Live data from Hacker News

Anonymous Hacks Epik

4chan.partyvan.epikfail.win

211–220 of 284 posts

Re: Anonymous Hacks Epik

#212

All these recent hacks. Cant any of these companies use proper security experts? I mean they have the funds, why skip this and avoid all the backlash that comes with this. Its expensive but not as much as letting everyone know you messed up hard

Implementing security guidelines is not as easy as paying a security expert. You then have to follow their advice, which means security practice for all employees. It can be costly and cumbersome. Of course, it would have reduced damaged, such as pointing out that unhashed or unsalted MD5 passwords in a database is... what we've stopped doing 20 years ago for good reasons? :) But well, if you're a big hosting provide…

> It can be costly and cumbersome

That's the opportunity cost of defending. It's like walking through treacle at times, but you have to visualize the worst case scenario in your head and act as if you're gonna get breached. You need to essentially enact the situation in your head so that it gives you the momentum you need to keep defending.

Re: Anonymous Hacks Epik

#213
post #211

Are they currently writing up a blogpost about this? Their blog has nothing: https://www.epik.com/blog/ And this is a megadump of a hack. But you can buy a .MONSTER TLD For $1.49: https://www.epik.com/promos/monster

rob.monster is still available apparently

Re: Anonymous Hacks Epik

#214

Anonymous strikes again, this time with a well known web registration company with a decade of data. This is a blatant example how poor security management leads to the hardship of thousands if not millions of regular people. Now their private details have a risk of being public and fully open to scrutiny. And its not just some simple data breach they allegedly stole domain purchases and transfers, account credential…

> Now their private details have a risk of being public

They are public. A simple torrent away.

Re: Anonymous Hacks Epik

#216
post #211

Are they currently writing up a blogpost about this? Their blog has nothing: https://www.epik.com/blog/ And this is a megadump of a hack. But you can buy a .MONSTER TLD For $1.49: https://www.epik.com/promos/monster

rob.monster is still available apparently

Looks registered to me, but seems like it's parked:

https://whois.domaintools.com/rob.monster

    Domain Name: ROB.MONSTER
    Registry Domain ID: D98633729-CNIC
    Registrar WHOIS Server: whois.psi-usa.info
    Registrar URL: https://www.internetx.com/
    Updated Date: 2021-06-05T01:19:43.0Z
    Creation Date: 2019-04-01T14:00:01.0Z
    Registry Expiry Date: 2022-04-01T23:59:59.0Z
    Registrar: InternetX GmbH    
    Registrar IANA ID: 151
    Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
    Registrant Organization:
    Registrant State/Province: nrw
    Registrant Country: DE
    Registrant Email: Please query the RDDS service of the Registrar of Record identified in this 
    output for information on how to contact the Registrant, Admin, or Tech contact of the queried 
    domain name.
    Admin Email: Please query the RDDS service of the Registrar of Record identified in this 
    output for information on how to contact the Registrant, Admin, or Tech contact of the queried 
    domain name.
    Tech Email: Please query the RDDS service of the Registrar of Record identified in this output 
    for information on how to contact the Registrant, Admin, or Tech contact of the queried domain 
    name.
    Name Server: NS1.WESELLTHISDOMAIN.COM
    Name Server: NS2.WESELLTHISDOMAIN.COM
    Name Server: NS3.WESELLTHISDOMAIN.COM
    DNSSEC: unsigned
    Billing Email: Please query the RDDS service of the Registrar of Record identified in this 
    output for information on how to contact the Registrant, Admin, or Tech contact of the queried 
    domain name.
    Registrar Abuse Contact Email: 
    Registrar Abuse Contact Phone:
    URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/

Re: Anonymous Hacks Epik

#217

Anonymous strikes again, this time with a well known web registration company with a decade of data. This is a blatant example how poor security management leads to the hardship of thousands if not millions of regular people. Now their private details have a risk of being public and fully open to scrutiny. And its not just some simple data breach they allegedly stole domain purchases and transfers, account credential…

^ we found a nazi sympathizer here folks and or a guy who had nazi things hosted on epik who is now scared to be doxxed

Re: Anonymous Hacks Epik

#218
post #199

Earlier quoted context omitted.

I agree with you about Epik’s stance, although I believe they’re doing it for the wrong reasons. Rob Monster for instance has expressed support for the KKK and claimed that the Christchurch shooting was a hoax. I’ll defend with my life his right to say abhorrent things. But that also means I get to express myself and call him a bad dude.

Sure, this dude sound like nuts from comments describing him here (I can’t even be bothered to look this shit up myself) and I’m glad I dodged a bullet. However, the private info of all their customers from their inception are allegedly exposed; and lots of people here seem to be cheering the hackers on. Does this mean we need — actually, needed — to do research on the political standings of every founder, CEO, CXO o…

Yes you should be cognizant enough to know not to host your shit in a cesspool of nazi trash

Re: Anonymous Hacks Epik

#219
post #14
post #11

Eventually the cloud is going to burst and everyone’s data will be public. The motive will be similar to this one, where a huge blast radius of collateral damage is accepted in the name of harming bad people. Seeing people eagerly download this data that surely includes countless amounts of personal info of non-Nazis shows this clearly.

How many just regular folks would actually pick Epik? Why?

I registered an account with Epik in 2017 before any notoriety over Gab or whatever (though I did not ultimately end up using their services). Apparently this justifies doxxing and slandering me as a neo-nazi.

Considering that Epik have been in operation for almost a decade before a pivot to extremist hosting, I would assume that the vast majority of this """noble""" hack concerns innocent people.

Re: Anonymous Hacks Epik

#220
post #79

Earlier quoted context omitted.

I had an extremely bad experience with Namecheap with an extremely high value domain (5 letters, dictionary word.) They had a fault on their backend and dropped my domain where it got picked up by a parking service. This happened despite me having paid in advance on time for over a decade. After weeks of going back and forth with Namecheap management I contacted an attorney. Some research hours later we find out Name…

Very few people reading your comment have high-value domains. Also, every registrar sends you scary emails before and after a domain expires and enter the redemption period [1]. That means you failed to: - register for 10 years in advance - pay attention to your email for at least 60 days (including your redemption period) - enable auto-pay If you had done any one of those very normal measures for a high-value domain…

Many domain registries allow you to send domains directly to the pending delete status (or drop them entirely.) It's how domain tasting used to work about 10 years ago before ICANN/Verisign changed up the rules.
Post reply on HN