Live data from Hacker News

Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

thenextweb.com

11–20 of 33 posts

Re: Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

#11
post #8

> The company's developers accidentally uploaded the entire database to Github Wait, from what I've heard, the programmer just uploaded a configuration file that contains the password of the database? And oh boy, he's not the only one, Maybe GitHub can do something about it. To the topic: This is the exact reason why I don't support any sort of system that log users personal information without user's control. Becaus…

please don't over estimate their skills and qualification. the leaked database username is root and the password is 123456.

the screenshot of the github file can be access here: https://www.secrss.com/articles/4851

and yes, that "programmer" pushed such highly sensitive company information to his personal github repo.

Re: Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

#12
Ignoring the moral/ethics concerns, how would a potential buyer know that the data is legit (if it even exists at all?).

Give me a couple of days and I'll create a fake -but real looking- set of records with millions of false customers (it would be made real enough by using public information)...

If you tell me that they'll provide an extract as "proof", I'll answer: it's easy to cook-up a realistic small sample, just using and remixing former leaks/hacks for instance...

In summary: the money aspect makes the data MUCH more suspicious than a "bragging/4tehLULz" hack.

Re: Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

#13
post #11
post #8

> The company's developers accidentally uploaded the entire database to Github Wait, from what I've heard, the programmer just uploaded a configuration file that contains the password of the database? And oh boy, he's not the only one, Maybe GitHub can do something about it. To the topic: This is the exact reason why I don't support any sort of system that log users personal information without user's control. Becaus…

please don't over estimate their skills and qualification. the leaked database username is root and the password is 123456. the screenshot of the github file can be access here: https://www.secrss.com/articles/4851 and yes, that "programmer" pushed such highly sensitive company information to his personal github repo.

This happens so frequently, and is easy to scan for, sadly.

What is missing is a way to programmatically, and secretly, inform people of their mistakes. I've personally found literally hundreds of examples of this and lack the manpower to file that many tickets....

Re: Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

#14
post #11
post #8

> The company's developers accidentally uploaded the entire database to Github Wait, from what I've heard, the programmer just uploaded a configuration file that contains the password of the database? And oh boy, he's not the only one, Maybe GitHub can do something about it. To the topic: This is the exact reason why I don't support any sort of system that log users personal information without user's control. Becaus…

please don't over estimate their skills and qualification. the leaked database username is root and the password is 123456. the screenshot of the github file can be access here: https://www.secrss.com/articles/4851 and yes, that "programmer" pushed such highly sensitive company information to his personal github repo.

> please don't over estimate their skills and qualification

No, I said "careless" rather than "incompetent".

Lot's of things could go wrong and cause that, I don't comment on the detail until the reason of why the password end up been pushed to GitHub is explained.

Also, I suggest Please REMOVE anything that MAY help to locate the stolen information, including content of the advertising post (Can be keyword searched).

Re: Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

#15
post #12

Ignoring the moral/ethics concerns, how would a potential buyer know that the data is legit (if it even exists at all?). Give me a couple of days and I'll create a fake -but real looking- set of records with millions of false customers (it would be made real enough by using public information)... If you tell me that they'll provide an extract as "proof", I'll answer: it's easy to cook-up a realistic small sample, jus…

mapping of 居民身份证 to real names..

Re: Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

#16
post #12

Ignoring the moral/ethics concerns, how would a potential buyer know that the data is legit (if it even exists at all?). Give me a couple of days and I'll create a fake -but real looking- set of records with millions of false customers (it would be made real enough by using public information)... If you tell me that they'll provide an extract as "proof", I'll answer: it's easy to cook-up a realistic small sample, jus…

Reputation and repeat business. You might get away with selling fake information once, i highly doubt you would get away with it twice.

I imagine its a similar scenario to how other dodgy markets work such as drugs or cryptolocker decryption keys, reputation and customer service mean a lot.

Re: Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

#17
post #11

Earlier quoted context omitted.

please don't over estimate their skills and qualification. the leaked database username is root and the password is 123456. the screenshot of the github file can be access here: https://www.secrss.com/articles/4851 and yes, that "programmer" pushed such highly sensitive company information to his personal github repo.

This happens so frequently, and is easy to scan for, sadly. What is missing is a way to programmatically, and secretly, inform people of their mistakes. I've personally found literally hundreds of examples of this and lack the manpower to file that many tickets....

Missing? I thought they already did that. IIRC a couple of my teammates reported getting emails from github about accidentally uploading AWS credentials and the like.

Re: Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

#18
post #12

Ignoring the moral/ethics concerns, how would a potential buyer know that the data is legit (if it even exists at all?). Give me a couple of days and I'll create a fake -but real looking- set of records with millions of false customers (it would be made real enough by using public information)... If you tell me that they'll provide an extract as "proof", I'll answer: it's easy to cook-up a realistic small sample, jus…

Reputation and repeat business. You might get away with selling fake information once, i highly doubt you would get away with it twice. I imagine its a similar scenario to how other dodgy markets work such as drugs or cryptolocker decryption keys, reputation and customer service mean a lot.

For hackers good opsec would require them to use a new persona for each separate hack. Compartimentalization. Linking separate hacks together is a really bad idea.

Re: Hackers sell data of 130M Chinese hotel guests on dark web for 8 Bitcoin

#19
post #11
post #8

> The company's developers accidentally uploaded the entire database to Github Wait, from what I've heard, the programmer just uploaded a configuration file that contains the password of the database? And oh boy, he's not the only one, Maybe GitHub can do something about it. To the topic: This is the exact reason why I don't support any sort of system that log users personal information without user's control. Becaus…

please don't over estimate their skills and qualification. the leaked database username is root and the password is 123456. the screenshot of the github file can be access here: https://www.secrss.com/articles/4851 and yes, that "programmer" pushed such highly sensitive company information to his personal github repo.

[deleted]
Post reply on HN