Page 1 of 1

I hacked Jumba!

Posted: Thu Jul 20, 2006 8:25 am
by radar
[url=\"http://digg.com/security/I_hacked_Jumba!#c2382525\"]http://digg.com/security/I_hacked_Jumba!#c2382525[/url]

I hacked Jumba!

Posted: Thu Jul 20, 2006 9:31 am
by Tibs
I didn\'t understand anything accept for the Hacked part /blum.gif\' class=\'bbc_emoticon\' alt=\':P\' />

I hacked Jumba!

Posted: Thu Jul 20, 2006 12:55 pm
by radar
Ok. I downloaded phpMyAdmin to the server using wget, then extracted it. Then I went to the folder like [url=\"http://site.com/phpMyAdmin\"]http://site.com/phpMyAdmin[/url] and saw that I had root access.

Jumba is a 5000+ client webhosting company.

I hacked Jumba!

Posted: Thu Jul 20, 2006 5:20 pm
by Josh
Honestly, I don\'t get why you would find a security hole, PUT IT ON DIGG before knowing if the hole is fixed or not, and flaunting it around everywhere? That kind of puts a new light on you in my opinion. :\

I hacked Jumba!

Posted: Fri Jul 21, 2006 12:26 am
by radar
I didn't flaunt it around "everywhere" I revealed VERY little information about it before they fixed it. All I said was that it was on Jumba.

After they fixed it I revealed how I did it.

I hacked Jumba!

Posted: Fri Jul 21, 2006 1:02 am
by Josh
Yet people on digg was laughing at the fact of what they were doing after they learned the process from you. >_>

I hacked Jumba!

Posted: Fri Jul 21, 2006 2:36 am
by to@ds
No offence but hacking isnt big or clever in my opinion. Hackers cost business time and money, which are then costs that get passed on to the consumer. Its especialy not clever to go round telling people on forums that you've just hacked a website. What stoping me from notifying the right authorities to your little skirmish? Hacking is a criminal offence and carries jail terms with it, not to mention that you'd never be allowed to work for an IT based company. Hackers are generaly small people who usualy have a beef with the world over something and vent their frustration on people who dont deserve it. I second Dren in saying that youve gone down in my estimations too Radar sorry(and yes I know I have no bearing on your life and you probably dont care but I wanted to say it anyway).

I hacked Jumba!

Posted: Fri Jul 21, 2006 4:02 am
by Endo
Ok people. Radar didnt actually force entry into the site database. He \'stumbled\' across it, it was Jumba\'s fault clearly. He could have done alot worse, yet he didnt. I somehow think the person who commented saying they were deleting the database\'s were not literal, and I highly doubt Jumba would have left a major security flaw unpatched for that long after being notified, they arnt microsoft and take months.

So Radar didnt literally hack Jumba, he gained access out of now flaw other then Jumba....

I hacked Jumba!

Posted: Fri Jul 21, 2006 4:23 am
by radar
As a clarification, I digg'd the story AFTER they fixed it.

What someone said about deleting databases was a JOKE, you know? The "ha ha" kind.

I didn't keep any of the information I saw inside the databases, and I didn't edit, delete or otherwise interfere with the data on Jumba's servers. What I did was legal. Don't hate me because I stumbled across, AND ALERTED THEM, about someone's mistake.

I guess if people can't read plaintext here, then I might as well leave.