Hackers Run Wild Spending BitTorrent Tracker’s Donations

Written by enigmax on December 29, 2007 

The SuperTorrents BitTorrent tracker has been the subject of a major security breach, with hackers gaining access to private accounts from which they donated all the site’s money to a religious group. The hackers even went as far as contacting the site’s host and canceled all of their seedboxes.

SuperTorrents

Earlier this year, the anti-piracy company MediaDefender was torn apart when its email system was compromised and hackers laid the company’s secrets bare for the world to see. Some months later, the SuperTorrents (ST) BitTorrent tracker has been the victim of hackers. According to a so-called ’scene notice’ circulating at the moment, the 35,000 member site was compromised when the hackers discovered that the admin of ST used the same password on a lot of other sites, as he does on other accounts - email etc. This is the same mistake that MediaDefender made.

The notice begins:

Now this is the story all about how Ersan’s life got flipped turned upside down and I’d like to take a minute and just sit right there and tell you how Ersan became the prince of a town called bel air. This weeks source of lulz is provided free of charge via a site called supertorrents.org and the nicest Administrator you’ve ever met, Ersan.

The hackers discovered that the same password secured the site’s PayPal donations account. They claimed that due to the admin of ST making derogatory comments about a religious group, they decided to donate all the site’s available donations - over $2000 - to an Internet portal dedicated to that same religion.

While the hackers said they had fun deleting and disabling some more minor accounts like the admins YouTube account, they had rather more malice in mind when they managed to get access to the admins Gmail account (same as MediaDefender again). They discovered the admin’s real name, address, age and even the car he drives. After having fun making a mess of the account, the hackers said: “At this point we just deleted his account, because maximum lulz were achieved.”

The hackers then accessed the site’s admin panel for communicating with their host: “we logged into his [hosts] account panel where he hosts the supertorrents seedboxes and canceled them.”

The hackers give an explanation of the way they compromised the site:

“This all began a few days ago. Me and some friends were scoping around supertorrents irc network, when we discovered that they had a public prechan. Upon discovering this moderate scene security problem some friends and I decided to check the security of said prebot, turns out it was not so secure. Upon rooting the box and grabbing the unsecure predb and some scripts to play with we then rainbow tabled’d his password hash”

The motives for hacking the site seem to be twofold. Many Scene members consider torrent sites to be to blame for compromising their security and there does seem to be indication that this provoked the hacking in part. Money is mentioned quite a lot, in that it seems the hackers are annoyed at the level of donations at SuperTorrents, even appealing to the members to consider where their money is going.

It’s also claimed that many torrent sites are getting their releases from the same place and there are suggestions that this supply to the BitTorrent community should be strangled.

No doubt the MPAA will be delighted to hear this.

Update: More information is coming through which suggests that Ersan feels that his address hasn’t been compromised and he doesn’t drive the car the hackers say he does. Ersan says that his host did not cancel the seedboxes and he further says that his Google email (far from being deleted) is actually recovered and the password has been reset. He continues: “From what I can tell, the server that they’re talking about was not rooted, but I’m going to reload the OS on it anyway. This has no effect on SuperTorrents in any way, it just screws with my personal email and finances for a few days. The worst part is not knowing the extent of the damages that have been done, if all that was done was what was stated above then I’ll be fine. If they downloaded all of my emails and chat logs or something then I have a real problem on my hands”

Update 2: The hackers seem to have responded: “Nice attempt at damage control. :/ We do have your real street address, among with a few others you were using. If we were just going to blank it out anyway, whats it matter? Shouldn’t you be happy we did that, I guess we could go with the unedited copies of your name and addresses for the third notice. You just made an order XXXXXXX.com (lol, nerd) would you like us to post the usps tracking number & address? (1) Your address is talked about many times in google chats, once again you’re lucky we dont post them here. You did buy a BRANDX(car), for $12,000. Heres some screenshots (2&3). We could always post more information about it, as we have your entire email box from a few weeks ago until now. Would you like us to? was it your father or brother that you got the carfax for, lol?”

In reponse to Ersan’s claim that the host did not cancel his servers: “Correct, [host] did not cancel your servers, they did however cancel your account. Oh well I guess we can’t win them all.”

The hackers then go on to deny that Ersan has recoverd his Gmail account and provide some sort of screenshot as proof. They also ask Ersan to stop sending ‘forgot my password’ to his own account as “it’s not helping.” They then go on to use Ersan’s real name and in what could be seen as a veiled threat say: “Be thankful Eric, that we didn’t give you the raging that was easily possible with all of the email and google chat logs we have. We PROBABLY won’t release those, but hey you never know! :)”

thanks r10t

Previously: Steal This Film 2 Goes Live

Next: Top 10 Most Popular Torrent Sites of 2007

247 Responses (Add yours or TrackBack)

Pages: [1] 2 3 4 5 6 7 8 9 10 » Show All

1 Dec 29, 2007 at 16:43 by kewld00d

That isnt good.

2 Dec 29, 2007 at 16:45 by S_

“level of donations at SceneTorents” should that be supertorrents?

3 Dec 29, 2007 at 17:04 by Ernesto

[quote comment="250954"]“level of donations at SceneTorents” should that be supertorrents?[/quote]

fixed, thanks

4 Dec 29, 2007 at 17:09 by Anonymous

Torrent site run by a 19 year old retard who was stupid enough to use the SAME PASSWORD EVERYWHERE. I’m sorry but he had it coming.

5 Dec 29, 2007 at 17:12 by Anonymous

scene people are bastards

6 Dec 29, 2007 at 17:22 by eejit

If u guys saw the screenshots in the releases youd be laughin to!!

7 Dec 29, 2007 at 17:23 by anonymous

An /i/nvasion to a torrent tracker in favor of a religious group. WTF?

This is the cancer killing /i/

8 Dec 29, 2007 at 17:25 by Anonymous

I did it for the lulz
I did it for the lulz

I did it for the lulz

9 Dec 29, 2007 at 17:28 by Ezekiel Crowe

Is it wrong that I find this humorous at the same time as depressing?

10 Dec 29, 2007 at 17:29 by Nev

He used the same password for everything, even his goddamn youtube account! Wow. The ‘hackers’ sound awfully familiar for the way they talk. Hmm.

11 Dec 29, 2007 at 17:31 by suss

an hero

12 Dec 29, 2007 at 17:44 by ViRAL

God dammit. A torrent site hacked? That’s like taking a “blade” from one of our own!

13 Dec 29, 2007 at 17:52 by Deimon

And the moral of the story is to never use the same password everywhere. Atleast use one for email account and one for forums.

14 Dec 29, 2007 at 17:55 by Kos

Donating money to a religious group? :(
must be the worst way to spend money.

I hope there wasn’t religious motives behind this.

15 Dec 29, 2007 at 17:56 by DOOOMKULTUS

Honestly,im happy that this hapened,sites like these do nothin but ask for stupid donations all the time,even when content they have is not unique all the time,its so annoying.
Stuff should be free,if im supposed to pay to downlaod,i’ll just buy the damn thing,jezz.
Hack them again i say.
P.S :I know they dont force u but the situation is made as such ,that if u pay u get preference and all that,thats not cool.

16 Dec 29, 2007 at 18:00 by Anonymous

Hey if the site admin is missusing donations, hell hack away scene! :)

17 Dec 29, 2007 at 18:02 by fl0p

haha!

18 Dec 29, 2007 at 18:05 by Yatti

Wow so what they did is actual hacking? Not some crazy script work? Crazy stories yo..

19 Dec 29, 2007 at 18:07 by booga1134

they did it for da lulz. I can respect that.

20 Dec 29, 2007 at 18:13 by anon

The site doesnt ASk for donations and for the record it is stated that they give a large percentage of the money to charity every month, extra that is not needed for the servers and seedbox’s.

some people need to realise that Ersan is one of the torrenting hero’s of the moment, supporting piracy and helping us though this all…

xxx hope you get through it Ers.

21 Dec 29, 2007 at 18:28 by lulz

The actual .rars that were released:
Part1: http://uploaded.to/file/o0nn4d
Part2: http://rapidshare.com/files/79729242/SuperTorrents.Got.Owned.Ersan.Got.Raped.TOTALOWNAGE.READ.NFO.PART.2-CELLKILL.rar

Enjoy!!

22 Dec 29, 2007 at 18:50 by Anonymous

And this only goes to prove that the “scene” is really a bunch of attention-starved dickwads.

I mean really now. What the fuck was the point of doing it? For “lulz”? Yes, very funny, we’re all laughing.

Please do try to isolate your mediocre “scene” from the torrent world - we don’t need your superior asshattery.

Kthxbai.

To Ersan: Hope you work it out.

23 Dec 29, 2007 at 18:51 by slash

what a way to do the MPAA’s job for them.

24 Dec 29, 2007 at 18:54 by anon

Seems a bit strange that the ‘hackers’ say they’ve deleted his gmail account, then later offer proof that it hasn’t been deleted by ersan?

25 Dec 29, 2007 at 18:55 by anon

as in offer proof that it was still active.

Pages: [1] 2 3 4 5 6 7 8 9 10 » Show All

Add your response

It takes approximately 1 minute for your comment to appear on TorrentFreak after it's posted.