Hackers Expose 26,000 Sex Website Passwords
An anonymous reader writes "Passwords and email addresses of almost 26,000 members of adult website Pron.com have been released on the internet by the notorious hacking group LulzSec. To add to the victims' humiliation, LulzSec called on its followers to try the email/password combinations against Facebook, and tell friends and family of the users that they were subscribers to a pornographic website. In addition LulzSec released passwords belonging to the administrators of dozens of other adult websites, and highlighted military and government email addresses that had signed up for the xxx-rated services."
i only read it for the articles.
Where can I find the passwords?
Dropbox drops it like it's hot.
Who signs up with a government issued email or even real info to a sex site? Who even pays for that? Amazing. So much free stuff to watch who would bother?
To be honest. This does not help anyone and certainly will create a strong wrong perception of hackers.
Is this hacker group christian or something like that? Seriously folks...
http://lulzsecurity.com/releases/
so we can see some pron for free...
You're new to this whole 'internet' thing aren't you?
Who the fuck still pays for porn?
People watch porn... so what?
Do we live in the Dark Ages and masturbation is a sin?
On one hand, I couldn't agree more with one of the posters who said something along the lines the how people make a bog deal out of sex between consenting adults, including the watching of it. The Victorian-esque morality that most aspects of sex are something that people should be ashamed of, including porn, is not something I can relate to.
That said, I have to wonder about the kind of people who would be paying for porn. Even if you are particularly desperate, there's so much free porn on the Internet that it's almost pointless to pay for porn. Plus, if you're that desperate, just how hard is it to pick girls up at a bar (or if you're a geek Don Juan, Craigslist)? Paying for sex in any shape or form has to be one of the silliest things, given how easy it is to find women who are more than willing if you just looked around.
The reason why you never hear about porn sites getting cracked is because it is fucking easy. Most porn sites are vulnerable as hell and almost anyone with some technical proficiency can exploit them. They are run by low budget companies who often just cant afford to secure their sites. Cracking porn sites are for pathetic script kiddies with little to no skill what so ever. Also what's up with trying to shame owners of porn site memberships? Fucking puritans.
Football Odds
Seems like people are entirely unaware of how there have for over 10 years now been f.e. IRC channels available (in the dozens) with people just spending time cracking and mining passwords for sex websites - for fun, and on request. But I guess the lulzsec guys deserve some more attention and praise.
I think it'd be nice to relate this to the latest "scandal" in the US:
azmeal@cmc.gov.my | ilovedyna
flag@whitehouse.gov | karlmarx
kamarudinalias@mmea.gov.my | 814550
james.ben.hopkins@us.army.mil | j347576
wade.quigley@ang.af.mil | mywife01
aaron.c.sewell@us.army.mil | 3689817
Upward mobility is a slippery slope - the higher you climb the more you show your ass.
Or did we just get hacked?
"LulzSec called on its followers to try the email/password combinations against Facebook, and tell friends and family of the users that they were subscribers to a pornographic website"
I cant believe those hackers are so influenced by american puritanism...
We all like sex. Its the way nature designed us to be able to spread.
My friends dont care if i'm subscribed to a porn site... well i guess bc im not in the US.
After they exposed loads of username/password combinations off some Sony service, I thought to myself; who are they actually hurting? It seemed to me they just made it loads easier for criminals without the skills to do this sort of thing themselves.
Yes, it is possible that some more sinister hackers already had this data without telling anyone, just secretly exploiting them, but actually publishing the combinations makes it many times more likely that someone will exploit your personal data.
I consider this hacking group no more than simple vandals and criminals at this stage. There is no "honour" in it, and exposing porn clients are extremely likely to be hypocritical. I don't believe for a second that all members of this hacker group has a "clean conscience" about porn.
Surprise surprise:
123456
123456789
12345
1234
12345678
1234567
password
1234567890
123
123123
Now they've gone too far.
Help! I'm a slashdot refugee.
They must have a phemonenal amount of personal info on people based on web search alone, never mind everything else they do.
Some Google engineers must have the ability (if not necessarily permission) to track the porn surfing habits of the vast majority of the world's internet surfers. Think how many powerful people that they could blackmail with this information.
Don't fuck with Google ...
Why are they going after everything and anything?
Maybe they should blow up some unmarked yellow vans to further obscure whatever their "message" is.
anybody going to that site will get a mandatory free "upgrade" for his system, offered by LulzSec.
Privacy is terrorism.
Looks like a lot of those people use their phone number as their password.
http://michaelsmith.id.au
Who else would be that stupid and give them the attention they want?
Only completely stupid retards with an IQ of 63 or members of the hacker group...
I lulzed and I've almost been that dumb myself once.
Sure I jerk off, but I don't pay for it, and I don't do it in the White House or in the Pentagon using their mail servers etc. (or interns).
Anyways don't the boobs on the list know that everything they do is being seen by their technical staff and network administrators? XD It's not like my ISP doesn't know my exact sexual preferences, they might even think they're boringly ordinary verging on stereotypical.
The truth shall set us free :) Bring these humans back down to the ground here with the rest of us and maybe things will work out better.
Wow! Humans like porn? Damn, I never saw that one coming...
I didn't know these hacking groups were so fascio-christian.
marvelcash@gmail.com | Slashdot69
Anybody owning up to this one?
http://michaelsmith.id.au
What is the purpose of the threat to tell peoples families about the porn they look at?
This is looking like a blackmail mechanism. Similar to "we got ur noods, don't worry we won't show mom and dad"
Not sure I'd really care if people found out I was subscribing to a porn site....it's not as if my Wife doesn't go there too :-)
As a result, I feel sorry for those who apparently think it's something to be shocked at.
In fact, I'd be more embarrassed at people knowing I *paid* for it when there's so much free stuff about.
Since none of us know just how many porn passwords they have cracked, along with Facebook accounts. We do not know whether or not for example some Anon somewhere cracked our most sick perverted teen porn password, and also has our Facebook to tell our family.
Seriously, this sort of stuff can cause suicides. Remember that gay kid who committed suicide over something similar?
They are telling people to go and destroy peoples lives.
Telling them to log into their Facebook accounts and tell their families about their porn habit?
So if a guy or girl is secretly going to gay porn sites, and his or her parents are religious, what kind of damage could that do?
Really is it that hard to build some basic security into one's site? I mean like storing the passwords as hash, instead of plaintext? It is just a few bits of code... so simple... but yet again a web site failing on such a basic matter. No wonder they got hacked to boot, and now have all their member's e-mails and passwords out on the street.
I would expect a porn site to care a bit more about their user's privacy, considering the business they're in. Though considering how much some of their users care (using a .mil or .gov address to sign up) maybe indeed it's just as well that they didn't care too much. Oh well, let's hope it's a lesson learnt for porn site subscribers, even though considering they are paying for on-line porn they're not the smartest cookies of the pack.
How many signups were done by someone else "ordering a pizza" for a little revenge.
Passionately Indifferent
Are we talking about George Michael?
Confucius say, "Find worm in apple - bad. Find half a worm - worse."
root@host:~# strings pronz.txt |grep -o "[^ ]*$" | sort | uniq -c | sort -nr | head
671 123456
212 123456789
111 12345
75 1234
72 12345678
65 1234567
62 password
52 1234567890
49 123
41 123123
Someone is registered with the email "microsoft@microsoft.com". Can that be accurate?
Now that is just mean!
people like porn, everyone needs to stop pretending they don't and get on with life
None of the logins work now unless i'm missing something :(
I just posted to my own facebook wall that I watch porn! Beat em to it!
"why don't you just slip into something more comfortable...like a coma!"
If it weren't for the stigma surrounding porn this would just be another hacked website. I still don't understand societies taboos about sexually related things. Especially when we are so accepting of of violence and death. The number of crime scene centric shows on public TV is staggering. The number of sex centric shows? Almost non-existent. People are perfectly fine looking a images of death and dismemberment, but put naked people on TV and it's a travesty. Personally I think the world would better off if people spent more time watching pornography than watching people get killed. Remember, you can have safe sex, you cannot have safe war!
Sounds like lulzsec is a bunch of religious moral crusaders with this act.
We already have the "don't re-use passwords" security best practices, but it seems e-mail addresses themselves are just as dangerous, as they can be linked to identities, which could have social implications way beyond simple security compromise.
Always register accounts on porn sites (or other embarrasing websites) using a different e-mail address, an e-mail address not known to friends, employers, coworkers, churchgoers, neighborhood busybodies, etc; one that cannot easily be linked to your identity, social network accounts.
Security will also be improved, if you use separate e-mail accounts for private business. For example: use one e-mail address for Facebook, use a separate e-mail address for your bank account.
The hacker may attempt to login with the same e-mail address and password at many sites; but if the e-mail address is different, they won't even have an account ID to attempt to attack (even if the password did happen to be similar)
This wouldn't be such an issue if every website didn't demand to know your e-mail address and store it in their database; but the reality, is your e-mail address has become kind of like your internet driver's license or SSN, that every website demands before they can establish an account for you.
Thankfully, unlike a driver's license or SSN, you can have as many of them as you want, due to the event of..... free webmail-based email services such as Gmail, Hotmail, Yahoo Mail :)
others use the internets.
They only took this half-way to completion! If they would have only pulled the sites IP log to see who was looking at what particular video's then I'm sure we would have had a much more interesting reaction...
... that porn sites everywhere get Slashdotted?
You don't get it, do you? Nobody takes you seriously drinkypoo.
I took a peek at your post history.
There, it's shown that You ran away from simple questions asked of you here that show you're also nothing but a troll http://tech.slashdot.org/comments.pl?sid=2225174&cid=36390518 which your evasion and running away from that simple question makes you out as a logically invalid off topic troll (because that's a fairly simple question asked of you that you ran from which shows you are nothing but an online trash troll).
Porn (as mentioned in other posts) is sex between consenting adults (generally speaking).
For those less "vanilla," and you know who you are, even depicted rape in porn is consenting.
Lets take the extreme route of one of these government addresses being registered on one of these rape oriented sites...
Just because you like all the SAW movies, doesn't mean you're going to go all Jigsaw on us...
Something witty.
SO glad there wasn't any coffee in my mouth as I read this. Hardest I've laughed in a week. Golf clap.
Some combo name+family name seem rare enough on the net. No I won't give an example, after all I have nothing against porn myself.
Free sex is often the most expensive kind of sex.
This reminds me of the "Linux is only free if your time is worth nothing" assertion that is often thrown about. Lets fix the rest of your post:
"Paying for software in any shape or form has to be one of the silliest things, given how easy it is to find programmers who are more than willing if you just looked around."
90% of companies are incapable of getting software for free. At a minimum, they have to pay at least for a few consultant or support contract. Usually multiple times, and with no guarantee of their effort and expenditure resulting in working software. Not to mention the costs of code mergers and forks.
"Plus, if you're that desperate, just how hard is it to hire a programmer in India (or if you're a geek Don Juan, Spain)?"
How hard? This is the Unwashed Masses, where picking up women at a bar is easier than comprehending the average three letter acronym. Random programmers on Linkedin or software-only online download sites? ... can you say viruses?
Free software is often the most expensive kind of software.
Hmm, maybe I should send this to Microsoft's PR department.
...But seriously...
:-(
Could you possibly rewrite that in a copy/pasteable SQL Injection format? My ISP blocks port 25 outbound
Boot Windows, Linux, and ESX over the network for free.
If the password is a four to six digit number that is not 1234 then it's probably an ATM card number as well. Actually if it's 1234 then it's still probably an ATM card.
Top ten passwords:
password 123123 , count 41.0
password 123 , count 49.0
password 1234567890 , count 52.0
password password , count 62.0
password 1234567 , count 65.0
password 12345678 , count 72.0
password 1234 , count 75.0
password 12345 , count 111.0
password 123456789 , count 212.0
password 123456 , count 669.0
total: 25887.0
Top ten emails:
domain yahoo.co.id , count 248.0
domain yahoo.in , count 284.0
domain live.com , count 400.0
domain yahoo.co.in , count 437.0
domain rediffmail.com , count 463.0
domain ymail.com , count 509.0
domain aol.com , count 593.0
domain hotmail.com , count 3572.0
domain gmail.com , count 4044.0
domain yahoo.com , count 9325.0
total: 25884.0
That said, I have to wonder about the kind of people who would be paying for porn.
Perhaps they pay to support the actresses?
Kinda like the same way people donate to Wikipedia or the Mozilla Foundation, or buy Red Hat?
You can criticize the Sony PSN hack and this one and a lot of other on any moral, ethical and whatnot grounds. But what if all these hacks actually served a real purpose?
To open some managers' eyes on the poor state of security? After all not all the companies got hacked because most don't want to be hacked: it's not like all the world SMEs and big corp. where running unpatched Windows ME boxen behind no firewall.
Maybe that the more public exploits, the more managers will realize that they're potentially the next victim and the more they can convince upper management to take security more seriously?
For example, shall the PSN come back online and be as vulnerable as it was? What if after the HBGary hack sysadmins realized they really shouldn't give root passwords by email etc.?
Maybe that, say, in twenty years or so, networks will eventually become a little bit more secure?
If that's the case, then I'm in for as many RSA hacks, HBGary, Sony PSN, lulzec whatever etc. exploits.
I thought that it was wrong to assert morality. Now we have hackers coaching people to disclose personal habits? Of course it is wrong for politicians to do it but I guess hackers can under the guise of technology.
Any sys admin creating a system that stores passwords should be held liable for damages.
I think its safe to say that a good deal of this community should have already known about this 3 days ago.
Disposable email
Let's see. The site I use:
- Does not come with spyware and stuff
- Has all the stuff sorted and searchable
- Uses pay per view, so I pay only for the time I watch
Of course there is no chance in hell I would use my businessaddress or the same password I use on other sites. But why should I bother using crappy sites that try everything to rip my money and my personal information, when I could use a normal business service that has an interest in me coming back and is until now proven to be secure?
Why should I care about free stuff when paying gives me better service?
I am single - again :) - and I am allowed to use pr0n. There is nothing bad about that. I don't use the site TFA mentions, but to me it is perfectly reasonable to pay for pr0n. I don't waste time with the free stuff to find the pr0n I like. I don't need to think about security. I don't need to think if the file is what it says it were.
Wait, wait, what? You need passwords to view porn on the internet now?
Oh great, again something important changed and no story on /.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
From the list:
test@test.com | test
So it seems like they dumped a list of registered, but not necessarily activated, accounts. Not that I want to defend the .gov/.mil people in there, but it seems like anyone could have created an account named president@whitehouse.gov and get some "lulz" out of it, but it does not mean that the POTUS is actively using that account.
So these hackers want to "embarrass" people for doing something that is not illegal by publishing personal information. However, they, who are engaged in illegal activity, carefully hide their own private information.
Sorry, the LulzSec people are in the wrong and until they are willing to publish their own private information they are just a bunch of internet thugs breaking laws for their own benefit.
Lemme see now; I pay good tax money for the benefit of militarists and government 9 to fivers. I have a share in being their employer. If it were me I'd fire the lot of their sorry asses. Not 'cos they're on Pron sites but because their against my company's IT policy. Oh, wait. I'm Canadian and only get to pay taxes without a vote. Here's Pron: Let me pull my pants down a little lower! Darn! will one of you Americans please fire them for me. Thanks.
May the lies we live by make us strong, healthy, happy and wise - Kurt Vonnegut.
Really. Just use Google Video search, with SafeSearch turned off. Porn has gone ad-supported, like all other forms of content.
(If only the music industry would figure that out.)
Pretty ironic that one of the addresses mentioned above belongs to a Malaysian government official given their stance on porn.
These people would never dare to subscribe to a porn-site themselves. Obviously conservatives with messed up morals and small brains. Despicable. Nothing is even the slightest bit funny about this blatant fundamentalist propaganda.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
The tendency for people with a religious reference in the email to use a religious based password is interesting. Hopefully I'm not adding to the damage, as this list is very public now.
youthpastor49@hotmail.com | balls11a
alligatorchurch@gmail.com | broadstairs
lasterbarbara@yahoo.com | Iovejesusforlife
Danielbenjamin4jesus@yahoo.com | 111222
ambersmith4jesus@yahoo.com | splash9
emennamdi4christ@yahoo.co.uk | holyman
ecw_champion_christan@yahoo.com | christan
"and tell friends and family of the users that they were subscribers to a pornographic website."
that usually isn't a shocker for most...it would be weird if your family members name ISN'T on that list
http://newschoolsecurity.com/2011/06/are-lulz-our-best-practice/
This is a good article worth reading. Yes i also agree, security sucks in many places and it takes groups like Lulz to show it, because management can't be bothered to... and everything else is covered.
Which makes me wonder, isn't lulz a group with the task of pointing out security weakness? True attackers would obtain the same info, without divulging, so they can exploit it for years... And i believe they are doing a service of elevating security conscience.
It is a shame it has to be this way, but reality shows this is the only method for some to get it...
Yep, just because some hacktivist group posts a list of emails and passwords, supposedly taken from a pron website, all the text in it *must* be 100% true.
;)
Because nobody would ever put in a fake email address when subscribing to a porn site, even if we give lulzsecurity the benefit of the doubt and the list is 100% authentic.
I'd personally be more concerned that actually going to lulzsecurity's website to fetch the list would have them place an exploit to a vulnerability in my browser on that page.
Hey! That's the combination to my luggage!
hfink37@yahoo.com | hunter2
Nice to see the classics aren't neglected
ambersmith4jesus@yahoo.com | splash9
Danielbenjamin4jesus@yahoo.com | 111222
jimmy.pelham@yahoo.com | jesus08
lasterbarbara@yahoo.com | Iovejesusforlife
sweetsabu20@gmail.com | jesus143
Hee hee...
The fact is that more crimes are committed by people with hotel rooms that have Bibles in them than rooms that have have pornography in them, so burning the former makes even more sense than burning the latter.
Before I start this rant i should point out i havent been compromised by LulzSec so these arent the words of someone who has been burnt. /sarcasm off
Hacking to prove a point is one thing but releasing passwords for 100's of users is the act of juvenile twats that have never had a girlfriend. All they have suceeded in doing is causing grief for innocent people. Well done! Why dont you go round pissing in peoples letter boxes while your at it
They need to grow up, move out of their mothers basement and get laid.
They remind me of the teenage anarchists that go to protests, not to protest about anything but just to smash stuff up. To seek attention for their pathetic lives and score points and try to look cool with their retarded friends.
So basically, fuck you LulSec I hope you get whats commig to you.
I've found majority of all porn sites have major flaws that accept ACH/online checks, all you have to do is put a legit routing number (you can get routing numbers for all banks online just google) then use a fake account number but a real address. Works every time for registration, and the username/password lasts from 3 days to a week. Course you only need it for a few minutes anyhow... HA! :)
btw kudos to the Lulz
FUCK lulzsex
1) Use Linux, BSD or another real OS.
2) pwgen -sy 128 1 > mypasswd
3) steghide embed -ef mypasswd.txt -cf verylarge.jpg -e rijndael-256
4) post in plain sight
5) Connect to SSL only.
Wow, this would not have passed muster on Slashdot once upon a time...
How about
/path/to/lulsec_passwords.txt
while read email foo
do
commands
done <
My Password dictionary thanks you.
awk -F '|' '{print $2}' pronz.txt | sort -u >> passwords.txt
As a whole, Anonymous tends to be far more political oriented and symbolic with its attacks while Lulzsec's attacks have been more harmful and not linked with a political message. Though they have aimed at big corporations, the FBI, Fox News, they've also hit PBS and a porn website. Your argument would be true if "Anonymous" were responsible for the Lulzsec attacks or if Lulzsec was promoting itself in the same way Anonymous does, yet hits PBS and porn sites and exposes personal data of thousands of ordinary people. In the best light, Lulzsec is showing these big companies, despite their massive profits, are not spending the extra money to make sure the data of their employees and customers are safe and people need to be careful with their usernames across sites, the emails they use to sign up to sites, and their passwords. However, many may just be motivated for the personal thrill of getting access to this data from big companies and governments.
To do this is just stupid. Why would people do this? If there was some sort of way to earn money of it, I would at least understand why. Who cares if some people watch porn? Even if you think watching porn is harmful in some ways (I think it might be in some cases), to spread peoples passwords is in any case a lot worse than that. You have to be some heartless idiot to do this to people for fun.
That a group of people can do this to other people makes me loose a bit of faith in human beings. Did no one in this group stop and think what they were doing?
That would be great then we would all point and laugh and tease them all like little school children for liking midget donkey porn; o how we love to point out other peoples' short coming.
After actually looking at the list for a minute I came to the conclusion that the mail addresses were not verified (domain names spelt wrong :-) . The question really is - what percentage of these mail addresses are fake and which are real? Anybody can punch in your mail address in a webform. It doesn't proof anything. I would be very careful drawing any conclusions from this list, or trying to do anything with the data - it can land you in a lot of trouble.
Specific example of domain name problems. I searched for all e-mail addresses for South African companies (.co.za) and came across "0789746848@mtnloeded.co.za". The real domain name should be mtnloaded.co.za - mtnloeded.co.za does not exist. If the spelling mistake slipped through it means that the mail address is unverified. Now I would love to give "Cecil" a call on +27 78 974 6848, but I cannot be sure it is in fact him. The sheer number of wrong e-mails I receive on my e-mail is of further concern in this situation - somebody could by accident type in my mail address and I would suddenly appear on a list like this!
So all in good fun - chances are the more controversial mail addresses are fake.
Sarcasm noted, but I wonder what kind of market there would be for sexy stuff that's actually well-written and well-acted?
I listen to both RIAA and non-RIAA stuff if I like the music, tangential business/politics nonwithstanding.
...won't somebody think of the pedophiles?!
So they are no better than the kids that paint graffiti.. no point or direction, just to cause mischief.
---- Booth was a patriot ----
Should it not have read:
Hackers Expose 26,000 Sex Website Passwords
from the sex-wants-to-be-free dept?
OR:
Hackers Expose 26,000 Sex Website Passwords
from the just-another-26,000-exposed-Weiners dept?
http://xkcd.com/792/
The reason why you never hear about porn sites getting cracked is because it is fucking easy. Most porn sites are vulnerable as hell and almost anyone with some technical proficiency can exploit them. They are run by low budget companies who often just cant afford to secure their sites. Cracking porn sites are for pathetic script kiddies with little to no skill what so ever. Also what's up with trying to shame owners of porn site memberships? Fucking puritans.
My cat can hack into it.
to look for the free stuff, they deserve to be exposed.
Awesome. Not only they are exposing their "hobbies" which are OK... the worst is that they are exposing the stupidity of some people. .gov or .mil ending... gosh, stupidity will destroy human life sometime very soon.
You can set up a free anoymous email address in like 3 minutes. Why do these melon heads use thoir personal work address. More so if they have a
Hoaxers, Hackers, and Policymakers
This looks like false flag work done by the crazy judeo-christians at the FBI who take vows of computer purity when entering the Bureau and who feel guilty after jerking off, so they want to expose anyone in government who doesn't share their "morality" and guilt. They are all Catholics and Mormons and Orthodox Jews, they won't let you into the secret club unless you are into secret handshakes and blood atonements. The REAL Anonymous guys have known how to hack porn sites for years and they would go after more corporate targets, than this stoopid, amateurish operation.
Signed, anonymous