Adult Friend Network Gets Hacked - Again

More than 399 million accounts are fake ones. No worry.

That is not the point of this post. The fake accounts don't matter. This network clearly has security issues that needs to be fixed. They've been hacked twice now. That's a problem, don't you think?
 
Then they need diapers. Or surgery.
?

You'd think. Not sure if they're being cheap or just have people working on it that don't know what they're doing.
I am not sure either. All these fixes are really invisible to me.
My main interest is fucking real shit.
 
Then they need diapers. Or surgery.



You'd think. Not sure if they're being cheap or just have people working on it that don't know what they're doing.
You can't secure yourself - it's just not possible. You can only hope someone doesn't pop you, and if it happens that your response game is on point.

Sure you can patch SQLi and the known exploits, to keep out skiddies, but ultimately you draw someone's attention you're going to get owned, there is just no way around it without completely disconnecting yourself the Internet. And even then, DMZ servers have been owned time and time again.

lots of times its not even the main site(in this case ADF) that gets popped, but some peripheral company or vendor and then they leverage that laterally to gain access.

Read through the latest HTP5 E-zine(Hack The Planet - it's still a little dated, 2014 I believe, Nacash mirrors it on GitHub)and you'll see just how easy it is to traverse through "side channels" once you break one link in a very long chain.

They dumped sucuri, linode, and several other high profile security PROVIDERS - even giving an 0day to the trendmicro site(that would be Norton AV).

It would be great if there was a simple 1-click fix to security, but there isn't.

The real question is why all the passwords were either cleartext or sha1.. Someone had to OK that.. And then someone had to actually implement that - without even questioning it. Unsalted too...
 
Last edited:
You can't secure yourself - it's just not possible. You can only hope someone doesn't pop you, and if it happens that your response game is on point.

Sure you can patch SQLi and the known exploits, to keep out skiddies, but ultimately you draw someone's attention you're going to get owned, there is just no way around it without completely disconnecting yourself the Internet. And even then, DMZ servers have been owned time and time again.

lots of times its not even the main site(in this case ADF) that gets popped, but some peripheral company or vendor and then they leverage that laterally to gain access.

Read through the latest HTP5 E-zine(Hack The Planet - it's still a little dated, 2014 I believe, Nacash mirrors it on GitHub)and you'll see just how easy it is to traverse through "side channels" once you break one link in a very long chain.

They dumped sucuri, linode, and several other high profile security PROVIDERS - even giving an 0day to the trendmicro site(that would be Norton AV).

It would be great if there was a simple 1-click fix to security, but there isn't.

The real question is why all the passwords were either cleartext or sha1.. Someone had to OK that.. And then someone had to actually implement that - without even questioning it. Unsalted too...
I wonder if she can understand this. lol
 
Biggest issue is large amount of passwords saved in plain text in this age..
 
Do you think being hacked like that damages their bottom line? I don't think they were doing too good to begin with.
 
Do you think being hacked like that damages their bottom line? I don't think they were doing too good to begin with.
They don't seem like as big a brand as AM was, so it's not as damaging to them as it was to AM when they got hacked.

Also, the kind of guys who click on an ad for "hot women in your neighbourhood looking to fuck" probably aren't the best fact checkers, so the hack should go undetected for the larger populous.
 
Back
Top