Fraud Bazaar Carders.cc Hacked

VasiliyPupkin

Carder
Messages
40
Reputation
3
Reaction score
3
Points
8
http://krebsonsecurity.com/2010/05/fraud-bazaar-carders-cc-hacked/

Fraud Bazaar Carders.cc Hacked

Carders.cc, a German online forum dedicated to helping criminals trade and sell financial data stolen through hacking, has itself been hacked. The once-guarded contents of its servers are now being traded on public file-sharing networks, leading to the exposure of potentially identifying information on the forum’s users as well as countless passwords and credit card accounts swiped from unsuspecting victims.

The breach involves at least three separate files being traded on Rapidshare.com: The largest is a database file containing what appear to be all of the communications among nearly 5,000 Carders.cc forum members, including the contents of private, one-to-one messages that subscribers to these forums typically use to negotiate the sale of stolen goods. Another file includes the user names, e-mail addresses and in many cases the passwords of Carder.cc forum users.

A third file — which includes what appear to be Internet addresses assigned to the various Carders.cc users when those users first signed up as members — also features a breezy explanation of how the forum was compromised. The top portion of this file — which is accompanied by an ASCII art picture of a cat — includes an oblique reference to the party apparently responsible for the Carders.cc site compromise, noting that the file is the inaugural issue of Owned and Exposed, no doubt the first of many such “e-zines” to come from this group.

Ironically, the anonymous authors of the e-zine said they were able to compromise the criminal forum because its operators had been sloppy with security. Specifically, they claimed, the curators of Carders.cc had set insecure filesystem permissions on the Web server, which essentially turned what might have been a minor site break-in into a total database compromise. From the e-zine’s opening salvo:

Many of you guys may have noticed this breeding German “underground” shit called carders.cc. For those who don’t: Carders is a marketplace full of everything that is illegal and bad. Carding, fraud, drugs, weapons and tons of kiddies. They used to be only a small forum, but after we erased 1337-crew they got more power. The rats left the sinking ship. The voices told us to own them since carders is our fault and we had to fix our flaw. So we did.

During the ownage they also gave us lulz by showing off their ridiculous configuration skills which had a specific impact on their security. They actually managed to chmod and chown nearly everything to 777 and www-user readable. Including their /root directory.

On the surface, it’s tempting to grin at the misfortune of these fraudsters. Still, the leaked database contains no small amount of password and banking information for many innocent victims. In addition, these types of vigilante attacks typically come with hidden costs: For one thing, while it may be true that law enforcement officials could use some of this information to locate people engaged in computer trespass, and buying or selling stolen personal and financial data, the public release of this information could just as easily prompt those individuals to abandon those accounts and Internet addresses, and even potentially jeopardize ongoing investigations.
 

bl4ckmarket

Member
Messages
17
Reputation
0
Reaction score
0
Points
1
They should have ironed out all the bugs and hardened the web server before going live. There are tools available to check all this stuff.
 

paranoiamix

Member
Messages
13
Reputation
-2
Reaction score
0
Points
1
That is true. Obviously there were vulnerabilities.

Remember though, that regardless of the strength of the server, trust is placed on those who are in control. Everything from physical security at their points of access and servers, as well as the site structure itself.

Sabotage from rival hacking/carding communities, security firms, LE or an original founder have all happened in the past. Don't share information, or techniques over PMs - when forum takeovers happen, and they always do (Yes, carder.market, csu will come down one day), LE has a treasure trove of information to sort through. They should be used to establish a point of contact only. Use encrypted ICQ clients, and image/document upload sites to share information. Keep your socks clean. It's as simple as that.
 

al2000

RIPPER
Messages
101
Reputation
2
Reaction score
2
Points
18
Uraaaaaaaaaaa!!!
 

donvoto

Vendor of wu drop
Messages
54
Reputation
5
Reaction score
12
Points
8
as one of our friend says TRUST is something which is a issue..... we never no who is behind this.... at last all information are avilable and best part is i never get any spam to my mail and today alone i got 3 spam mail..... lol ..... people have now hold on all the carders mail ids..... so better change them.............
 
Top