Unstoppable Domains โ€” Expired Auctions

alert Epik Had A Major Breach

SpaceshipSpaceship
Watch

DaveX

@GoDaveXTop Member
Impact
52,011
Last edited:
36
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
Unstoppable Domains โ€” AI StorefrontUnstoppable Domains โ€” AI Storefront
@FiniteCrystal @Paul
I have ultra specific question: If I supply you with my IP, can u return the 'password list' of my failed login attempts?
Yes, but only if your IP never changed. I can also look up an email address. I can do that, that doesn't necessarily mean I will hand over a bunch of potential passwords for other sites.
 
1
•••
Yes, but only if your IP never changed. I can also look up an email address. I can do that, that doesn't necessarily mean I will hand over a bunch of potential passwords for other sites.

I would not do this on a forum without knowing anything about the identity of the forum member asking for that specific info.
 
3
•••
They easily could have implemented something like fail2ban that blocks an IP address after a number of failed logins without storing the passwords

Speaking for NamePros, a much smaller target, fail2ban wouldn't work for us. These days, most of the credential stuffing attacks we see are from large numbers of residential connections, presumably compromised consumer devices. Even a small registrar likely would've seen such attacks years before us.

I don't understand why they opted to store passwords in plaintext, or at all for that matter. That in addition to the fact that they've been doing it since 2011 and never cleared the table suggests gross negligence in my opinion.

Probably, though I've already expressed my frustration and befuddlement at these practices elsewhere in this thread--maybe 500 or so posts ago.
 
4
•••
I have ultra specific question: If I supply you with my IP, can u return the 'password list' of my failed login attempts?

I'd prefer if we don't get into the habit of encouraging such requests here, as it seems like it could lead to abuse. Furthermore, IP addresses tend to change fairly often, so this wouldn't work too well for most people.

Ultimately, the data is in text form. You could search it yourself if you so desired.
 
Last edited:
3
•••
I'd prefer if we don't get into the habit of encouraging such requests here, as it seems like it could lead to abuse.
This is the exact reason I won't take requests like that, just confirming that it is possible.
 
2
•••
No , i am not gatekeeper of NP but owners & admins of forum must think about this & should grand access to new members after we know new members , have some posts , have some positve feedbacks etc..& only after to have access on some area ( topics ) on NP otherwise will be a mess here in a time o period & full of people that they don't have a clue about this industry

FYI ... I know who is behind the username FiniteCrystal. All good! @FiniteCrystal Continue with your research.

Regards
 
1
•••
1
•••
@Paul
I understand that it can be abused. Download is quite large for me. But I give you permission to use my current IP (after login) to look for passwords of failed login attempts. If you are up for it, if not never mind. The thing is, my failed passwords, are passwords just for some other websites. I would like to know what I entered. I changed a lot of passwords, but I cannot remember everything.
 
1
•••
Last edited:
2
•••
4
•••
Nothing special, just to not agree with - "new user ... can't participate..." .

Regards
Ah, sorry. After the way some of the journalists that broke this story were treated, it's a little offputting to read something like "I know who you are".
 
7
•••
There must be no justification for such a Hack and their hackers, many websites get hacked and you will never know it.
In fact it's good that the hack went public it will give strength and security upgrades to the company.
The most harmful terrorists are those which are unknown, not those which are known.
And I have a long question.
Why those companies which host the hacked data on their websites are up and running if they expose so many private data of thousands of users, but a simple site such as those (forgot their DN's) which are mentioned in the hack are down?
 
2
•••
btw, I thought I had bought killcops.com here on Namepros but I had to look it up to be sure. I think I paid $10.

https://www.namepros.com/threads/updates-list-of-names.87000/#post-566345

Also bought QUICKBUNNY.COM, POKERBITCH.COM, and a couple others on the list.

And wow about the Hitler crap. This is turning into a witch hunt. The narrative is obvious. Paint Rob as a Nazi and destroy his image.

I'm not denying epik is a honeypot of the radical right, but let's be objectively fair and aware of scale..

Epik has some major players of the Far Right like Gab. But as you pointed out about many Right Wing sites and domains they are not exclusively or even the majority registered at Epik. Also note that IT IS NOT ILLEGAL. There is absolutely nothing illegal happening.

Cancel culture working really hard today.

They screwed up massively, they stored tons of data that they shouldn't have been storing at all, stored tons of sensitive data in a horrible insecure way, and ignored serious security problems despite people trying to get in contact with them. Your "confidence" that everything is fine comes off as super desperate. Being willingly oblivious to how bad the problem is doesn't make it magically disappear.
[insert "This Is Fine" dog meme here]

Yes, all fairly true. Massive screw up by Epik. I'm fairly sure they know that. A person could absolutely decide to leave their service and middle-finger them on the way out. Or a person could decide their value to them and choose to forgive expecting them to fix the problems. I don't see that as super desperate. Just willing to give Epik a chance at fixing this and moving forward hopefully stronger.

They are doing our industry a favor by investing their time into enumerating a massive dataset. It's hard to relay just how much text fits in 150 GB. It would be different if it were mostly photos or videos, but text takes up far less space. If we were to combine all of the text on NamePros, it would barely put a dent in 150 GB.

But that's where Epik goofed. You logged EVERYTHING and you should not have. I assume you know this now but realistically your site should never had needed 150GB of database or files. My site is 17 years old with 50m posts and millions of members. The whole thing is under 10GB archived. I prune what I don't need. I don't log what I don't need. I don't backup what I don't need. I'm gonna assume Rob made these choices and I hope the lesson he learns from all this is to find a competent CTO to make these choices.

I look at the whole Federated thing and I get it but I don't like it. I've seen these types of attempts at multi-system integrations before. I even tried it myself once. They tend to fail. It might sound easier to have one login but it ends up causing headaches. You're better off allowing social logins like Google, Twitter, and Facebook if you want that type of system. If I want a Bitmitigate account, then I'll sign up for that.

I understand and respect that, but when you're a member of a marginalized community that is often targeted by the groups that Rob is willing to stick up for and serve even when nobody else will, it's impossible to set politics aside. It's impossible to be "apolitical" when the validity of your humanity is a political issue.

Then understand and respect that when you're a member of a community targeted by groups like Anonymous, SJW's or Marxists that people like Rob are brave as they are the few willing to stand up and help when nobody else will. It's impossible to be apolitical when your ideals and speech are being cancelled.

You just want the right to exist, maybe that's all other people want as well. You think it's okay to target people you don't agree with but you're not okay with people targeting you. There is a word for that, hypocrisy. You're here to be political and to smear Rob. I doubt you were ever an Epik customer so this has never personally effected you. I question your motives for participating here. I think you're gloating and want to do your best to spread the story and say whatever you can to hurt Rob and Epik because you have an agenda. Joining here just for that imho disqualifies you from participating in a manner befitting this community.

EPIK was supporting racists and extremists...BUT MANY OF YOU LET THAT GO, and thats why you got fukd in this breach. seriously!

It's actually why I used Epik. Not because I agree with racists or extremists but because I know my domain is protected by someone that actually cares about free speech. As an American I've grown up believing in the Constitution. I continue to see its power being diminished by cancel culture and I don't like it. I'm not a racist, extremist, or whatever label. Just a guy that believes in liberty, not just mine but yours too. When I test on political spectrums I'm dead central. Just saying that believing someone who uses Epik is supporting racism or is a racist isn't accurate.
 
8
•••
Also bought QUICKBUNNY.COM, POKERBITCH.COM, and a couple others on the list.
That list also included MONSTERFIGHTS.COM. Ah, the irony. Lol
 
0
•••
Why those companies which host the hacked data on their websites are up and running
Stop right there with that conspiratorial nonsense. I've been unable to find a working "website" where the data is being hosted. You must download a torrent, which uses a distributed peer-to-peer network to download the files from other users who have also downloaded it. I am not condoning the hack, but now that the data is out there, it's important for many groups to find out what it contains.
 
0
•••
I don't know what this is supposed to mean, but it's vaguely threatening and I don't appreciate it. I know people like you don't appreciate the work I'm doing and hate me for speaking ill of your nazi-enabling pals at Epik (or other mysterious reasons), but attempting to intimidate me with statements like this is incredibly immature.
Don't feel obligated to answer people, I am sure you wouldnt reply to a madman talking to you in the streets.

We appreciate what you've shared so far.
 
7
•••
I don't know what this is supposed to mean, but it's vaguely threatening and I don't appreciate it. I know people like you don't appreciate the work I'm doing and hate me for speaking ill of your nazi-enabling pals at Epik (or other mysterious reasons), but attempting to intimidate me with statements like this is incredibly immature.

"I think" means "in my opinion" ... :) [ Shakespeare has often been compared with a contemporary domainers ]
 
0
•••
That's good enough.
Now back to the topic.
 
3
•••
"I think" means "in my opinion" ... :) [ Shakespeare has often been compared with a contemporary domainers ]

I would imagine she was referring to the "we all know who you are" part of the message as a point of concern, not the "I think" part.
 
Last edited:
1
•••
Just heard about all this. Bit mind blowing as I trusted them with high level security, LOL. If a personchanges their password, adds 2FA, and changes to an email that uses 2FA, that would eliminate most risk of unwanted access/transfers? I'm keen to hear others thoughts, as I have a few there. Cheers all, stay safe
 
2
•••
Spaceship
Domain Recover
CatchDoms
DomainEasy โ€” Zero Commission
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back