After my expert negotiating skills (I just asked how they did it), they told me how they compromised "Go Momentum" or "Momentum Telecom".
> be ransomware group
> "EndZone" (lmfao wtf)
> want to extort companies
> find url that ISP uses for managing customers
> facing internet
> bonk it with stick
> realize you can bypass authentication
> website-dot-com/ViewCustomer.do?customerId=1
> shows customer information
> wtf
> they try customerId=2
> shows customer information again
> write python script
> repeat millions of times
> get millions of peoples and companies PII
> realize if on url, and hit refresh, legitimately logs you in
> bypasses auth all together
> realized when bypass auth can manage users
> can deactivate modems
> write python script
> disable over 100,000 modems
> over 100,000 places no longer have internet
> they contact ISP
> demand ransom money
> "give us $$$ or else we leak data, do more damage"
> ISP tells them theyre not paying and to fuck off
> compromise never made the news
Post #9490
6.83K
vx-underground dawg, someone just contacted me saying theyve compromised an internet service provider and showed proof wtf am i supposed to do with this? this isnt goop


- 🔥 123
- 😁 62
- 😱 14
- ❤ 7
- 😢 2