u t c h
|
sig spot :thumbsup
|
Nice thread...
|
1234567890876543212345790
|
That shit is old. I thought he should have fixed this years ago.
|
| All times are GMT -7. The time now is 09:39 AM. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123