Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Hacking News

December 13th, 2012, 14:22 GMT · By

Inj3ct0r Team Hacks ExploitHub, Latter Claims No Exploits Have Been Stolen

SHARE:

Adjust text size:

ExploitHub hacked
Enlarge picture
A couple of days ago, members of Inj3ct0r Team – owners of the famous exploit marketplace – have breached the systems of ExploitHub, a rival website. At the time, they claimed that they had managed to steal $242,333 (189,000 EUR) worth of private exploits.

“We hacked exploithub.com because the people who publish private exploits on exploithub.com need know that the ExploitHub admins are lamers and cannot provide them with adequate security,” Inj3ct0r Team said back then.

On the other hand, while they admit that their systems have been breached, ExploitHub representatives claim that no exploits have been stolen.

“After our initial investigation we have determined that the web application server itself was compromised and access to the database on that server was available to the attacker. The server was compromised through an accessible install script that was left on the system rather than being removed after installation, which was an embarrassing oversight on our part,” they said.

“The database on that server however only contains information used by the web application itself as well as product information such as exploit name, price, and Author, but does not contain any actual product data such as exploit code.”

The investigation is ongoing, but ExploitHub administrators claim that the valuable data is stored in another location and there’s no evidence that Inj3ct0r has managed to compromise it.

Furthermore, they highlight the fact that the information published by Inj3ct0r is actually freely available and it can be accessed by anyone via the web application’s search and browse functions.

“Current assessment of the attack indicates that the impact was limited to compromise of data from only the web application server which does not house exploit code or other product data. Again, there is currently no evidence that the exploits or other products themselves have been compromised or stolen,” they concluded their statement.


1,649 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Site of Indian Telecoms Company BSNL Hacked, Defaced by Anonymous

Muslim Freedom Fighters Deface Website of British MP David Morris

Over 400 Indian Websites Defaced by Sizzling Soul and P@khTuN72

OpIsrael: Tens of Israeli Websites Defaced by Teamr00t and Argentinian Hackers

Saudi Aramco: Insiders Didn’t Help Hackers Breach Our Systems

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM