Skip to content

Comment on Another Security Blunder Takes Down Another Dark Web Drug Emporium

Comments

What happened, according to the leaker, was he/she went to the site, and index.php started downloading... So it would have to be a web-server (Apache, Nginx) mis-configuration that removed the php-handler from the file-type.

http://iobm.net/forum/dos/index.php/topic,17.0.html

It was not our aim to bring BMR down, we just published the leak because if we had it, enforcement and private hackers could have it as well, trouble could arise if the leakage would have been exploited without people to know.
Besides, we want to make clear that we have no contact to anyone of the involved parties, neither backopy nor VPS admin.
When we tried to access the site, it offered us the index.php for DOWNLOAD. So we downloaded it as we assumed we were not the only one to be able to download it.
For any reason the file was not executable anymore by the VPS and thus offered for download! Whether ot not this happened intentionally or was a simple but severe mistake, is outside our knowledge.
We just think that such mistakes must not happen as they can endanger the users and we think they must be published and not exploited.

yeah, sounds more likely, otherwise someone needs to name names of the VPS provider. i'm very skeptical that a VPS provider actually started snooping.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.