World-wide-web web hosting firm Freedom Web hosting II, which hosts concerning 1500 to 2500 Tor-based web sites, has been hacked. A number of safety gurus have confirmed the hack, and some have estimated that around 20 % of all internet sites on the Dim World-wide-web had long gone offline as a final result of it. Dim World-wide-web and privateness scientists Sarah Jamie Lewis tweeted, “Given former estimates on Dim World-wide-web web sites and OnionScan figures, this is probable about 20 % of energetic ark World-wide-web web sites.” The hacker dependable, has claimed that the firm hosts 1000’s of child pornography images, alongside numerous “scam” web sites, and cited this as the purpose for the hack. The hacker has revealed specifics of internet site directors, and place up a concept on FHII’s internet site which reads, “Hi there, Freedom Web hosting II, you have been hacked”. The hacker said in his statement that “50 % of internet sites hosted by FHII ended up child porn-based and also involve ‘many’ fraud web sites.” The attacker, who instructed news internet site Motherboard that it was their initial at any time hack, claims to have stolen 74GB of information and a two.3GB databases. A list of impacted internet sites has been curated and posted on-line. The databases has also been confirmed and posted to facts sharing internet sites. Troy Hunt, who runs Have I Been Pwned, has been offered the MySQL databases and claims it is made up of 381,000 e-mail addresses. He added that it contains, “a really wide range of knowledge from unique units (PHPBB, WordPress).” Hunt described the breach as a “pretty critical incident”, and “as you can envision, a ton of the knowledge is really express.” Hunt claims that there are numerous .gov addresses saved in the databases, but warned they may well not be true. Lewis (over) warned that in which the Dim World-wide-web is acknowledged for web hosting express supplies and enables for the sale of medicine, it also enables journalists, for illustration, to avoid surveillance from an oppressive regime they may well be dwelling less than. Lewis tweeted, “FHII designed it easy for men and women to get started actively playing with anonymous publishing – and in accomplishing so made a massive vulnerability.” Hunt has also warned that the knowledge from Freedom Web hosting II is probable to have been gathered by law enforcement and intelligence organizations. “Law enforcement will unquestionably have this knowledge, it can be ‘very’ public. It also of course has numerous true e-mail addresses in it.” The news of the FHII hack comes as a Dim World-wide-web market heading by the name of “Hansa” announces a bug bounty, in a bid to secure its business from hacking. The market enables for the trading of stolen credit history playing cards, medicine and other shady dealings. It has invited safety scientists to request out vulnerabilities in its method which can be worthy of up to ten Bitcoins which could lead to buyers, distributors or directors. Less-intrusive bugs and glitches gain just .five BTC. Internet site directors have vowed to retain a terrific bug bounty programme, and alert that any one employing the bug for their have attain before the bug is patched, will have their payment withheld. By comparison, hackers who provide a evidence-of-idea will gain bigger benefits. This article initially appeared at scmagazineuk.com
Source backlink Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on Google+ (Opens in new window)
Related
World-wide-web web hosting firm Freedom Web hosting II, which hosts concerning 1500 to 2500 Tor-based web sites, has been hacked.
A number of safety gurus have confirmed the hack, and some have estimated that around 20 % of all internet sites on the Dim World-wide-web had long gone offline as a final result of it.
Dim World-wide-web and privateness scientists Sarah Jamie Lewis tweeted, “Given former estimates on Dim World-wide-web web sites and OnionScan figures, this is probable about 20 % of energetic ark World-wide-web web sites.”
The hacker dependable, has claimed that the firm hosts 1000’s of child pornography images, alongside numerous “scam” web sites, and cited this as the purpose for the hack.
The hacker has revealed specifics of internet site directors, and place up a concept on FHII’s internet site which reads, “Hi there, Freedom Web hosting II, you have been hacked”.
The hacker said in his statement that “50 % of internet sites hosted by FHII ended up child porn-based and also involve ‘many’ fraud web sites.”
The attacker, who instructed news internet site Motherboard that it was their initial at any time hack, claims to have stolen 74GB of information and a two.3GB databases.
A list of impacted internet sites has been curated and posted on-line. The databases has also been confirmed and posted to facts sharing internet sites.
Troy Hunt, who runs Have I Been Pwned, has been offered the MySQL databases and claims it is made up of 381,000 e-mail addresses. He added that it contains, “a really wide range of knowledge from unique units (PHPBB, WordPress).”
Hunt described the breach as a “pretty critical incident”, and “as you can envision, a ton of the knowledge is really express.”
Hunt claims that there are numerous .gov addresses saved in the databases, but warned they may well not be true.
Lewis (over) warned that in which the Dim World-wide-web is acknowledged for web hosting express supplies and enables for the sale of medicine, it also enables journalists, for illustration, to avoid surveillance from an oppressive regime they may well be dwelling less than.
Lewis tweeted, “FHII designed it easy for men and women to get started actively playing with anonymous publishing – and in accomplishing so made a massive vulnerability.”
Hunt has also warned that the knowledge from Freedom Web hosting II is probable to have been gathered by law enforcement and intelligence organizations. “Law enforcement will unquestionably have this knowledge, it can be ‘very’ public. It also of course has numerous true e-mail addresses in it.”
The news of the FHII hack comes as a Dim World-wide-web market heading by the name of “Hansa” announces a bug bounty, in a bid to secure its business from hacking.
The market enables for the trading of stolen credit history playing cards, medicine and other shady dealings.
It has invited safety scientists to request out vulnerabilities in its method which can be worthy of up to ten Bitcoins which could lead to buyers, distributors or directors. Less-intrusive bugs and glitches gain just .five BTC.
Internet site directors have vowed to retain a terrific bug bounty programme, and alert that any one employing the bug for their have attain before the bug is patched, will have their payment withheld. By comparison, hackers who provide a evidence-of-idea will gain bigger benefits.
This article initially appeared at scmagazineuk.com