Hackers Run Wild Spending BitTorrent Tracker’s Donations
Written by enigmax on December 29, 2007The SuperTorrents BitTorrent tracker has been the subject of a major security breach, with hackers gaining access to private accounts from which they donated all the site’s money to a religious group. The hackers even went as far as contacting the site’s host and canceled all of their seedboxes.

Earlier this year, the anti-piracy company MediaDefender was torn apart when its email system was compromised and hackers laid the company’s secrets bare for the world to see. Some months later, the SuperTorrents (ST) BitTorrent tracker has been the victim of hackers. According to a so-called ’scene notice’ circulating at the moment, the 35,000 member site was compromised when the hackers discovered that the admin of ST used the same password on a lot of other sites, as he does on other accounts - email etc. This is the same mistake that MediaDefender made.
The notice begins:
Now this is the story all about how Ersan’s life got flipped turned upside down and I’d like to take a minute and just sit right there and tell you how Ersan became the prince of a town called bel air. This weeks source of lulz is provided free of charge via a site called supertorrents.org and the nicest Administrator you’ve ever met, Ersan.
The hackers discovered that the same password secured the site’s PayPal donations account. They claimed that due to the admin of ST making derogatory comments about a religious group, they decided to donate all the site’s available donations - over $2000 - to an Internet portal dedicated to that same religion.
While the hackers said they had fun deleting and disabling some more minor accounts like the admins YouTube account, they had rather more malice in mind when they managed to get access to the admins Gmail account (same as MediaDefender again). They discovered the admin’s real name, address, age and even the car he drives. After having fun making a mess of the account, the hackers said: “At this point we just deleted his account, because maximum lulz were achieved.”
The hackers then accessed the site’s admin panel for communicating with their host: “we logged into his [hosts] account panel where he hosts the supertorrents seedboxes and canceled them.”
The hackers give an explanation of the way they compromised the site:
“This all began a few days ago. Me and some friends were scoping around supertorrents irc network, when we discovered that they had a public prechan. Upon discovering this moderate scene security problem some friends and I decided to check the security of said prebot, turns out it was not so secure. Upon rooting the box and grabbing the unsecure predb and some scripts to play with we then rainbow tabled’d his password hash”
The motives for hacking the site seem to be twofold. Many Scene members consider torrent sites to be to blame for compromising their security and there does seem to be indication that this provoked the hacking in part. Money is mentioned quite a lot, in that it seems the hackers are annoyed at the level of donations at SuperTorrents, even appealing to the members to consider where their money is going.
It’s also claimed that many torrent sites are getting their releases from the same place and there are suggestions that this supply to the BitTorrent community should be strangled.
No doubt the MPAA will be delighted to hear this.
Update: More information is coming through which suggests that Ersan feels that his address hasn’t been compromised and he doesn’t drive the car the hackers say he does. Ersan says that his host did not cancel the seedboxes and he further says that his Google email (far from being deleted) is actually recovered and the password has been reset. He continues: “From what I can tell, the server that they’re talking about was not rooted, but I’m going to reload the OS on it anyway. This has no effect on SuperTorrents in any way, it just screws with my personal email and finances for a few days. The worst part is not knowing the extent of the damages that have been done, if all that was done was what was stated above then I’ll be fine. If they downloaded all of my emails and chat logs or something then I have a real problem on my hands”
Update 2: The hackers seem to have responded: “Nice attempt at damage control. :/ We do have your real street address, among with a few others you were using. If we were just going to blank it out anyway, whats it matter? Shouldn’t you be happy we did that, I guess we could go with the unedited copies of your name and addresses for the third notice. You just made an order XXXXXXX.com (lol, nerd) would you like us to post the usps tracking number & address? (1) Your address is talked about many times in google chats, once again you’re lucky we dont post them here. You did buy a BRANDX(car), for $12,000. Heres some screenshots (2&3). We could always post more information about it, as we have your entire email box from a few weeks ago until now. Would you like us to? was it your father or brother that you got the carfax for, lol?”
In reponse to Ersan’s claim that the host did not cancel his servers: “Correct, [host] did not cancel your servers, they did however cancel your account. Oh well I guess we can’t win them all.”
The hackers then go on to deny that Ersan has recoverd his Gmail account and provide some sort of screenshot as proof. They also ask Ersan to stop sending ‘forgot my password’ to his own account as “it’s not helping.” They then go on to use Ersan’s real name and in what could be seen as a veiled threat say: “Be thankful Eric, that we didn’t give you the raging that was easily possible with all of the email and google chat logs we have. We PROBABLY won’t release those, but hey you never know! :)”
thanks r10t
Previously: Steal This Film 2 Goes Live
Next: Top 10 Most Popular Torrent Sites of 2007



247 Responses
Pages: « 1 [2] 3 4 5 6 7 8 9 10 » Show All
Actually it is quite ironic that they should choose to attempt to donate the money to charity, as ironically that is preciselly what is happenning with the excess anyway.
It should be noted that none of the site servers were compromised and everything that they got their hands on was personal to ersan and not the users of the site. All of the money that is donated is only being spent on the site. Some of the acusations in the NFO (not all) are actually quite amped up to make them sound far worse than they are - or in the case of a couple of them are plain outright lies.
Fuck anyone who asks for money for torrenting - in ANY form (i.e. donations, subs, whatever.)
I pity the poor fool, but
(i) he duplicated his password across his accounts,
&
(ii) it seems he was targeted BECAUSE he’s a ‘pay-to-leech’ site.
Pretty much your own fault, dude…
i will never understand the concept of hacking. seems like a complete waste of time, i never find any humor in it. then again, i don’t find joy in being extremely computer savy so, that might be my downfall.
[quote comment="251035"]
Please do try to isolate your mediocre “scene” from the torrent world - we don’t need your superior asshattery.
Kthxbai.
[/quote]
We do need your files tho!
Happiness in the misfortune of others?
http://youtube.com/watch?v=2NUQ_oa3JSU
Fuck sites that ask for donations you say? Then how to you think the servers will be payed for?
To those of you who say asking for donations or sites rewarding donors to show appreciation is wrong: Obviously have no idea what it costs to actually run a site of that magnitude.
As long as you dont have to pay to become a member there’s nothing wrong with donations or adding a couple of gigs to someones account in order to keep the donations up.
You’re all fucking unrealistic morons who sit there on your high horses and expect the server bills to be payed without help from donors. Get a fucking grip. I know tons of admins who have to pay a lot of money out of their own pocket to pay the server bills just because the donations aren’t covering the costs.
Of course someone has to pay for torrenting, because in the end there’s a big fat server bill to pay. Maybe in your mind servers pay for themselves with fantasy money and candy? Please share with us your elitist and far superior idea for how to cover server costs!
Bunch of emo scene queers got mad one day, so they decided to use some scripts. Aww how nice, now go fuck yourself, and get rid of the skin tight pants and the over gel’d hair.
yeah i think that was pretty shitty thing to do
I see a lot of hate twoard members of the scene in these comments but the simple truth is that 90% of the worthwhile stuff on most torrents sites comes from the scene, and also that 90% of people using these sites to download scene stuff would not beable to contribute to it.
The scene is the essence of P2P, everyone has something to contribute and works for the right to get the rest, and because of torrents and Limewire they are the target of the MPAA etc even more than ever now.
bahahahahahah
So tell me again why private trackers are safer than public ones?
It was a group of 12-15 year old kids that call themselves Anonymous
a very small amount of them are actually educated with computers and can hack, the rest just egg eachother on and act like retards.
you can find them at:
4chan.org
7chan.org
420chan.org
12chan.org
[warning, many boards are not safe for work]
BS… most of the stuff come from individual such as ourselves
Private site doesn’t make you cool or elite
It’s just people who are selfish and want to share with only those who are member.
The point of p2p is to share
Not to make money
Not to take credit for what you share
But to make it widely available to the general public
Who cannot afford to pay for it
or cannot buy it due to limited quantity of it and is sold out…
Capitalism is a flawed system that only the rich can afford everything and we need something better called freetalism
:D
free= p2p.
Money is a form of control with p2p it will undo it’s evil
All you need is a computer, with internet connection, a dvd burner
plenty of blank media and you’re set
[…]
Your response is awaiting moderation.
^^^
i see the nazi are in control of this website as well
if you’re going to moderate what we say you may as well become hitler!
fuchthisgayshit
By the way the amount of donations he was recieving are FAR more than the server maintenance costs. Who says he was donating all the money to charity? Where is the evidence of that? The only expense I see is a new Lexus.
[quote comment="250993"]Honestly,im happy that this hapened,sites like these do nothin but ask for stupid donations all the time,even when content they have is not unique all the time,its so annoying.
Stuff should be free,if im supposed to pay to downlaod,i’ll just buy the damn thing,jezz.
Hack them again i say.
P.S :I know they dont force u but the situation is made as such ,that if u pay u get preference and all that,thats not cool.[/quote]
[quote comment="251045"]Fuck anyone who asks for money for torrenting - in ANY form (i.e. donations, subs, whatever.)
I pity the poor fool, but
(i) he duplicated his password across his accounts,
&
(ii) it seems he was targeted BECAUSE he’s a ‘pay-to-leech’ site.
Pretty much your own fault, dude…[/quote]
Ri-i-i-ght. So websites and servers should be bought, set up, and maintained and you a$$holes think someone else should pay for it all out of there pocket just so your cheapskate a$$ doesn’t have to contribute anything to the community. Why don’t you pinheads STFU and go leech off of some other community. Damn, there ought to be a minimum age to torrent. I’m so f’n sick of these whining juvenile crybabies who think they’re entitled to anything and everything and never give back Jack Squat.
I would seriously pay money to see one of them hauled out of their homes by a police officer. They really need to get a life.
Did this affect STmusic, as well?
I still think half of the people bitching about donations are idiots. ST takes an enormous ammount of traffic, hosting that means that server costs for the webserver alone are enormous. Add to that any other infrastructure required so that things dont run at 1kb/s, and you can quickly see where it goes. In the past, some people have come up to me and said “Why are you paying that much, u can get a 10mb server for $50 a month”. The irony of that is that they obviously have no clue as to a) bandwidth demands or b) resource demands of a site that large.
I would suggest that those who presume to tell admins to fund it out of their own pockets - which is the alternative - should set up their own site and see if they can absorb the costs on the couple of bucks they get in pocket money a week.
As for the bit about “who said they were donating stuff”, try reading a bit more info before spouting off about things like that. Its common knowledge! - go look at the banner on the front page!
Ersan Updated his response to the 2nd scene notice yesterday:
Once again, I do not have a lexus, I thought about buying one but there’s no way I can afford it, the VIN numbers I looked up were for my father, he works for the florida government in law enforcement and wanted to run title searches on the two cars I looked up - run your own history reports and you’ll see that there was no title transfer in the last several months. I drive a 1993 honda accord that I bought from my dad’s friend for $2500 and recently replaced the engine in, which is something I talked about on IRC quite a bit… (if any of that is important to you)
Softlayer did not cancel my account, and I currently have full access to it, the subaccount they had access to has been disabled.
The only thing I don’t have access to anymore is my e-mail.
Apparently google didn’t reset my password, it will ‘take up to 15 business days to investigate the issue’ and they probably do have my real address, but the one on softlayer is somewhere I haven’t lived in months… There’s nothing I can do about that, the only thing I can do is wait for google. I have no control over what these people do with my information - I do hope there’s no public release of my home address or I will be forced to move, my name is not so important. If anyone knows how to contact google directly please let me know, otherwise I have no more options but to wait for them to ‘investigate’…
Let me stress again that none of this affects supertorrents in any way, it only affects me personally, the passwords and e-mail addresses associated with ST are different than my personal ones - whether that was their intention or not is something I don’t know.
$12k for a lexus? He donates his time to. If people want to donate let them. It doesn’t hurt anyone except him when the MPAA/RIAA knocks on his door.
2 references to this post
Pages: « 1 [2] 3 4 5 6 7 8 9 10 » Show All
Responses are closed
All remaining responses will continue to be archived. Use the TorrentFreak forums if you want to discuss something.