LES Members Respond to FlorinMarian Exposing IHostArt Panel Issues

edited January 2024 in Industry News

Hello everyone we informed recently about a data breach of our main website (ihostart.com data base)

we would like to inform you that the data on the VPS was NOT AFFECTED, only the database of the website ihostart.com, the following objects were compromised

Email address
Tickets requests/views

We recomanded for all customers ASAP , to change VPS password (as a precautionary measure) , we leave here coming soon more updates about this , in same time , i'm want inform , no one knew about this security breach, only after a user posted on LET, and we will take all legal measures for this
We leave in next hours more details about this situation

«13

Comments

  • We send coming soon to all emails about this , for now we back to put website online

  • Just tell the truth ...
    The bug was made public by a competing company named hazi.ro managed by @FlorinMarian ...

  • edited January 2024

    Calin borked web server config and for unknown amount of time visitors could download raw .php files. Whmcs config file also was accessed raw.

    @FlorinMarian exposed redacted config file publicaly on LET to defame calin. A scum move.

  • Data breach happened at 8:25 PM - 1/18/2024 (bucharest time)
    We shutdown all our web servers at 8:37 - 1/18/2024 (bucharest time)
    @everyone For now we confirmed just config.file and our data base password start expose , we confirm coming soon if anybody download main data base

  • @Calin said:
    Data breach happened at 8:25 PM - 1/18/2024 (bucharest time)
    We shutdown all our web servers at 8:37 - 1/18/2024 (bucharest time)
    @everyone For now we confirmed just config.file and our data base password start expose , we confirm coming soon if anybody download main data base

    Could database be accessed remotely?

  • @legendary said: Could database be accessed remotely?

    >

    Hello no ,all work at localhost

  • I'm a huge proponent of responsible disclosure, and that thread on LET is not even close to being responsible.

    It's clear that thread was created with the intent to harm @Calin/IHostArt, I would genuinely be surprised if it didn't result in a ban.

    Swiftnode LLC − Baremetal | Colocation | Cloud | DDoS Mitigation
    Established 2014 − 24/7/365 Support − 1000+ Customers Served

  • MannDudeMannDude Provider IncogNET - Speech and Privacy

    Yeah, Florin is a real piece of crap for that. Also, Calin, buy a legitimate WHMCS license and don't use a nulled one...

  • MikeAMikeA ProviderOG

    @MannDude said:
    Yeah, Florin is a real piece of crap for that. Also, Calin, buy a legitimate WHMCS license and don't use a nulled one...

    Lord is this true.

  • @MannDude said:
    Yeah, Florin is a real piece of crap for that. Also, Calin, buy a legitimate WHMCS license and don't use a nulled one...

    Calin: "hi, we fix license next week"
    Florin: "you are an idiot suggesting me to pay $60 per month for some license when my clients pay me peanuts"

    Why?

  • @everyone After we investigate more attented this breach we confirmed emails or phones or tickets not exposed , just our password of config.php from WHMCS

    AGAIN , as a precautionary measure we recommend you to change the VPS password

    At the same time, we plan to migrate from WHMCS to blesta or another billing panel

    We don't have for now a ETA when website back online

    More Answers/Questions (Q&A)

    Question: Data base it's possible accesed outside from VPS network?

    Anwser: NO , we usage all on localhost

    Question: Any customer from ihostart network possible try to login on web panel to accesed data base?

    Answer: NO , we usage separed provider for our main website (ihostart.com / panel.ihostart.com)

  • edited January 2024

    @MikeA said:

    @MannDude said:
    Yeah, Florin is a real piece of crap for that. Also, Calin, buy a legitimate WHMCS license and don't use a nulled one...

    Lord is this true.

    Yes, the screenshot FlorinMarian posted of Calin's config file showed the first part of a shared license key,

  • Maybe you two should take a month off les and focus on drama at ogf.

  • teamaccteamacc OG teamacc

    @MannDude said:
    Yeah, Florin is a real piece of crap for that. Also, Calin, buy a legitimate WHMCS license and don't use a nulled one...

    ihostart.com shows legit on whmcs license checker though

    Hey teamacc. You're a dick. (c) Jon Biloh, 2020.

  • MannDudeMannDude Provider IncogNET - Speech and Privacy
    edited January 2024

    @teamacc said:

    @MannDude said:
    Yeah, Florin is a real piece of crap for that. Also, Calin, buy a legitimate WHMCS license and don't use a nulled one...

    ihostart.com shows legit on whmcs license checker though

    From: https://lowendtalk.com/discussion/comment/3892511/#Comment_3892511

    gblic is nulled

    What I have seen before now is people will pay the lowest licence to verify a domain but need a much higher package, so they replaces the licence file with the cracked one and have a little bash script that will run every day to put the original back, run the force update licence and then put the nulled back to continue the higher package

    I am not saying that is what is going on here but just what I have observed with others in the past.

    Maybe not nulled. Maybe nulled.

  • @teamacc said:

    @MannDude said:
    Yeah, Florin is a real piece of crap for that. Also, Calin, buy a legitimate WHMCS license and don't use a nulled one...

    ihostart.com shows legit on whmcs license checker though

    It didn't on the first checks after it was revealed on LET that it was a shared license.

  • I would hope that publicly exposing an exploit that could potentially leak customer data is bannable on LES as well.. it would be different if the issue was raised to Calin first and no measures were taken but the issue was never raised privately.

  • FrankZFrankZ ModeratorOG
    edited January 2024

    @BruhGamer12 said:
    I would hope that publicly exposing an exploit that could potentially leak customer data is bannable on LES as well.. it would be different if the issue was raised to Calin first and no measures were taken but the issue was never raised privately.

    The provider tag was suspended pending review when this came to my attention. A final decision will be made regarding this after the rest of the LES staff has weighed in.

    As long as they do not break the rules here at LES, I can't see how it would be justifiable to ban a member for things that they do elsewhere. As an example some members that are upstanding citizens here have been banned for actions taken at the OGF.

  • @FrankZ said:

    @BruhGamer12 said:
    I would hope that publicly exposing an exploit that could potentially leak customer data is bannable on LES as well.. it would be different if the issue was raised to Calin first and no measures were taken but the issue was never raised privately.

    The provider tag was suspended pending review when this came to my attention. A final decision will be made regarding this after the rest of the LES staff has weighed in.

    I don't see how we can ban a member here if the issue does not happen here. As an example some members that are upstanding citizens here have been banned for actions taken at the OGF. As long as they do not break the rules here at LES, I can't see how it would be justifiable to ban a member.

    Devil's advocate, if a vendor deadpooled on OGF and a bunch of people lost money but he never advertised here would you let them keep their provider tag? But it only happened over on OGF ....

  • It doesn't matter if hazi broke specific rules at OGF. It was an illegal olympic-sized dick move against a competitor, for petty and stupid reasons.

    This is kill -9, this person is a potential threat to any community due to a combination of low intelligence and malevolence.

    Ban won't make any sense, as no one forbits him to create a new account. But IMHO he shouldn't sell anything again anywhere.

  • FrankZFrankZ ModeratorOG
    edited January 2024

    @skorous said: Devil's advocate, if a vendor deadpooled on OGF and a bunch of people lost money but he never advertised here would you let them keep their provider tag? But it only happened over on OGF ....

    Not the same thing. As I said in the first part of my statement above, I suspended the provider tag when this came to my attention. Provider tags are removed, or never issued, to providers that the staff feels have a reasonable potential to be a danger to the community. Permanent removals or denials are generally decided by a majority vote of the staff, not just by any one person.

    EDIT: It should be noted that there are other reasons, in addition to what I stated above, that a provider tag would not be issued or would be revoked but they don't apply to this situation.

  • @FrankZ said:

    @skorous said: Devil's advocate, if a vendor deadpooled on OGF and a bunch of people lost money but he never advertised here would you let them keep their provider tag? But it only happened over on OGF ....

    Not the same thing. As I said in the first part of my statement above, I suspended the provider tag when this came to my attention. Provider tags are removed, or never issued, to providers that the staff feels have a reasonable potential to be a danger to the community. Permanent removals or denials are generally decided by a majority vote of the staff, not just by any one person.

    EDIT: It should be noted that there are other reasons, in addition to what I stated above, that a provider tag would not be issued or would be revoked but they don't apply to this situation.

    So the provider tag portion wasn't as important as the fact that they never did anything wrong here. It was an attempt to show that some mistakes are big enough that they follow you. I don't really have an opinion so last I'll say on it.

  • edited January 2024

    So the provider tag portion wasn't as important as the fact that they never did anything wrong here. It was an attempt to show that some mistakes are big enough that they follow you. I don't really have an opinion so last I'll say on it.

    @skorous I'm confused by this comment, FrankZ has just explained above that the provider tag was suspended so he can no longer sell anything in this board, so what did I missed?

  • edited January 2024

    Kudos for extremely fast disclosure, Romanian king is only one.

    @FlorinMarian If you are confident in your new 20Gbps "Arbor" protection, think again, you made yourself many new enemies. I liked to laugh at your incompetence, but such retarded malicious move is a no go.
    (this is not a threat, i'm just sure someone will do it)

  • cybertechcybertech OGBenchmark King YABS 24/7/365

    @FlorinMarian care to clarify

    I bench YABS 24/7/365 unless it's a leap year.

  • cybertechcybertech OGBenchmark King YABS 24/7/365

    I think it's unfair to ban this boy based on what he does/did on OGF, but yes there should be certain requirements to being a provider here and anywhere else.

    I bench YABS 24/7/365 unless it's a leap year.

  • edited January 2024

    @treesmokah @cybertech
    This is what I can say about this situation:

    Maybe I'm writing this message a bit early and the situation is still hot, I hope you will try to put some effort to understand the whole situation with Calin and from my perspective.
    As I mentioned in the thread, I randomly went to his whmcs and saw the horror related to there being no php interpreter. At that moment I was shocked and glad at the same time that karma had done its job and without further checking if the error existed and after creating the thread, I posted it.
    Yes, it can be considered a pretty major error but let's keep in mind that Calin created a thread in which he announced about this incident and marked the time of the beginning of the incident exactly when at minute 25 when I created the thread and the time of the end of the incident at minute 37, after at minute 32 I had given him DM to announce that the error still persists.
    Please note that I did not catch a fraction of a second when this error existed but consider that he had no idea of this issue at least in the 12 minutes of the thread and who knows how long before since he was not actively working on his page to realize that his changes were disastrous.
    After the blurred screenshot and the fact that I made sure there was no external connection for DB try please understand that I was trying to get back at Calin but to a limited extent (after all there is no leak other than some useless credentials that can be changed) and I was trying to open the eyes of the community to the fact that they judge too much for my shortcomings and are blind to the shortcomings of others like me.
    Then, also out of fairness, I think you should also note that Calin is in turn breaking the 'don't be a dick' rule by hardening those who are already against me with my threads and that old 'Hazi.ro offers for refugees' post for which he may have deserved the ban but was in turn forgiven.

  • Otus9051Otus9051 The Original Freeloader

    @FlorinMarian said:
    @treesmokah @cybertech
    This is what I can say about this situation:

    Maybe I'm writing this message a bit early and the situation is still hot, I hope you will try to put some effort to understand the whole situation with Calin and from my perspective.
    As I mentioned in the thread, I randomly went to his whmcs and saw the horror related to there being no php interpreter. At that moment I was shocked and glad at the same time that karma had done its job and without further checking if the error existed and after creating the thread, I posted it.
    Yes, it can be considered a pretty major error but let's keep in mind that Calin created a thread in which he announced about this incident and marked the time of the beginning of the incident exactly when at minute 25 when I created the thread and the time of the end of the incident at minute 37, after at minute 32 I had given him DM to announce that the error still persists.
    Please note that I did not catch a fraction of a second when this error existed but consider that he had no idea of this issue at least in the 12 minutes of the thread and who knows how long before since he was not actively working on his page to realize that his changes were disastrous.
    After the blurred screenshot and the fact that I made sure there was no external connection for DB try please understand that I was trying to get back at Calin but to a limited extent (after all there is no leak other than some useless credentials that can be changed) and I was trying to open the eyes of the community to the fact that they judge too much for my shortcomings and are blind to the shortcomings of others like me.
    Then, also out of fairness, I think you should also note that Calin is in turn breaking the 'don't be a dick' rule by hardening those who are already against me with my threads and that old 'Hazi.ro offers for refugees' post for which he may have deserved the ban but was in turn forgiven.

    if bad, why do?
    and, if do, why public?

    youtube.com/watch?v=k1BneeJTDcU

  • MannDudeMannDude Provider IncogNET - Speech and Privacy

    @FlorinMarian said:
    @treesmokah @cybertech
    This is what I can say about this situation:

    Maybe I'm writing this message a bit early and the situation is still hot, I hope you will try to put some effort to understand the whole situation with Calin and from my perspective.
    As I mentioned in the thread, I randomly went to his whmcs and saw the horror related to there being no php interpreter. At that moment I was shocked and glad at the same time that karma had done its job and without further checking if the error existed and after creating the thread, I posted it.
    Yes, it can be considered a pretty major error but let's keep in mind that Calin created a thread in which he announced about this incident and marked the time of the beginning of the incident exactly when at minute 25 when I created the thread and the time of the end of the incident at minute 37, after at minute 32 I had given him DM to announce that the error still persists.
    Please note that I did not catch a fraction of a second when this error existed but consider that he had no idea of this issue at least in the 12 minutes of the thread and who knows how long before since he was not actively working on his page to realize that his changes were disastrous.
    After the blurred screenshot and the fact that I made sure there was no external connection for DB try please understand that I was trying to get back at Calin but to a limited extent (after all there is no leak other than some useless credentials that can be changed) and I was trying to open the eyes of the community to the fact that they judge too much for my shortcomings and are blind to the shortcomings of others like me.
    Then, also out of fairness, I think you should also note that Calin is in turn breaking the 'don't be a dick' rule by hardening those who are already against me with my threads and that old 'Hazi.ro offers for refugees' post for which he may have deserved the ban but was in turn forgiven.

    You "randomly" went to a competitors WHMCS. You "randomly" checked to see if files were available through non-standard methods. Then instead of informing Calin directly, like a reasonable person, you submitted your findings to LET with a snarky message and thread title that made it clear your actions were malicious. As I'm sure you expected, and to no surprise of anyone, the information and method YOU posted was used maliciously. Only after did you share your findings publicly did you then decide to inform him.

    I'm not going to defend Calin, to be quite frank I think the two of your are cut from the same cloth and greatly lack business ethics. We'll all judge him in our own ways for his poor security practice that lead up to this event, but you really shot yourself in the foot. What did you expect to happen when you posted that thread? Everyone would clap for you, carry you on their shoulders and shower you with praise?

  • edited January 2024

    @MannDude said:

    @FlorinMarian said:
    @treesmokah @cybertech
    This is what I can say about this situation:

    Maybe I'm writing this message a bit early and the situation is still hot, I hope you will try to put some effort to understand the whole situation with Calin and from my perspective.
    As I mentioned in the thread, I randomly went to his whmcs and saw the horror related to there being no php interpreter. At that moment I was shocked and glad at the same time that karma had done its job and without further checking if the error existed and after creating the thread, I posted it.
    Yes, it can be considered a pretty major error but let's keep in mind that Calin created a thread in which he announced about this incident and marked the time of the beginning of the incident exactly when at minute 25 when I created the thread and the time of the end of the incident at minute 37, after at minute 32 I had given him DM to announce that the error still persists.
    Please note that I did not catch a fraction of a second when this error existed but consider that he had no idea of this issue at least in the 12 minutes of the thread and who knows how long before since he was not actively working on his page to realize that his changes were disastrous.
    After the blurred screenshot and the fact that I made sure there was no external connection for DB try please understand that I was trying to get back at Calin but to a limited extent (after all there is no leak other than some useless credentials that can be changed) and I was trying to open the eyes of the community to the fact that they judge too much for my shortcomings and are blind to the shortcomings of others like me.
    Then, also out of fairness, I think you should also note that Calin is in turn breaking the 'don't be a dick' rule by hardening those who are already against me with my threads and that old 'Hazi.ro offers for refugees' post for which he may have deserved the ban but was in turn forgiven.

    You "randomly" went to a competitors WHMCS. You "randomly" checked to see if files were available through non-standard methods. Then instead of informing Calin directly, like a reasonable person, you submitted your findings to LET with a snarky message and thread title that made it clear your actions were malicious. As I'm sure you expected, and to no surprise of anyone, the information and method YOU posted was used maliciously. Only after did you share your findings publicly did you then decide to inform him.

    I'm not going to defend Calin, to be quite frank I think the two of your are cut from the same cloth and greatly lack business ethics. We'll all judge him in our own ways for his poor security practice that lead up to this event, but you really shot yourself in the foot. What did you expect to happen when you posted that thread? Everyone would clap for you, carry you on their shoulders and shower you with praise?

    Why do you look at the situation in one way?
    Calin, a provider in his turn, affects the image of the provider FlorinMarian in FlorinMarian's threads.
    Why do you expect FlorinMarian to show true fraternity towards the one who tries to bury his image?

    EDIT:

    You "randomly" checked to see if files were available through non-standard methods.

    What was non-standard? I've used my browser to access his homepage and index.php was downloaded instead of interpreted and then did the same with configuration file to see if still works with that.

  • MannDudeMannDude Provider IncogNET - Speech and Privacy

    @FlorinMarian said:

    @MannDude said:

    @FlorinMarian said:
    @treesmokah @cybertech
    This is what I can say about this situation:

    Maybe I'm writing this message a bit early and the situation is still hot, I hope you will try to put some effort to understand the whole situation with Calin and from my perspective.
    As I mentioned in the thread, I randomly went to his whmcs and saw the horror related to there being no php interpreter. At that moment I was shocked and glad at the same time that karma had done its job and without further checking if the error existed and after creating the thread, I posted it.
    Yes, it can be considered a pretty major error but let's keep in mind that Calin created a thread in which he announced about this incident and marked the time of the beginning of the incident exactly when at minute 25 when I created the thread and the time of the end of the incident at minute 37, after at minute 32 I had given him DM to announce that the error still persists.
    Please note that I did not catch a fraction of a second when this error existed but consider that he had no idea of this issue at least in the 12 minutes of the thread and who knows how long before since he was not actively working on his page to realize that his changes were disastrous.
    After the blurred screenshot and the fact that I made sure there was no external connection for DB try please understand that I was trying to get back at Calin but to a limited extent (after all there is no leak other than some useless credentials that can be changed) and I was trying to open the eyes of the community to the fact that they judge too much for my shortcomings and are blind to the shortcomings of others like me.
    Then, also out of fairness, I think you should also note that Calin is in turn breaking the 'don't be a dick' rule by hardening those who are already against me with my threads and that old 'Hazi.ro offers for refugees' post for which he may have deserved the ban but was in turn forgiven.

    You "randomly" went to a competitors WHMCS. You "randomly" checked to see if files were available through non-standard methods. Then instead of informing Calin directly, like a reasonable person, you submitted your findings to LET with a snarky message and thread title that made it clear your actions were malicious. As I'm sure you expected, and to no surprise of anyone, the information and method YOU posted was used maliciously. Only after did you share your findings publicly did you then decide to inform him.

    I'm not going to defend Calin, to be quite frank I think the two of your are cut from the same cloth and greatly lack business ethics. We'll all judge him in our own ways for his poor security practice that lead up to this event, but you really shot yourself in the foot. What did you expect to happen when you posted that thread? Everyone would clap for you, carry you on their shoulders and shower you with praise?

    Why do you look at the situation in one way?
    Calin, a provider in his turn, affects the image of the provider FlorinMarian in FlorinMarian's threads.
    Why do you expect FlorinMarian to show true fraternity towards the one who tries to bury his image?

    I'm not defending Calin. I think you two are more similar than unalike. I just think you took things too far, is all.

  • edited January 2024

    @MannDude said:

    @FlorinMarian said:

    @MannDude said:

    @FlorinMarian said:
    @treesmokah @cybertech
    This is what I can say about this situation:

    Maybe I'm writing this message a bit early and the situation is still hot, I hope you will try to put some effort to understand the whole situation with Calin and from my perspective.
    As I mentioned in the thread, I randomly went to his whmcs and saw the horror related to there being no php interpreter. At that moment I was shocked and glad at the same time that karma had done its job and without further checking if the error existed and after creating the thread, I posted it.
    Yes, it can be considered a pretty major error but let's keep in mind that Calin created a thread in which he announced about this incident and marked the time of the beginning of the incident exactly when at minute 25 when I created the thread and the time of the end of the incident at minute 37, after at minute 32 I had given him DM to announce that the error still persists.
    Please note that I did not catch a fraction of a second when this error existed but consider that he had no idea of this issue at least in the 12 minutes of the thread and who knows how long before since he was not actively working on his page to realize that his changes were disastrous.
    After the blurred screenshot and the fact that I made sure there was no external connection for DB try please understand that I was trying to get back at Calin but to a limited extent (after all there is no leak other than some useless credentials that can be changed) and I was trying to open the eyes of the community to the fact that they judge too much for my shortcomings and are blind to the shortcomings of others like me.
    Then, also out of fairness, I think you should also note that Calin is in turn breaking the 'don't be a dick' rule by hardening those who are already against me with my threads and that old 'Hazi.ro offers for refugees' post for which he may have deserved the ban but was in turn forgiven.

    You "randomly" went to a competitors WHMCS. You "randomly" checked to see if files were available through non-standard methods. Then instead of informing Calin directly, like a reasonable person, you submitted your findings to LET with a snarky message and thread title that made it clear your actions were malicious. As I'm sure you expected, and to no surprise of anyone, the information and method YOU posted was used maliciously. Only after did you share your findings publicly did you then decide to inform him.

    I'm not going to defend Calin, to be quite frank I think the two of your are cut from the same cloth and greatly lack business ethics. We'll all judge him in our own ways for his poor security practice that lead up to this event, but you really shot yourself in the foot. What did you expect to happen when you posted that thread? Everyone would clap for you, carry you on their shoulders and shower you with praise?

    Why do you look at the situation in one way?
    Calin, a provider in his turn, affects the image of the provider FlorinMarian in FlorinMarian's threads.
    Why do you expect FlorinMarian to show true fraternity towards the one who tries to bury his image?

    I'm not defending Calin. I think you two are more similar than unalike. I just think you took things too far, is all.

    It is true that this action (posting) was based on hatred.
    I had a pact with him to ignore each other after we had some tougher discussions in private, but after a while Calin returned to the old habit but loved by the community.
    Being less popular than him, I couldn't post when I could see that he was lying about something, and that's how the hatred that raged yesterday accumulated.
    What did Calin lie about?

    • that it has over 3000 IPs (3x/24 in reality)
    • that he has 10Gbps at home, not 1Gbps like me (at any time of the day, if you add the sum of his servers on the uptime, you don't have more than 1Gbps up/down)
    • that I have no chance to keep my servers at home, that he also tried until he rented a hall, blah blah that for Christmas we will see the picture with the green walls from the grandparents' house.

    Considering that I kept all these reasons in mind, it is clear that it affected me emotionally that my truths were ruining my image while his lies raised him far above me.

  • Otus9051Otus9051 The Original Freeloader

    @FlorinMarian said: What was non-standard? I've used my browser to access his homepage and index.php was downloaded instead of interpreted and then did the same with configuration file to see if still works with that.

    1. is your browser cURL or wget?
    2. curiosity kills the cat

    youtube.com/watch?v=k1BneeJTDcU

  • @Otus9051 said:

    @FlorinMarian said: What was non-standard? I've used my browser to access his homepage and index.php was downloaded instead of interpreted and then did the same with configuration file to see if still works with that.

    1. is your browser cURL or wget?
    2. curiosity kills the cat

    In the screenshots deleted from the LET, it was clear that Google Chrome had been used, just so that in my mind that vulnerability only existed for a fraction of a minute and not to be accused of who knows what hacking engineering.

  • Otus9051Otus9051 The Original Freeloader

    @FlorinMarian said:

    @Otus9051 said:

    @FlorinMarian said: What was non-standard? I've used my browser to access his homepage and index.php was downloaded instead of interpreted and then did the same with configuration file to see if still works with that.

    1. is your browser cURL or wget?
    2. curiosity kills the cat

    In the screenshots deleted from the LET, it was clear that Google Chrome had been used, just so that in my mind that vulnerability only existed for a fraction of a minute and not to be accused of who knows what hacking engineering.

    understandable

    youtube.com/watch?v=k1BneeJTDcU

  • edited January 2024

    @FlorinMarian said: that I have no chance to keep my servers at home, that he also tried until he rented a hall, blah blah that for Christmas we will see the picture with the green walls from the grandparents' house.

    LOL

    @FlorinMarian said: In the screenshots deleted from the LET, it was clear that Google Chrome had been used, just so that in my mind that vulnerability only existed for a fraction of a minute and not to be accused of who knows what hacking engineering.

    Bro, you wrote bachelor thesis on DDoS attacks and hacking, you obviously know how to be a haxor.

    Regarding whether you did it maliciously or not, I think its the first option. You whined about Calin in other threads already, you spotted opportunity to pick at him and you did.
    I was judged for pettier things than this, it was 100% expected your tactic will backfire, I have no idea what were you thinking posting it. If any other member posted it, it could be justified for other reasons, but you are his direct competitor. It was clearly a dirty attack against your competitor. You could've stayed quiet, and wait for someone else to notice and then pick at him, instead you disclosed it yourself in the shittiest way possible.
    If you given a fuck about ethics or his customers, you wouldn't disclose it like that.
    I'm also aware you called certain people in the past to try and get Calin kicked out from Orange Romania(or try and ruin his business), knowing that, there is no doubt in my mind it was a malicious attack.

    I rooted for you from your very beginnings with your "datacenter", It was extremely cool to me and I also wished I could have such setup for my homelab some day. But you fucked everything up, I'm just disappointed.

  • FalzoFalzo Senpai
    edited January 2024

    @FlorinMarian said: I had a pact with him to ignore each other after we had some tougher discussions in private, but after a while Calin returned to the old habit but loved by the community.
    Being less popular than him, I couldn't post when I could see that he was lying about something, and that's how the hatred that raged yesterday accumulated.
    What did Calin lie about?

    you are going on about what HE did as if this is some kind of justification for your action.

    it simply is not.

    if you find a vulnerability like that by accident simply act like a grown up and inform him. I probably could even understand if you'd just look the other way and ignore what you found.

    however posting about it publicly like you did is a nogo , no matter what. the screenshot doesn't play a role at all.
    what you posted is a direct prompt to go and look after it for anyone with possible malicious intent. you knowingly instigated people to harm your competitor.

    like @MannDude said you have no business ethics at all and in the end this is the reason why you are failing.
    it will always come back around to you one way or another. you build your bad reputation all by yourself with this kind of actions, so rather stop talking about all the bad things your competitors did to you.
    it won't help and is no justification for your own behaviour anyway.

  • @Falzo said:

    @FlorinMarian said: I had a pact with him to ignore each other after we had some tougher discussions in private, but after a while Calin returned to the old habit but loved by the community.
    Being less popular than him, I couldn't post when I could see that he was lying about something, and that's how the hatred that raged yesterday accumulated.
    What did Calin lie about?

    you are going on about what HE did as if this is some kind of justification for your action.

    it simply is not.

    if you find a vulnerability like that by accident simply act like a grown up and inform him. I probably could even understand if you'd just look the other way and ignore what you found.

    however posting about it publicly like you did is a nogo , no matter what. the screenshot doesn't play a role at all.
    what you posted is a direct prompt to go and look after it for anyone with possible malicious intent. you knowingly instigated people to harm your competitor.

    like @MannDude said you have no business ethics at all and in the end this is the reason why you are failing.
    it will always come back around to you one way or another. you build your bad reputation all by yourself with this kind of actions, so rather stop talking about all the bad things your competitors did to you.
    it won't help and is no justification for your own behaviour anyway.

    Yes, I am his direct competitor, as he is in my threads in which he drags the reputation I'm trying to build into the mud.
    I would totally agree with you if there wasn't the essential element of the story: I went to the site and that shit was there, on the main page. Calin has no idea when that vulnerability was there, marking the time when I made the post the time when the cure appeared, which is not true. Between with/without my post the big difference is that more people saw that that vulnerability exists, nothing more.
    There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.

  • Otus9051Otus9051 The Original Freeloader
    edited January 2024

    @treesmokah said: you obviously know how to be a haxor

    i js thought bro curl'ed the homepage

    @FlorinMarian said: Between with/without my post the big difference is that more people saw that that vulnerability exists, nothing more.

    There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.

    People access backdoors all of the time, do see them posting it publicly?
    The difference between revealing a vulnerability to the public, while it is not fixed, and letting the public find out the vulnerability, is that revealing will have a larger impact than the public finding it itself. Considering me, a person who has been into the interwebs for quite some time now, its almost always that some vulnerability that isnt disclosed is abused way less than the one which has been.

    youtube.com/watch?v=k1BneeJTDcU

  • @Otus9051 said:

    @treesmokah said: you obviously know how to be a haxor

    i js thought bro curl'ed the homepage

    @FlorinMarian said: Between with/without my post the big difference is that more people saw that that vulnerability exists, nothing more.

    There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.

    People access backdoors all of the time, do see them posting it publicly?
    The difference between revealing a vulnerability to the public, while it is not fixed, and letting the public find out the vulnerability, is that revealing will have a larger impact than the public finding it itself. Considering me, a person who has been into the interwebs for quite some time now, its almost always that some vulnerability that isnt disclosed is abused way less than the one which has been.

    The database does not accept external connections and those credentials are useless without SSH access to the VM hosting the site.

  • @FlorinMarian said:

    @Otus9051 said:

    @treesmokah said: you obviously know how to be a haxor

    i js thought bro curl'ed the homepage

    @FlorinMarian said: Between with/without my post the big difference is that more people saw that that vulnerability exists, nothing more.

    There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.

    People access backdoors all of the time, do see them posting it publicly?
    The difference between revealing a vulnerability to the public, while it is not fixed, and letting the public find out the vulnerability, is that revealing will have a larger impact than the public finding it itself. Considering me, a person who has been into the interwebs for quite some time now, its almost always that some vulnerability that isnt disclosed is abused way less than the one which has been.

    The database does not accept external connections and those credentials are useless without SSH access to the VM hosting the site.

    Have you checked if that's the case before posting it?

  • @treesmokah said:

    @FlorinMarian said:

    @Otus9051 said:

    @treesmokah said: you obviously know how to be a haxor

    i js thought bro curl'ed the homepage

    @FlorinMarian said: Between with/without my post the big difference is that more people saw that that vulnerability exists, nothing more.

    There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.

    People access backdoors all of the time, do see them posting it publicly?
    The difference between revealing a vulnerability to the public, while it is not fixed, and letting the public find out the vulnerability, is that revealing will have a larger impact than the public finding it itself. Considering me, a person who has been into the interwebs for quite some time now, its almost always that some vulnerability that isnt disclosed is abused way less than the one which has been.

    The database does not accept external connections and those credentials are useless without SSH access to the VM hosting the site.

    Have you checked if that's the case before posting it?

    Yes, no matter how retarded you think I am, I would not have publicly shown something like that for both ethical and legal reasons.

  • @FlorinMarian said:

    @treesmokah said:

    @FlorinMarian said:

    @Otus9051 said:

    @treesmokah said: you obviously know how to be a haxor

    i js thought bro curl'ed the homepage

    @FlorinMarian said: Between with/without my post the big difference is that more people saw that that vulnerability exists, nothing more.

    There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.

    People access backdoors all of the time, do see them posting it publicly?
    The difference between revealing a vulnerability to the public, while it is not fixed, and letting the public find out the vulnerability, is that revealing will have a larger impact than the public finding it itself. Considering me, a person who has been into the interwebs for quite some time now, its almost always that some vulnerability that isnt disclosed is abused way less than the one which has been.

    The database does not accept external connections and those credentials are useless without SSH access to the VM hosting the site.

    Have you checked if that's the case before posting it?

    Yes, no matter how retarded you think I am, I would not have publicly shown something like that for both ethical and legal reasons.

    Well, you are retarded. You just admitted to trying to illegally access database of your competitor.

  • @treesmokah said:

    @FlorinMarian said:

    @treesmokah said:

    @FlorinMarian said:

    @Otus9051 said:

    @treesmokah said: you obviously know how to be a haxor

    i js thought bro curl'ed the homepage

    @FlorinMarian said: Between with/without my post the big difference is that more people saw that that vulnerability exists, nothing more.

    There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.

    People access backdoors all of the time, do see them posting it publicly?
    The difference between revealing a vulnerability to the public, while it is not fixed, and letting the public find out the vulnerability, is that revealing will have a larger impact than the public finding it itself. Considering me, a person who has been into the interwebs for quite some time now, its almost always that some vulnerability that isnt disclosed is abused way less than the one which has been.

    The database does not accept external connections and those credentials are useless without SSH access to the VM hosting the site.

    Have you checked if that's the case before posting it?

    Yes, no matter how retarded you think I am, I would not have publicly shown something like that for both ethical and legal reasons.

    Well, you are retarded. You just admitted to trying to illegally access database of your competitor.

    You talk nonsense and you know it, but I leave you, you have no reason to be on my side anyway.

  • @FlorinMarian said: you have no reason to be on my side anyway

    Not anymore.

  • dosaidosai OG தோசை

    Why isn't @FlorinMarian banned here?

  • edited January 2024

    Why not admit it?

    You were driven by revenge because of all the harassment from Calin and didn't think it through, and your move potential could harm all his customers.

    Or did you check if the database port was open, so you were sure customers wouldn't be harmed? If so, I can't see you have done worse than Calin.

  • RapToNRapToN ProviderOG
    edited January 2024

    @FlorinMarian

    What you did was absolutely not okay and it doesn't matter who it was or what you had against him. You don't publish something like that without giving the person concerned the chance to fix it and admit that there was a weakness.
    If it hadn't been published by Calin, you could have published it, but not like this.

    I'm really shocked that a hoster would do something like this, even though he should be aware that he himself could be in a similar situation at any time.

  • Otus9051Otus9051 The Original Freeloader

    @FlorinMarian said:

    @Otus9051 said:

    @treesmokah said: you obviously know how to be a haxor

    i js thought bro curl'ed the homepage

    @FlorinMarian said: Between with/without my post the big difference is that more people saw that that vulnerability exists, nothing more.

    There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.

    People access backdoors all of the time, do see them posting it publicly?
    The difference between revealing a vulnerability to the public, while it is not fixed, and letting the public find out the vulnerability, is that revealing will have a larger impact than the public finding it itself. Considering me, a person who has been into the interwebs for quite some time now, its almost always that some vulnerability that isnt disclosed is abused way less than the one which has been.

    The database does not accept external connections and those credentials are useless without SSH access to the VM hosting the site.

    yk its actually pretty easy to spoof local connections, wont say how, and you probably know that.

    youtube.com/watch?v=k1BneeJTDcU

  • edited January 2024

    @dosai said:
    Why isn't @FlorinMarian banned here?

    He doesn't deserve to be banned here, he didn't do anything wrong here.
    I'm also banned on LET but free to talk here as long as I play by local rules.

    @xvps said: because of all the harassment from Calin

    There was no harassment that I was aware of, shitting at someone on a public forum and in public threads in not harassment in any shape or form.
    If he got intimidated by a kid with broken english and his caveman operation, I don't know what to tell you, Florin shouldn't have access to the internet.

Sign In or Register to comment.