MediaDefender Phone Call and Gnutella Tracking Database Leaked

Written by Ernesto on September 16, 2007

The leak of MediaDefender’s emails caused quite some controversy, Ironically, in a recently leaked phone call, a New York attorney and MediaDefender discuss the security of their email-server. Whilst there is some initial confusion as to where the leak may have originated, they eventually write it off as some technical problem.

The leaked phone call shows that they are unsure about their network protection, their IDS etc. One of the parties is on a VOIP connection which may explain how the leak was obtained.

Similar to the e-mail leak, a group called “MediaDefender-Defenders” released the file, and in the .nfo file we read:

MediaDefender-Defenders proudly presents some more internal MediaDefender stuff… more will follow when time is ready. MediaDefender thinks they’ve shut out their internals from us. Thats what they think.

The subject of the call is rather serious. MediaDefender is apparently involved in an ongoing Child Porn investigation. Their job is to identify child-porn images and report the IPs of the offending computers back to the government. A tricky project since it would mean that they actually have to download and rate the illegal content.

This wont be the end of the leaks according to the “MediaDefender-Defenders”, they claim that more will follow when time is ready.

In addition the the phone call, a huge MySQL database dump from a MediaDefender server was leaked on BitTorrent as well. The database shows tracking and decoy file information for the Gnutella network which is used by P2P clients such as LimeWire.

All this leaked information is a huge blow for MediaDefender, and it will undoubtedly cost them a lot of time and money to clean this up. Interestingly, no evidence can be found that MediaDefender is actually involved in prosecuting or gathering evidence against filesharers (as we reported earlier). Their core business is releasing fake files and polluting the filesharing networks.

Previously: Porn Industry Gloats Over Hollow Win vs BitTorrent

Next: The Pirate Bay blocked in Turkey

126 Responses (Add yours or TrackBack)

Pages: [1] 2 3 4 5 6 » Show All

1 Sep 16, 2007 at 21:07 by Tazer

How sad. :-(

Buy some firewalls or something already, sheesh. lol

2 Sep 16, 2007 at 21:14 by jpeg

hahahaha re pwned

3 Sep 16, 2007 at 21:21 by F-the-riaa

What a laugh! This has got to be one of the funniest things I’ve ever heard.

4 Sep 16, 2007 at 21:23 by diznam

Man, whoever’s doing these guys over - they’re doing them left, right, up, down, sideways, dressing them up in the french maid’s outfit, spanking them and making them scream ‘Papi’.

Only in public.

Seroiusly, mad props to that person.

5 Sep 16, 2007 at 21:26 by F-the-riaa

I don’t think these guys are even tracking this yet. While running PeerGuardian, the only banned I.P.’s that have come up so far are

Euroaccess(Anti-p2p)
Chaos Computer Club
CHINANET

I love it! Chinanet is trying to download this torrent also. Pretty soon we’ll see this stuff burned onto CD and offered for sale on Ebay. It’s great!

6 Sep 16, 2007 at 21:31 by Ak

Hahaha.

Holy shit. again!

7 Sep 16, 2007 at 21:34 by santa

“more will follow when time is ready” - I cant wait

Its certainly not going to be a ‘mundane monday’ at the MD office this week!

8 Sep 16, 2007 at 21:48 by linux_user

i lol’d

9 Sep 16, 2007 at 21:55 by Hamster

http://pastebin.com/f5ae055cf

Transcript

10 Sep 16, 2007 at 21:59 by Anonyslimez

Bye bye retards! What a sad attempt at security and trying to prevent P2P file sharing.

11 Sep 16, 2007 at 22:00 by Noby

There is a transcript of the phonecall available. Just check out the Digg-comments (by JB55).

12 Sep 16, 2007 at 22:01 by Santa's Elf

ROFL @ comment 7

13 Sep 16, 2007 at 22:01 by alkdevil

where’s the torrent for the mysql dump? links, anyone?

14 Sep 16, 2007 at 22:04 by I9sm

[quote comment="166679"]Man, whoever’s doing these guys over - they’re doing them left, right, up, down, sideways, dressing them up in the french maid’s outfit, spanking them and making them scream ‘Papi’.

Only in public.

Seroiusly, mad props to that person.[/quote]

That has to be the funniest thing I’ve heard all week! :P

15 Sep 16, 2007 at 22:07 by Timbob

alkdevil: Search for it.

16 Sep 16, 2007 at 22:09 by enter

is there some “this IP searched for this stuff” in the mysql db?

for the db look in google for Gnutella.Tracking.Database.Leak

17 Sep 16, 2007 at 22:09 by rarbytes

sounds like an old phone call to me.. that last guy said “have a good long weekend” and this weekend isn’t one afaik

18 Sep 16, 2007 at 22:09 by Cartman

Let’s hope this public outing doesn’t affect the CP investigations. No one likes a paedo/pedo.

19 Sep 16, 2007 at 22:50 by Kenny

Given the time of the leak and some other hints in the call ( such as Jay’s absense until Tuesday, and the “long weekend”) it sounds like the call took place on August 12, or pre-email leaks in any case.

What I wonder: Does it really take more than a month to implement PGP encryption?

20 Sep 16, 2007 at 22:59 by elgoog

[quote comment="166732"]Given the time of the leak and some other hints in the call ( such as Jay’s absense until Tuesday, and the “long weekend”) it sounds like the call took place on August 12, or pre-email leaks in any case.

What I wonder: Does it really take more than a month to implement PGP encryption?[/quote]

Well, I don’t think it matters as long as an employee decides to copy his entire in (out?) box to his gmail account….

21 Sep 16, 2007 at 23:03 by aphexacid

This is so god damned hilarious. they’re talking about what to do to secure their emails, and the possibility of calling each other to communicate the new passwords over the phone so they dont get intercepted, meanwhile this very conversation has been intercepted.

wow.

22 Sep 16, 2007 at 23:08 by FCKGW

Yeah total corpsehump on MD. Check out the Slyck forums, someone over there did a decent reconstruction of the probable date and said it was likely an August 30 call.

23 Sep 16, 2007 at 23:40 by Flep McGlep

[quote comment="166742"]Yeah total corpsehump on MD. Check out the Slyck forums, someone over there did a decent reconstruction of the probable date and said it was likely an August 30 call.[/quote]

Link to this?

Seems unlikely they’d be preparing for a long weekend on a Sunday, though.

Pages: [1] 2 3 4 5 6 » Show All

Add your response

It takes approximately 1 minute for your comment to appear on TorrentFreak after it's posted.