some canadian fucker pwned my website.

99luft

Banned
Oct 12, 2010
101
3
0
so I have a automotive forum and today I came to discover a little message blackmailing me for $2000 or he's going to fuck shit up like encrypt the database, sell user information and everything, aparently he has root access....he's in Canada and I have his email and paypal information.

What to do ? I am an American.
 


Buy a hat and bend over,

i_love_my_canadian_lover_hat-p148359328473933261tdto_210.jpg


Report him, what else can you do?
 
the server, do you still access? who manages your server? has the domains nameservers been changed? who now has control of the domain? do you keep backups?

regarding the selling of data, you cannot win, so pay him nothing. If you pay him an amount he can just ask for more, and even if he gives you what you want, there's nothing stopping him retaining a copy of the data and blackmailing you again.

Step 1: regain control of your domain and/or server
Step 2: sort server security out
Step 3: restore backups
Step 4: mail your userbase telling them what has happened (up to you, I'd probably only let active users know)
Step 5: if your userdb stores plaintext passwords, reset everyones password and get them to choose a new one
Step 6: if your userdb doesnt store plaintext password(more likely), so nothing
Step 7: tell your pal to fuck off
 
Simple, hackforums.net, DDOS the fuck out of his IP range. There's someone on there selling their services who has enough power to take down steampowered.com, as well as others of comparable size.
 
Haha so just how many friends do you have down there in Canada, Rexibit?

:D
 
the server, do you still access? who manages your server? has the domains nameservers been changed? who now has control of the domain? do you keep backups?

regarding the selling of data, you cannot win, so pay him nothing. If you pay him an amount he can just ask for more, and even if he gives you what you want, there's nothing stopping him retaining a copy of the data and blackmailing you again.

Step 1: regain control of your domain and/or server
Step 2: sort server security out
Step 3: restore backups
Step 4: mail your userbase telling them what has happened (up to you, I'd probably only let active users know)
Step 5: if your userdb stores plaintext passwords, reset everyones password and get them to choose a new one
Step 6: if your userdb doesnt store plaintext password(more likely), so nothing
Step 7: tell your pal to fuck off



Who is hosting your server? Inside job? Reliable host?
 
can't he get criminal prosecution for blackmail and breaking into my server? what about selling all the database ?
 
can't he get criminal prosecution for blackmail and breaking into my server? what about selling all the database ?

Sure. Call 911 and tell them what's happening. Whatever advice they give you is what you should follow.

COOL STORY BRO!
 
dewd I feel for you

a month ago some guy from denmark came across my subscription website and found vulnerabilitys in the database and code.

He actually extracted 5 user names/ email address/ and passwords from my database as proof that the DB was not secure. He works for a company called hackavoid(dot)dk

He offered to secure the site for me for $200 and is currently doing it. I told him to send me a report on what the vulnerablilitys were and what he did to fix um.

Like me, unless you know how to do website security on your own you are pretty much at the mercy of the guy that knows more then you (hacker).

I would suggest you...
1. backup your data right now
2. hire a professional to secure your website and lock that mofo out for good.
 
dewd I feel for you

a month ago some guy from denmark came across my subscription website and found vulnerabilitys in the database and code.

He actually extracted 5 user names/ email address/ and passwords from my database as proof that the DB was not secure. He works for a company called hackavoid(dot)dk

He offered to secure the site for me for $200 and is currently doing it. I told him to send me a report on what the vulnerablilitys were and what he did to fix um.

Like me, unless you know how to do website security on your own you are pretty much at the mercy of the guy that knows more then you (hacker).

I would suggest you...
1. backup your data right now
2. hire a professional to secure your website and lock that mofo out for good.

That's a nice business model. Win-Win.
 
dewd I feel for you

a month ago some guy from denmark came across my subscription website and found vulnerabilitys in the database and code.

He actually extracted 5 user names/ email address/ and passwords from my database as proof that the DB was not secure. He works for a company called hackavoid(dot)dk

He offered to secure the site for me for $200 and is currently doing it. I told him to send me a report on what the vulnerablilitys were and what he did to fix um.

Like me, unless you know how to do website security on your own you are pretty much at the mercy of the guy that knows more then you (hacker).

I would suggest you...
1. backup your data right now
2. hire a professional to secure your website and lock that mofo out for good.

i remember an australian news story about a guy who showed a hostel their system could be hacked, and he ended up getting spanked by a court for it