Page 4 of 5 FirstFirst 12345 LastLast
Results 31 to 40 of 41

Thread: HDBits Bitmetv exploit

  1. #31
    DISABLED PRIVS BT Rep: +8BT Rep +8
    Join Date
    Jan 2007
    Posts
    350
    Quote Originally Posted by kalpesh View Post
    By Hdbits
    In response to the random claim that we know all your passwords and can/will use them on bitmetv if you have the same password there, I would like to point out that the only trace of your password stored in the database is your passhash.
    This is a 128bit md5 hash of your password and a 20 character long random string.
    For those of you who that makes no sense to, it means all that is stored is something like 1055d3e698d289f2af8663725127bd4b....which cannot be reversed back into your password.
    Yes, I already did it for one doubter here: https://filesharingtalk.com/vb3/p-ple...39/postcount22


    Quote:
    Originally Posted by zaguar
    Really? So you've magically found a way to reverse the MD5 hashing process? If so, tell me what this string is: 1cbd3b9800b88f9cb98755e40a15c813 . Thanks.

    It reverses to Liar. Found with the help of the first google hit on the search "reverse md5 hash": http://md5.benramsey.com/

    On topic: I think a lot less of HDBits that they didn't come clean about what Valerio was doing.

  2. BitTorrent   -   #32
    kayvanblue's Avatar Poster BT Rep: +11BT Rep +11BT Rep +11
    Join Date
    Oct 2005
    Location
    Tehran-iran(toronto)
    Age
    41
    Posts
    323
    i hope it s not true

  3. BitTorrent   -   #33
    maxpower76's Avatar thegoodguy BT Rep: +7BT Rep +7
    Join Date
    Sep 2006
    Location
    UK
    Posts
    369
    how do i found out about my hash password

  4. BitTorrent   -   #34
    Quote Originally Posted by maxpower76 View Post
    how do i found out about my hash password
    You cant get what it is. Its only stored on the sites database itself it isnt shown to anyone for the most part unless they have db access.
    Or if they find a exploit on the site like someone else who posted in this thread does to other sites.

    BTW They were hacked by the clown in refrence. There was about 4 pages of logs to confirm what was said. I however will not repost anything said.
    And in responce to the passhash comment I made a similiar statement in another thread about how easy that was about 2 days ago.

  5. BitTorrent   -   #35
    Jaits's Avatar n00b BT Rep: +3
    Join Date
    Apr 2006
    Posts
    172
    Quote Originally Posted by maxpower76 View Post
    how do i found out about my hash password

    if they dont use salting, from ur cookies... if they do its impossible to get the passhash from the cookie...

  6. BitTorrent   -   #36
    Poster BT Rep: +14BT Rep +14BT Rep +14
    Join Date
    Feb 2007
    Posts
    450
    why they do this? sounds daft

    i have never had an account with them but do have lots of sites with same username

  7. BitTorrent   -   #37
    maseunit's Avatar Poster BT Rep: +1
    Join Date
    Apr 2006
    Location
    Oswego, NY
    Age
    39
    Posts
    179
    Yeah sketchy

  8. BitTorrent   -   #38
    DISABLED PRIVS BT Rep: +8BT Rep +8
    Join Date
    Jan 2007
    Posts
    350
    New info I just happened upon on this. Matt865, an admin at x264 posted the following about the situation:

    Quote Originally Posted by Matt865
    They may or may not store your passwords insecurely and use them, but what is true is that their admin Valerio (quoting him), "Made a rss feed for bitmetv so you can download stuff from there without an account." This caused a few members to loose their accounts there. [IMG]https://f******.net/pic/smilies/no.gif[/IMG]
    I don't see why anyone should trust their word on security if the whole staff feels it is ok to exploit other sites in this way.
    I lost my account at x264, so I don't know what they're saying on the site, but he seems to be one of the few admins anywhere in the torrent world to take a responsible position on this. Bitmetv went out of their way to push the news off their front page after only a day. FTN just locked the thread discussing this. HDBits itself refused to even admit any wrongdoing, let alone apologize and take responsibility.

    To me, the only fair way to interpret this is that it's more important to most site staff to keep HDBits staff from looking bad than to protect users (and ultimately the integrity of their own tracker).

  9. BitTorrent   -   #39
    RedRansom's Avatar Poster BT Rep: +9BT Rep +9
    Join Date
    Apr 2008
    Location
    don't know where
    Posts
    1,160
    wtf?

  10. BitTorrent   -   #40
    becomehokage's Avatar AAARGH! BT Rep: +1
    Join Date
    Feb 2008
    Location
    Little Big Planet
    Posts
    552
    I got an infraction once for bumping an old thread...And you know what? That was absolutely right and fair...You shouldnt bump ancient threads its just...pointless...
    Im kay

Page 4 of 5 FirstFirst 12345 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •