Popular Dark Web Hosting Provider Got Hacked, 6,500 Sites Down (zdnet.com)
Daniel's Hosting, one of the largest providers of Dark Web hosting services, was hacked this week and taken offline, ZDNet reports. From a report: The hack took place on Thursday, November 15, according to Daniel Winzen, the software developer behind the hosting service. "As per my analysis it seems someone got access to the database and deleted all accounts," he said in a message posted on the DH portal today. Winzen said the server's root account was also deleted, and that all 6,500+ Dark Web services hosted on the platform are now gone. "Unfortunately, all data is lost and per design, there are no backups," Winzen told ZDNet in an email today. "I will bring my hosting back up once the vulnerability has been identified and fixed."
Sorry TRUMP TRAITORS, you're going to get your dumper databased instead!
Oh, msmash and the eternally failing quest for k-radness. Welp, more drivel I don't need to read. NEXT.
Have gnu, will travel.
Only a moran would pay this tool anything.
but copied by the thieves first... DUH!
Dark Web.... That's some funny shit right there. Stupid, dumbass, motherfuckers!
If they had merely created a backdoor account and given the FBI access, I'm certain that the server would have been seized and a shitload of arrests would have happened. There is no way he was hosting 6500 darkweb sites without lots of them being highly illegal.
Anons need not reply. Questions end with a question mark.
Good chance that whoever deleted the accounts from the database also downloaded a list of account information. It makes you wonder whodunit.
Big Red Button next to the front door. 'In the event of a search warrant, press"
Have gnu, will travel.
Who in their right mind would use you as their host now?
Considering how linked the two are, I expect people are cashing out their ill gotten coins as fast as possible.
went dark. Oh the irony.
"Dark Web" does not necessarily mean "illegal" or "illicit".
He'll never be secure. The people who wiped the database no doubt kept a copy. All his customers are known. All their contacts known, probed now. If they try to re-establish hosting with him, they'll slip back in with that. No problem.
Let me guess, hacker router his connection through the dark web? :D
In your IMPERSONATIONS of me (like u do now) saying what you thought "makes me look bad" e.g. https://tech.slashdot.org/comm... (like now)? You did me a favor & got me to look @ these closely:
1st - Hosts stop portsmash (blocking downloads of it) "You basically have to already be able to run your own evil code on a machine in order to PortSmash it." from https://www.theregister.co.uk/...
2nd hosts MAY prevent the OTHER forms of Intel CPU weakness per ACADEMIC RESEARCH I read:
SPECTRE "As an attempted mitigation for our JavaScript-based attack" https://spectreattack.com/spec...
MELTDOWN "We presented Meltdown, a novel software-based attack" https://meltdownattack.com/mel...
So like portsmash?
Academics NEEDED LOCAL CODE (like portsmash hosts can prevent) so hosts ALSO work vs. Spectre/Meltdown!
APK
P.S.=> 3rd strike "yer out" - U FAIL PORTFILTERING TESTS https://yro.slashdot.org/comme... (IF hosts could DO it I'd implement it in my work & I STOP THAT ERROR) ... apk
Thinking of buying some wax from Dream Market. Any experiences with the place?
gweihir KNOWS you IMPERSONATE me https://it.slashdot.org/commen... c6gunner proves it https://linux.slashdot.org/com... forgetting to SUBMIT BY AC & f'd up using his registered 'lusrname' instead (just because he tried to mock me both BEFORE & after I FAIRLY challenged him to show he's done better work - he had ZERO).
& NO WAY I'd "cry" like you to any "ne'er-do-well" on /. OR post on hosts offtopic.
YOU EVEN HELPED ME https://science.slashdot.org/c... (& you quit trying to make me look bad trying to "tell lies" on hosts as "ME" IN YOUR IMPERSONATIONS of me e.g. https://tech.slashdot.org/comm... & regarding Intel speculative execution attack? Hosts DO PREVENT THEM)
APK
P.S.=> LMAO - I KNOW that 3rd/2nd to last link above's KILLING YOU that YOU ACTUALLY HELPED ME getting me to see if hosts stop more than portsmash (& Meltdown + Spectre too) & "lo & behold" - hosts WORK on 'em - U LOSE (& U STOPPED TRYING IT in your impersonations of me) .... apk
Perhaps not so popular after all.
Perhaps one-way is the wrong term, perhaps "Postbox"-Backups are a better term?
I mean, we have the tools to create a public & private key used for asymetric encryption.
With my public-key I can encrypt data and without the private key this data can't be decrypted?
How to use these keys in backup and restoration?
So when I would generate such a key-pair and put the public key into the backup service of this hosting provider, the data could be backed up and gets encrypted with the public-key. But nobody except the owner of the private key could decrypt it.
The owner of the private key should not be the hosting provider :)
postbox ..)
It is like a postbox, you can put letters in, however only the mailman can open the box with his key and get the letters out. (disclaimer: metaphorically speaking, not including access by lock picking, explosives, extortion, and so on
Another application
Naturally it would also be possible to equip an email service with this technique, the server receives an email and without storing it anywhere outside RAM, it will be encrypted with your "public" key first and then stored inside your mailbox. You receive it and decrypt it locally.
This way a person getting access to the eMail-Account without the private key will only get encrypted data.
Or am I getting something wrong?
I know if we would live in a perfect world we all would do key-exchanges and signing and ofc singing and dancing. But this world is far from perfect.
Why do so few people set up web servers at home? It ain't rocket science. It can be done on *any* computer. Really. Unless you're hosting something really huge or something that gets a huge amount of traffic, just fire up any old PC, install a web server, and you're done. Do your own backups (drag and drop folders, if you're too clueless to schedule something). People used to do it all of the time, back when setting up things like web and FTP servers were more complicated than it is now. It's100% free, and if you're doing something sketchy, you've got 100% control of your own files and your own backups.
I don't respond to AC's.
Good for him for operating a darkweb 'service' like it should be.
And switches and firewalls and VOIP-Gateways and .. and .. and ..
Yeah I know the hoster still looses because he hosts true to himself like a real darkweb hoster.
I'm sure people would love to vote for a candidate, boasting about groping womens genitals and doing such a bad job as being recorded with that statement?
And actually they did, what will this now tell about if these people would live to see children or women being raped in the open?
I'm just a guy who can help what is a HUGE problem out there - malware in general. That's all. My hosts engine's for that, for free. Less people can "spread the contagion" etc. too!
NOW, if the "powers that be" REALLY wanted to help that?
They'd STALL GoDaddy type hosting providers doing $1 unlimited domains!
WHY? Security pros KNOW the same thing I do on that note & say it:
"95% of all newly registered domains are associated with malware or spam. And they are very short-lived. For those who register hundreds of these domains, however, this is not a problem. For example, if a spam domain remains online for longer than 15 minutes, the players have already made a profit during this time. After that, a domain is usually either blocked, deleted or blacklisted" https://www.gdatasoftware.com/...
Those hosting providers ARE the BIGGEST part of the "CANCER".
I also STRONGLY suspect many "techies" wouldn't LIKE that as a GOOD 90% of many of their days ARE removing malware (& the more skilled of them imo? CREATE the malware to perpetuate all that + their income (greed & "$" IS the root of all evil imo))
APK
P.S.=> Lastly on trolls: They're PAPER TIGERS (@ best) vs. me, a Cyberian Tiger https://tech.slashdot.org/comm... ... apk
Of course we know the Feds kick first instead of ringing, so make sure you have a doorswitch as a wipe first backup :)
Hey slashdotters.
I was using DW's hosting service.
I didn't surprise he didn't took any backups because that's what I wanted to hear.
I have a backup myself, you know.
I know how to setup dot Onion server on my computer by myself.
I've used his service only for clearnet access, so anyone can visit my website via clearnet.
There are no alternative hosting service which meet my requirements:
1. Don't take my backups unless I told you to do so,
2. Don't require my identity, such as credit card, unless necessary,
3. The server MUST NOT block Tor access,
4. The server SHOULD NOT use Tor blockers, such as Cloudflare,
5. The server support Tor access.
DW hosting was perfect.
You are welcome to visit my website - completely legal. .onion is bad.
The "darknet" is just a part of Onion universe. Not everything on
Anonymous
Wow you really just can't stop yourself can you.
What none of us can understand is why you don't just fuck off and never look at this website again. Then all of our problems would be solved. Surely you would be happier on reddit?
Why do so few people set up web servers at home?
Last I checked there were 7 billion people in the world and roughly half that many IPv4 addresses. This means each IPv4 address will, on average,* correspond to more than one home subscriber. Thus ISPs in many countries put each neighborhood behind a carrier-grade network address translation (CGNAT) device, which allows a hundred or so to make outgoing connections on the same IP address. But a device behind CGNAT cannot receive incoming connections because the CGNAT does not know to whom to forward the connection. For example, if someone connects to port 443 of a public IP address that you share with 200 other subscribers, how does the CGNAT know that the connection is for your server, not a server run by someone who lives a block away? Even if you have your own /56 worth of routable IPv6 addresses, that doesn't help when an IPv4-only client attempts to connect to your server.
* Some countries have more IPv4 addresses per 1000 people than the average. But this means other countries have even fewer.
Just Dark Web? Imagine subpoenas for backups of 4chan's /b/ *the horror
now i know what to tell my boss the next time there are no backups.
it's by design!
On a long enough timeline, the survival rate for everyone drops to zero.
No, this is the planned downtime while they're finishing the server migrations...