I come in Peace

Hi Ladies and Gentlemen from Space Ghetto, this is my first post here so I hope you will appreciate it.

Well, first of all I've got to say that I really love your community : I really enjoy to get my eyes and brain fuck each time I spend time on the Ghetto.

I would like the Sg admins not to be butthurted by the following plox : I come in peace

 As I work in Netsec, I've got something that some of you will call bad habits : pressing compulsively Ctrl+U just to see what web fuck or shitz,......I also like to test some urls, you know  admins sometimes forget things.... so shit can  happen... 

And the shit has happenned : not because none  of the SG dirs are  secured, and are accessible, that's not dangerous if the system is kept up to date, as it seems for SG, and because Drupal is a robust system....But a simple nice .htaccess dropped on the site root will avoid flaws and vertigo. That's the first point.

The second point is that there is a directory accessible to all, this directory is not in the Drupal structure and it's called ????? (don't expect me to give you that url).... In that directory there were two files : a php script to upload in the database and another file.

A fucking big .sql file called Spaceghetto_final.sql.... Apparently this file was stored on the server since June 2011. As you all know sql files contains all the site or server life and more than any all the users data, like email and passwords....

I'm a nice guy (think what you want), but I was nice enough to delete that file using the upload script stored on the server and how : just with adding .php?delete=spaceghetto_final.sql at the end of that script.

I'm so nice that I've even deleted it from my computer because owning data that are not mine is like keeping a smelly shit in my house.

But just to prove that I'm not bullshitting you here is a screencap with all the sensible data blurred.:

So, I just strongly encourage all the SG users to change their passwords because even if they are MD5 hashed they are reversible, and just think about the shitload of guys not as nice as I'm who poke your datas since June 2011  i will also encourage the SG admins to put .htaccess to lock their dirs.

Then that's all. No you can go get some oil if you want to burn me.

I came in peace and will let SG in peace.

Have a nice time and keep on being awesome.

Comments

noseriously's picture

work in a nutsac? cool.
koshka's picture

uh, thanks?
bigTrue's picture

So, basically, you walked into somebodies house because the door was open and found some milk that was bad and poured it out and now you are standing on the front porch telling us how we shouldn't let our milk go bad?
me's picture

while i agree with this statement, im also glad he found the directory. now skeez can lock the door and keep the riffraff out ;)
bigTrue's picture

Oh, I'm not saying it's a bad thing....but a simple msg to you mods would have done the same thing.  90% of us don't care about this and don't need to know it.
me's picture

i concur. whats done is done, oh well
Ben Iarwain's picture

Dude, lay off.  I think this is pretty good to know about and he was damn cool about it to boot.

Thanks, OP.

xan's picture

YAY I was in the top 5

TYPES .php?UNDELETE=spaceghetto_final.sql

 

me's picture

there he is
cooter's picture

awww yeah numer 3. also: wtf does this even mean, I dont actually speak computer. I'm just here to delete child porn and beastiality. 
some asshole's picture

At first I was like "oh here we go a long introduction from a noob about nothing" but I was pleasantly surprised. thx bro
skeezoyd's picture

Dick move, bro.
Feckless's picture

Well, it's not actually your first post. I saw that one right before you deleted it. :P
cooter's picture

get bent Roy
heritage's picture

it would only be by him charging into the brick wall that he thinks is conspiring against him.
cooter's picture

I'm pretty sure this is the signup list from the spaceghetto in like 2008 anyway. I remember the last time we had to rebuild I was bummed I was no longer like the second person to register. 
Rapewhistle's picture

so is this bullshit and we really don't have netsec counterhackers examining our code for exploits in their free time

because I can get behind that

me's picture

ikr. i am disappoint :\
Rapewhistle's picture

idk what ikr means

I have a jitterbug so I don't do the texting

vulture capitalist's picture

Can you get space ghetto or the google on that thing?
Rapewhistle's picture

oh heavens no it doesn't sport those confusing bells and whistles just extra big keypad numbers and call waiting so I can keep in touch with the kids in case of an emergency
vulture capitalist's picture

"Ji-Ji-Ji-jitterbug oops I broke my hip"
dw's picture

Thanks,,,,,I guess.
vulture capitalist's picture

The tubes leaked?
TwistedT's picture

i thought the rule was to berate anyone who starts out with 'well, uh.. this is my first post and i think this and that'

letting me down SG
letting me down

Dugan Von Dokolencic's picture

What, there is only 53 people here?
laa laa's picture

most of us are actually tolland man.

i know i am, at least.

Rapewhistle's picture

great, now I have to change my password to P@SsW0rD and that is going to be such a bitch to type out

thanks a big fucking heap, "friend"

Mutatis_Mutandis's picture

So my password was just sitting out there for you to find????!
Spook's picture

IS it safe?
bigTrue's picture

Did you hear that Smith is planning on doing more C:TAS episodes?
Spook's picture

I'd be careful on getting any hopes up if it's one thing about K. Smith I know it's that he tends to be a bit ADD when it comes to his projects. 
anoriginalname's picture

acrackinthemold's picture

Peace? Or is it more passive aggressive? Either way better than most people's first posts.
GregHoush's picture

Glad to see my advices were usefull ^^