Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security Bug Social Networks The Almighty Buck The Internet

Attacker Compromises Pornhub, Sells Shell Access for $1,000, Says Columnist (csoonline.com) 57

An anonymous reader writes: Four days after launching a bug bounty program, Pornhub is said to be compromised. The person responsible used a vulnerability in the user profile script that handles images (not ImageMagick) and is selling shell access on one of their servers for $1,000 USD. This is the second major website the hacker has shelled. Prior to Pornhub, they compromised the LA Times website.
CSO's security columnist notes that Pornhub "announced their bounty program on May 9, but it's a private, invite-only program managed by HackerOne. As such, it isn't clear if there would've been a way to report this flaw and collect a reward to begin with." In addition, on Twitter the attacker reportedly posted "I don't report vulnerabilities anymore, go underground or go home."
This discussion has been archived. No new comments can be posted.

Attacker Compromises Pornhub, Sells Shell Access for $1,000, Says Columnist

Comments Filter:
  • by Anonymous Coward

    Bug bounties are bogus. Don't make a lottery out of security.

  • Distractions (Score:1, Offtopic)

    by jargonburn ( 1950578 )

    "I don't report vulnerabilities anymore; go underground or go home."

    Perfect opportunity for a semicolon, imo. Such a waste of an opportunity!
    /grin

  • "I don't report vulnerabilities anymore, go underground or go home."

    Here's hoping I see a future /. story titled "PornHub Hacker arraigned today". I don't give a rat's ass that it's Pornhub, the sentiment that this guy has deserves the consequences in anti-hacking laws.

    • by Anonymous Coward

      All those people that found critical vulnerabilities, reported them in a responsible way and got arrested for doing so are agreeing with him.

    • Re: (Score:2, Insightful)

      by Anonymous Coward

      "I don't report vulnerabilities anymore, go underground or go home."

      Here's hoping I see a future /. story titled "PornHub Hacker arraigned today". I don't give a rat's ass that it's Pornhub, the sentiment that this guy has deserves the consequences in anti-hacking laws.

      As much as I get your feelings on this, the number of people who've been sued after reporting vulnerabilities makes me understand it.

    • by Anonymous Coward

      Here's hoping I see a future /. story titled "PornHub Hacker arraigned today". I don't give a rat's ass that it's Pornhub, the sentiment that this guy has deserves the consequences in anti-hacking laws.

      Maybe you haven't noticed, but those anti-"computer hacking" laws are entirely overbroad and completely vague. That means you could be made to feel the full force of those laws for jaywalking* while holding... anything with a "computer" in it. Like your smartphone, but hey, that microcontroller-equipped sudoku game also qualifies. All you need to make it stick is an experienced smooth-talker, which is apparently the point of lawyer school.

      So while I understand your bloodthirsty sentiment, shoddy laws make e

  • by sycodon ( 149926 ) on Sunday May 15, 2016 @07:30AM (#52114989)

    I watch porn just like every other guy and not a small number of women.

    But who actually pays to subscribe to something that is obviously available for free?

    If they want me to pay money they'd better send one of those Nubile girls to my house.

    • by Nemyst ( 1383049 )
      I could see people paying if someone came up with a Netflix for porn: cheap, access to lots of content and some high quality in-house stuff. As it is now, I don't understand, paid porn sites have prices that'd make even cable providers blush.
      • Re: (Score:2, Funny)

        by Anonymous Coward

        ...a Netflix for porn

        Agreed, there's money to be made here. I mean someone's already made "the Facebook for Sex", which must be doing well as I see ads for it everywhere, AND apparently there's plenty of singles in my area!

    • You miss the point. This is less about them stealing your info, as using the Pornhub network (which by the way hosts many other port tube sites) to distribute malware (likely ransom ware as it makes a shit load of money) to all their free visitors.

  • That last sentence is bogus. Their bug-bounty program isn't invitation only. I have the submission form open in another tab right now. The only requirement that differs from any other is that if your first four reports are bogus, they may stop paying attention to you (known as a signal requirement) .

  • i can view all the porn i want for free, i wont pay some loser geek with leet hacking skills a thousand bucks for access,
    • Re:No Thanks! (Score:4, Informative)

      by sumdumass ( 711423 ) on Sunday May 15, 2016 @09:41AM (#52115379) Journal

      lol.. You are not paying for porn, you are paying for a shell account which can allow you to access porn and a lot more. Hell, you can even set up your own website and host your own porn on their servers if your privileges are high enough.

  • It requires a lot of cajoling or money or both.
  • Dude, not fucking cool.

    Certain sites get immunity from hacking just because. They are privy to an unspoken rule where they get left alone because messing with them is like shitting in your own bed.

    Thats what you did, you just shit in your own bed, and while I realize they have a section for that, its still not cool.

    This is about as uncool as when rootshell was hacked. Again, shitting in your own bed.

You are always doing something marginal when the boss drops by your desk.

Working...