Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Pornhub Says Hack Was 'Merely a Hoax'



Over the weekend, a hacker only known as Revolver claimed to have hacked Pornhub. He tweeted alleged screenshots of what looked like a server’s backend and offered to sell access to one of the site’s servers for $1,000.
But as it turns out, the hacker’s story might have been made up.
“He didn't have any server access,” a Pornhub spokesperson told me via Twitter message.
The adult video website said it investigated Revolver’s claims and found that while Revolver’s screenshots to prove his feat “might look realistic to people without knowledge of the underlying infrastructure, the attack as described by the hacker is not technically possible.”
“This incident was merely a hoax and no Pornhub systems were breached during those recent events,” the company said in a statement. (Other than posting the screenshots, Revolver didn’t demonstrate he had access to Pornhub’s server in any other way.)
Pornhub ended with the customary boilerplate corporate statement reassuring viewers that “the safety and security of our users is Pornhub's top priority.” The company also noted that since last week, it has a bug bounty program in place, with which friendly hackers can warn the site of flaws and bugs, and get rewards of up to $25,000.
Revolver could not be reached for comment on Monday morning. But this looks like yet another example of an overblown, or even nonexistent, hack. Earlier this month, a hacker was allegedly selling a stash of 272 millions emails and passwords for $1. Reuters first reported the story, slapping a big “Exclusive” in front of it, which prompted countless blogs to pick it up. But as it turned out, that story was also a hoax, and the database was likely just a collection of credentials leaked as part of older data breaches.
In this case, it looks like Revolver either completely made up the story, or at least oversold it. But breaches like these aren’t uncommon, even on large, well known sites or services such as Uber, the toy company VTech, and countless others.
Correction: a previous version of this story said the hacker was 19 years old. The hacker, however, said he lied when he told Motherboard his age. He now refuses to reveal it.

Hacker Claims to Have Full Control of Pornhub, Offers Access For $1,000



A 19-year-old hacker claims to have hacked into Pornhub’s server and is trying to sell the access for $1,000.
The hacker, who goes by the name Revolver, posted two pictures on his Twitter to prove he had access to Pornhub’s server. The alleged breach comes less than a week after Pornhub launched a bug bounty program to encourage friendly hackers to report flaws and vulnerabilities into the site and help get them fixed.
But Revolver didn’t seem interested in taking that road.
“I don't report vulnerabilities anymore,” Revolver tweeted. “Go underground or go away #FuckBugBounty.”
Revolver told me in an online chat that he hates bug bounty programs because in the past he ”reported a lot of bugs but got no reply from companies,” and he doesn't like to give companies his real name.
The hacker told CSO Online, which first reported the story, that he was able to upload a shell, essentially a control panel he could use to issue any commands on a Pornhub’s server. If true, in other words, Revolver had full control over the server. Revolver said he took advantage of a vulnerability in Pornhub’s “user profile script that handles image uploads.”
Pornhub did not respond to a request for comment, but said on Twitter that it was investigating and that “it doesn't seem like access was gained to a production server.”

“I don't report vulnerabilities anymore. Go underground or go away #FuckBugBounty.”

On Sunday, the hacker told Motherboard that he had already sold the access to three people. He also said Pornhub reached out to him via Twitter but he has still to hear back from them.
”I will tell them they can go fuck off," he said, adding that, however, ”if they gave me a premium account I'm ready to help them fix that.”
Revolver has been quite busy in the last few weeks. In April, he reported a bug in the website to the Freedom of The Press Foundation, which earned him a public thank you from Edward Snowden. He also claimed to have found a bug into the website of the embattled Panamanian law firm Mossack Fonseca, which has been at the center of the Panama Papers scandal. And in a similar incident to this Pornhub one, he also offered access to the LA Times website,
In March, Revolver created a site that displayed screenshots and IP address of random people’s hackable computers, which he called VNC Roulette.