Evening all. I'll be keeping this post short & sweet as I can't be bothered with a long, tedious writeup here. Hopefully this post will be the end of these fools.
http://fvcza3k7uoakcxal.onion/uploads/InsanityDRM.php
Firstly, if you're not familiar with WhiteShadow Market, head over & read this post;
https://www.reddit.com/r/DarkNetMarkets/comments/7ekvlc/avoid_white_shadow_market_at_all_costs/
Today I figured I'd take a look at /r/MambaMarket as someone brought it to my attention a week or so back. I had a hunch after having an initial peek that the /r/WSMarketplace admins were behind it.
Well, now I can confirm those suspicions. I won't delve into massive detail here but the end result can be summarised with these images below;
https://linx.li/ib8yvoih.png (Didn't even rename the database, lol)
https://linx.li/98y78ih9.png (Forum on the same server, lol)
https://linx.li/bui7v86.png
This is security at it's worst, it looks like the owner of the market may be running this from his home PC. He's running Whonix in a VM. He has a bunch of interesting stuff on his desktop, including but certainly not limited to the Mambas unencrypted private key & his personal BTC/LTC wallets with his unencrypted private keys. The bash history of the box is hilarious & is mostly the admin running 'bitcoin-cli getbalance' to see if any more unsuspecting users have deposited into his market. Fun fact, there was hardly any BTC in the market wallets regardless of some users have balances in the hundreds in the SQL user database, the greedy admin has already withdrawn most of the market funds so even if users wanted to withdraw, they can't. They also take 1% more commission than they actually claim to do.
Oh and before I head off, when I backconnected to the server to obtain root, the login was the default root:changeme. Solid security practices you have there admin...
Also, lol; https://www.reddit.com/r/DarkNetMarkets/comments/82am6t/olympus_market_is_a_joke/dva7xl3/
Nothing like famous last words I guess.
Lol the best part "they also take 1 percent more commission then they claim"
Sneaky scum