Post: Demon Forums *sigh*
11-08-2016, 12:52 AM #1
TeOz
The God of Fridges
(adsbygoogle = window.adsbygoogle || []).push({}); Hey,

Some of you know me, some don't. I've been around for many, many years and I've seen many things. Finally decided to move on with my life, settle down, get a missus, start pushing my career... but no. Out of the blue I get a call from an old friend who tried to purchase a site saying the admins scammed him for $100. I'm a nice guy at heart and I've done some hacking in the past, so I thought why not, let's see what I can dig up. The site in question is ofcourse DemonForums ran by a teenage scottish lad who goes by the alias of Nova among others I'm not going to disclose. Neither am I going to dox the wee lad, because it's not my style.

It was running MyBB. I've actually auditted MyBB in the past so I know a few tricks with it, including an object injection vuln in the Admin panel funnily enough. Good times. Long story short, the Site is dumped and my friend now has the copy of the site he payed for. I got bored one night and decided to do some digging through the DB and see what this "Nova" kid really was like... turns out this isn't the first guy he's scammed and the more I kept looking the worse it got.

Not only is he stupid enough to brag about everything he does... but he does it all in PMs which are stored in a database for people like me to look at. I'm not going to bore you all with the details, I cba and you cba reading it all anyway. So instead I'm going to drop an attachment of PMs between Nova and some wannabe blackhat gfx artist who greps for passwords. For some of you it'll be hilarious

Obviously after finding this shit out, I got access into as much as possible and logged everything. I've tried telling you all before, but I think every now and then you all seem to forget and have to be reminded. Carding is bad, Scamming is bad. If you do either of these things... you are a bad person. You're not hackers because you grep DB entries from other people's dumps and use wordlists to crack (yes crack! not decrypt) hashes.

Feel free to make a fool out of Nova on my behalf. Ohh and shoutout to the old PS guys I haven't seen in ages and all my old friends. If you want to stay in contact with me, let me know because I will be gone again really soon :p

You must login or register to view this content.
Last edited by TeOz ; 11-08-2016 at 12:57 AM.

The following 8 users say thank you to TeOz for this useful post:

BurtE, Father Luckeyy, Hydrogen, OfficialJesseP, Placid, Dacoco, Kronos, Tustin
11-08-2016, 01:03 AM #2
JB
[i]Remember, no Russian.[/i]
Originally posted by TeOz View Post
Hey,

Some of you know me, some don't. I've been around for many, many years and I've seen many things. Finally decided to move on with my life, settle down, get a missus, start pushing my career... but no. Out of the blue I get a call from an old friend who tried to purchase a site saying the admins scammed him for $100. I'm a nice guy at heart and I've done some hacking in the past, so I thought why not, let's see what I can dig up. The site in question is ofcourse DemonForums ran by a teenage scottish lad who goes by the alias of Nova among others I'm not going to disclose. Neither am I going to dox the wee lad, because it's not my style.

It was running MyBB. I've actually auditted MyBB in the past so I know a few tricks with it, including an object injection vuln in the Admin panel funnily enough. Good times. Long story short, the Site is dumped and my friend now has the copy of the site he payed for. I got bored one night and decided to do some digging through the DB and see what this "Nova" kid really was like... turns out this isn't the first guy he's scammed and the more I kept looking the worse it got.

Not only is he stupid enough to brag about everything he does... but he does it all in PMs which are stored in a database for people like me to look at. I'm not going to bore you all with the details, I cba and you cba reading it all anyway. So instead I'm going to drop an attachment of PMs between Nova and some wannabe blackhat gfx artist who greps for passwords. For some of you it'll be hilarious

Obviously after finding this shit out, I got access into as much as possible and logged everything. I've tried telling you all before, but I think every now and then you all seem to forget and have to be reminded. Carding is bad, Scamming is bad. If you do either of these things... you are a bad person. You're not hackers because you grep DB entries from other people's dumps and use wordlists to crack (yes crack! not decrypt) hashes.

Feel free to make a fool out of Nova on my behalf. Ohh and shoutout to the old PS guys I haven't seen in ages and all my old friends. If you want to stay in contact with me, let me know because I will be gone again really soon :p

You must login or register to view this content.


Shoutout my bro. Top quality scrub wrecking. I think I have your number? We texted the other day right? Haha
Last edited by JB ; 11-08-2016 at 01:08 AM.

The following user thanked JB for this useful post:

Black Panther
11-08-2016, 01:08 AM #3
Placid
Keeper
been a while since i got on here lol nice work bro
11-08-2016, 01:15 AM #4
TeOz
The God of Fridges
Originally posted by JB View Post
Shoutout my bro. Top quality scrub wrecking. I think I have your number? We texted the other day right? Haha


Yea you have my number, the people who stayed in contact with me know how to contact me anyway. I just haven't been on here since Tustin guested my other account for assuming I was involved in Stu's shenanigans when he spawned a shell with CSRF. Love how I get blamed for every NGU hack now xD
11-08-2016, 01:18 AM #5
JB
[i]Remember, no Russian.[/i]
Originally posted by TeOz View Post
Yea you have my number, the people who stayed in contact with me know how to contact me anyway. I just haven't been on here since Tustin guested my other account for assuming I was involved in Stu's shenanigans when he spawned a shell with CSRF. Love how I get blamed for every NGU hack now xD


It's fine I'm not exactly "trusted" either.. not sure why anymore but ah well aye! PS still gets namedropped on vb.org, they tried to blame us for vB4 and vB5 failing. Wanted to reply saying that's like blaming a burglar for robbing your house when you leave the front door keys on your doormat. If you don't secure your shit, shit will happen!
11-09-2016, 07:35 AM #6
TeOz
The God of Fridges
Originally posted by Vince
Adam, is that you?!


Vince long time no see. Some admin disabled pretty much every permission I have. I can't PM and I can't leave you a VM either. I'm not even sure if I can recieve them. If you could restore them or even give me access to the shoutbox for this account, I'll gladly speak to you there.
Last edited by TeOz ; 11-10-2016 at 05:51 PM.
11-09-2016, 03:35 PM #7
Hydrogen
Super Mod
Originally posted by TeOz View Post
Hey,

Some of you know me, some don't. I've been around for many, many years and I've seen many things. Finally decided to move on with my life, settle down, get a missus, start pushing my career... but no. Out of the blue I get a call from an old friend who tried to purchase a site saying the admins scammed him for $100. I'm a nice guy at heart and I've done some hacking in the past, so I thought why not, let's see what I can dig up. The site in question is ofcourse DemonForums ran by a teenage scottish lad who goes by the alias of Nova among others I'm not going to disclose. Neither am I going to dox the wee lad, because it's not my style.

It was running MyBB. I've actually auditted MyBB in the past so I know a few tricks with it, including an object injection vuln in the Admin panel funnily enough. Good times. Long story short, the Site is dumped and my friend now has the copy of the site he payed for. I got bored one night and decided to do some digging through the DB and see what this "Nova" kid really was like... turns out this isn't the first guy he's scammed and the more I kept looking the worse it got.

Not only is he stupid enough to brag about everything he does... but he does it all in PMs which are stored in a database for people like me to look at. I'm not going to bore you all with the details, I cba and you cba reading it all anyway. So instead I'm going to drop an attachment of PMs between Nova and some wannabe blackhat gfx artist who greps for passwords. For some of you it'll be hilarious

Obviously after finding this shit out, I got access into as much as possible and logged everything. I've tried telling you all before, but I think every now and then you all seem to forget and have to be reminded. Carding is bad, Scamming is bad. If you do either of these things... you are a bad person. You're not hackers because you grep DB entries from other people's dumps and use wordlists to crack (yes crack! not decrypt) hashes.

Feel free to make a fool out of Nova on my behalf. Ohh and shoutout to the old PS guys I haven't seen in ages and all my old friends. If you want to stay in contact with me, let me know because I will be gone again really soon :p

You must login or register to view this content.


Demon Forums?! LOOOOOOOOOOOOOOOOOOOOOOL
11-09-2016, 05:21 PM #8
TeOz
The God of Fridges
Originally posted by Vince
Let me talk to them and see what I can do. What happened to your old old account?


Guested because everyone assumed I was involved with the PHP backdoor spawned in the ACP. I know about it, but doesn't mean I was involved and/or was the person who did it.

Not that it matters to me that much now. I just would like the basic permissons so I can atleast stay in contact with people.
Last edited by TeOz ; 11-10-2016 at 05:27 PM.
11-10-2016, 05:27 PM #9
TeOz
The God of Fridges
Originally posted by Vince
Let me talk to them and see what I can do. What happened to your old old account?


* *
Last edited by TeOz ; 11-10-2016 at 05:49 PM.
11-10-2016, 05:35 PM #10
TeOz
The God of Fridges
Originally posted by Vince
skye is still nguvince. we do have an ngu discord as well.


* *
Last edited by TeOz ; 11-10-2016 at 05:49 PM.

Copyright © 2024, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo