Anon - Mass Owning of Seedboxes - A Live Hacking Exhibition
Anon - Mass Owning of Seedboxes - A Live Hacking Exhibition
Anon - Mass Owning of Seedboxes - A Live Hacking Exhibition
Major providers:
Cost: 1 Euro to 50 Euro a month. (yes they take bitcoin, stop asking. No, they don’t
accept dogecoin. I don’t think they accept NFT as trades.. Why are you asking me this crap? No I don’t run a seedbox. Which one
is best? I don’t know, leave me alone. For the last time, I’m not telling you my real name. don't
let this distract you from the fact that in 1998, the undertaker threw
Mankind off Hell In A Cell, and plummeted 16 ft through an announcer's table.
Software run by “users”
Indexers (Jackett / Prowlarr)
Some aren’t password protected - and leak API keys and l/p to private sites
Why pay for “l33t” private sites when you can steal API keys for them instead?
Why pay for Usenet access when you can just steal it?)
……
In case I don’t get to it during live talk …
● Rclone.conf is a great target
● Vpn.conf / vpn.zip / username.ovpn - great way to get free VPN
● $1 can get you a shell account on a small (insecure) VPS
● *arr does world-readable backups to /tmp/
○ sqlite3 *db "select * from downloadclients"
○ sqlite3 *db "select * from indexers"
○ Docker is bad (df/mount hack)
● Plaintext creds in nzbget.conf / sabnzb.ini / silc.conf / rclone.conf
● Giga-rapid.com sucks
● Seedhost.eu easiest target - biggest reward
● PLEX Tokens
● Orpheus - private torrent site - one admin uses a seedbox to leach/upload
Be careful…
Seedboxes protect you from your ISP - but that is all they do.
Your data is still at risk. Your data can/will be found.
If you pay for illegal things don’t get mad when they are stolen.
Don’t expect admins who run seedboxes to know anything about security.
Don’t put API keys or passwords on seedboxes… you moron.
The FEDs could be doing these same attacks. I could see the real source IPs for
all other users in `last` logs.
Lots of people used their same username on different providers.
Lots of people would tunnel data back to their home machine, or SSH to other
boxes, like idiots.
bye