PDA

View Full Version : HDBits Bitmetv exploit



Sentient
02-23-2007, 09:33 PM
This appeared on the bitmetv front page today:

SECURITY RISK:
Another torrent site - HDBITS - has been using their own members accounts (WITHOUT THEIR PERMISSION) whom are also members here and running an exploit through those members accounts. If you have accounts on both sites (especially where your password may be the same as here) then we advise that you change your PASSWORD and PASSKEY to avoid you account ending up possibly disabled. We apologise for this but this message is in our own members best security intrests.

Regards,
//BitMeTV.org Staff http://picz.bitmetv.org/smilies/smile1.gif

Anyone know anything more about it?

EDIT:

a bitmetv admin presented the following two lines of what is presumably an IRC log as "proof."

10.10.29 [user] THEN WHY THE F**K WAS MY PASSKEY BEING USED ON UR F**KING RSS FEED
10.10.29 » (Valerio) why do you care? it would've been unnoticible if i had moved the thing before i changed it :S

RainRoofer
02-23-2007, 09:44 PM
wtf ? Is this true ?

Sentient
02-23-2007, 09:50 PM
Beats me. We all know how paranoid bitmetv is. But either it's true or not, it'd be hard to just imagine it.

Sucks, Firon is an admin at HDBits. He's already had plenty of aspersions cast over him over utorrent; this won't help.

Ne'tu
02-23-2007, 09:59 PM
They banned one of the HDBits admins. He got mad at them... :D :lol:

Sentient
02-23-2007, 10:11 PM
They banned one of the HDBits admins. He got mad at them... :D :lol:

What was the exploit?

Jaits
02-23-2007, 10:31 PM
i m sure it is true...

when i hacked them a while back, i read their staff forums, and they were fighting against that other hd tracker (bit-hdtv)... and they were downloading movies from there to post them on their own tracker and also planning on how to take them out... back then bit-hdtv had security vunreabilities so they didnt have to use their users passwords (and i dont recall seeing any table that logged them in clear text).. they just hacked them and logged in as them... its not hard though to modify the login script to store the plaintext password as well...

EFS
02-23-2007, 11:17 PM
They banned one of the HDBits admins. He got mad at them... :D :lol:
Maybe THey will kill Him soon :D

marksman
02-23-2007, 11:21 PM
i m sure it is true...

when i hacked them a while back, i read their staff forums, and they were fighting against that other hd tracker (bit-hdtv)... and they were downloading movies from there to post them on their own tracker and also planning on how to take them out... back then bit-hdtv had security vunreabilities so they didnt have to use their users passwords (and i dont recall seeing any table that logged them in clear text).. they just hacked them and logged in as them... its not hard though to modify the login script to store the plaintext password as well...

uhh!!..hacked them?

gbilly72
02-23-2007, 11:43 PM
How very professional of HDBits, supposedly the largest HD tracker.

(if it's true, of course)

andrzejek1999
02-23-2007, 11:54 PM
all u need is to now a little of PHP...

crossfade
02-24-2007, 01:10 AM
i m sure it is true...

when i hacked them a while back, i read their staff forums, and they were fighting against that other hd tracker (bit-hdtv)... and they were downloading movies from there to post them on their own tracker and also planning on how to take them out... back then bit-hdtv had security vunreabilities so they didnt have to use their users passwords (and i dont recall seeing any table that logged them in clear text).. they just hacked them and logged in as them... its not hard though to modify the login script to store the plaintext password as well...

omg are they that easy to hack or what? you'd think private BT sites care about security...

seppypom
02-24-2007, 01:13 AM
Who said it was easy

crossfade
02-24-2007, 01:17 AM
Who said it was easy

well the way the said it made it look fairly easy, for someone who has some experience in that area of course

iNSOMNiA
02-24-2007, 01:33 AM
They banned one of the HDBits admins. He got mad at them... :D :lol:

They banned xREVx the HDbits @dmin right? :huh:

andrzejek1999
02-24-2007, 01:37 AM
dudes, everything is easy when u know how to do and what to do otherwise it's damn hard.

seppypom
02-24-2007, 01:37 AM
How very professional of HDBits, supposedly the largest HD tracker.

(if it's true, of course)

it is true, that HDbits did post a exploit of Bitmetv.org.

crossfade
02-24-2007, 01:40 AM
They banned one of the HDBits admins. He got mad at them... :D :lol:

They banned xREVx the HDbits @dmin right? :huh:

no they ip-banned valerio (xrevx is no admin, he's not even staff)

evening_star
02-24-2007, 01:46 AM
Right now HDbits isn't saying much about it, other then to deny the accusation in their forums.

BitMeTV gave the notice, but otherwise haven't given any more info on the subject.

Hopefully some explanation will come to light soon. I'm fond of both trackers.

iNSOMNiA
02-24-2007, 01:49 AM
I dunno why I thought he was staff or something
anyway he have been banned too :dabs:

seppypom
02-24-2007, 02:29 AM
he may have been banned, but two days ago he was an admin

iNSOMNiA
02-24-2007, 02:44 AM
no they ip-banned valerio (xrevx is no admin, he's not even staff)


he may have been banned, but two days ago he was an admin
Ah thanks seppy, i knew i was right...as always :P
next time double check your "infos" crossfade

bytetorrent
02-24-2007, 04:23 AM
i m sure it is true...

when i hacked them a while back, i read their staff forums, and they were fighting against that other hd tracker (bit-hdtv)... and they were downloading movies from there to post them on their own tracker and also planning on how to take them out... back then bit-hdtv had security vunreabilities so they didnt have to use their users passwords (and i dont recall seeing any table that logged them in clear text).. they just hacked them and logged in as them... its not hard though to modify the login script to store the plaintext password as well...

omg are they that easy to hack or what? you'd think private BT sites care about security...


how ?? RFI/LFI ,SQL INJECTION or XSS?? :naughty:

Sentient
02-24-2007, 05:55 AM
a bitmetv admin presented the following two lines of what is presumably an IRC log as "proof."

10.10.29 [user] THEN WHY THE F**K WAS MY PASSKEY BEING USED ON UR F**KING RSS FEED
10.10.29 » (Valerio) why do you care? it would've been unnoticible if i had moved the thing before i changed it :S

crossfade
02-24-2007, 09:02 AM
he may have been banned, but two days ago he was an admin
Ah thanks seppy, i knew i was right...as always :P
next time double check your "infos" crossfade

where am i wrong?
valerio, who always was hdbits admin, was banned at bmtv
xrevx is just a hdbits vip

bananaca
02-24-2007, 09:03 AM
I was a member of that site but my account is probably already disabled due to inactivity. :P

Texan
02-28-2007, 01:31 PM
So what happened finally ?

Ne'tu
02-28-2007, 01:45 PM
Really nothing interesting.

fit4trading
02-28-2007, 03:45 PM
Ahh the pathetic mods... Running here and there all day trying to be a little more elite than others and all they end up with is getting disabled (or fighting bitterly)... What a pathetic life... Its sad to see that the private tracker community has such bitter feelings towards each other. The average user still enjoys... :D

kalpesh
02-28-2007, 04:04 PM
By Hdbits
In response to the random claim that we know all your passwords and can/will use them on bitmetv if you have the same password there, I would like to point out that the only trace of your password stored in the database is your passhash.
This is a 128bit md5 hash of your password and a 20 character long random string.
For those of you who that makes no sense to, it means all that is stored is something like 1055d3e698d289f2af8663725127bd4b....which cannot be reversed back into your password.

shalako
02-28-2007, 05:10 PM
By Hdbits
For those of you who that makes no sense to, it means all that is stored is something like 1055d3e698d289f2af8663725127bd4b....which cannot be reversed back into your password.

That's not exactly true. they can be reversed.

Sentient
02-28-2007, 05:18 PM
By Hdbits
In response to the random claim that we know all your passwords and can/will use them on bitmetv if you have the same password there, I would like to point out that the only trace of your password stored in the database is your passhash.
This is a 128bit md5 hash of your password and a 20 character long random string.
For those of you who that makes no sense to, it means all that is stored is something like 1055d3e698d289f2af8663725127bd4b....which cannot be reversed back into your password.

Yes, I already did it for one doubter here: http://filesharingtalk.com/vb3/p-pledge-more-hd-content-trackers-post1780639/postcount22


Quote:
Originally Posted by zaguar http://filesharingtalk.com/vb3/synapse_kt8c/buttons/viewpost.gif (http://filesharingtalk.com/vb3/bittorrent/t-pledge-more-hd-content-trackers-159598-post1780359)
Really? So you've magically found a way to reverse the MD5 hashing process? If so, tell me what this string is: 1cbd3b9800b88f9cb98755e40a15c813 . Thanks.

It reverses to Liar. Found with the help of the first google hit on the search "reverse md5 hash": http://md5.benramsey.com/

On topic: I think a lot less of HDBits that they didn't come clean about what Valerio was doing.

kayvanblue
02-28-2007, 05:29 PM
i hope it s not true

maxpower76
03-01-2007, 12:09 AM
how do i found out about my hash password

Melvinmeow
03-01-2007, 03:38 PM
how do i found out about my hash password

You cant get what it is. Its only stored on the sites database itself it isnt shown to anyone for the most part unless they have db access.
Or if they find a exploit on the site like someone else who posted in this thread does to other sites.

BTW They were hacked by the clown in refrence. There was about 4 pages of logs to confirm what was said. I however will not repost anything said.
And in responce to the passhash comment I made a similiar statement in another thread about how easy that was about 2 days ago.

Jaits
03-01-2007, 04:32 PM
how do i found out about my hash password


if they dont use salting, from ur cookies... if they do its impossible to get the passhash from the cookie...

tintin123
03-01-2007, 08:10 PM
why they do this? sounds daft

i have never had an account with them but do have lots of sites with same username

maseunit
03-01-2007, 10:34 PM
Yeah sketchy

Sentient
03-04-2007, 09:33 PM
New info I just happened upon on this. Matt865, an admin at x264 posted the following about the situation:


They may or may not store your passwords insecurely and use them, but what is true is that their admin Valerio (quoting him), "Made a rss feed for bitmetv so you can download stuff from there without an account." This caused a few members to loose their accounts there. https://f******.net/pic/smilies/no.gif
I don't see why anyone should trust their word on security if the whole staff feels it is ok to exploit other sites in this way.

I lost my account at x264, so I don't know what they're saying on the site, but he seems to be one of the few admins anywhere in the torrent world to take a responsible position on this. Bitmetv went out of their way to push the news off their front page after only a day. FTN just locked the thread discussing this. HDBits itself refused to even admit any wrongdoing, let alone apologize and take responsibility.

To me, the only fair way to interpret this is that it's more important to most site staff to keep HDBits staff from looking bad than to protect users (and ultimately the integrity of their own tracker).

RedRansom
09-17-2008, 05:08 PM
wtf?

becomehokage
09-17-2008, 05:17 PM
I got an infraction once for bumping an old thread...And you know what? That was absolutely right and fair...You shouldnt bump ancient threads its just...pointless...

bugs.bunny
09-17-2008, 05:19 PM
wtf?you should do like your sig