zlacker

Anonymous Hacks Epik

submitted by cbtacy+(OP) on 2021-09-14 22:37:59 | 413 points 240 comments
[view article] [source] [go to bottom]

NOTE: showing posts with links only show all posts
1. ryan29+L7[view] [source] 2021-09-14 23:27:53
>>cbtacy+(OP)
Did anyone download it and look? This is huge if it's true isn't it? I don't want to download it because I don't know what the laws are, but I'm really interested to know if it's true. Rob Monster is a really big domain investor, right?

This is really big news if it's true.

Edit: I looked it up. Rob started Epik [1]. I wonder if that's really his password. Lol.

Edit 2: I wasn't aware of Epik's reputation either. I just knew they're a big (ish) registrar.

1. https://en.wikipedia.org/wiki/Rob_Monster

2. r721+28[view] [source] 2021-09-14 23:30:01
>>cbtacy+(OP)
Twitter thread: https://twitter.com/chadloder/status/1437517323775086594

Archived OP link: https://archive.is/KJTHN

◧◩
3. r721+U8[view] [source] [discussion] 2021-09-14 23:35:35
>>ryan29+L7
From Emma Best (DDoSecrets)'s tweets it looks like it's unavailable at the moment (6h ago):

>There don't seem to be any active seeds and just under 0.5% seems to be available ATM, so... we'll see what happens!

https://twitter.com/NatSecGeek/status/1437827363505573896

4. greyfa+19[view] [source] 2021-09-14 23:36:24
>>cbtacy+(OP)
Other discussion: https://news.ycombinator.com/item?id=28531447
6. banana+se[view] [source] 2021-09-15 00:14:06
>>cbtacy+(OP)
Looks like the seeder is gone, but they were online just barely briefly enough to get the torrent metadata.

For those that are curious what's in there:

https://gist.github.com/Q726kbXuN/57f3825493d04867c3d192fd93...

◧◩◪
13. 1vuio0+Dp[view] [source] [discussion] 2021-09-15 01:30:24
>>sieaba+xi
Thats because that page doesnt show the full list. Try this instead

https://gist.github.com/Q726kbXuN/57f3825493d04867c3d192fd93...

15. r721+Hq[view] [source] 2021-09-15 01:37:33
>>cbtacy+(OP)
Gizmodo story: https://gizmodo.com/anonymous-claims-to-have-stolen-huge-tro...
◧◩◪
16. desine+Gs[view] [source] [discussion] 2021-09-15 01:52:08
>>kadoba+np
If you truly believe in freedom of speech, it makes sense to support companies who enable those ideals. I'm not familiar enough with the company/drama/story here, but if Epik does not do anything "problematic" other than allow "problematic" speech, then I would consider them. A certain quote often mis-attributed to Voltaire comes to mind [0]. It appears they do have some lines drawn in the sand for free speech, they cancelled service for 8chan.

[0] : https://en.wikipedia.org/wiki/Evelyn_Beatrice_Hall

◧◩◪◨
21. burkam+ww[view] [source] [discussion] 2021-09-15 02:24:22
>>Syonyk+tv
Epik "ended its relationship" with The Daily Stormer because of content hosted on the site and the "entanglement" (meaning PR issues). If you're not ok with that, then I don't think Epik is what you're looking for. If you are ok with it, then you can accept service providers disassociating themselves with "distasteful" clients, it's just a matter of exactly how distasteful they have to be.

Source: https://www.npr.org/2021/02/08/965448572/meet-the-man-behind...

27. Lammy+Yz[view] [source] 2021-09-15 02:55:12
>>cbtacy+(OP)
>NOTORIOUS "HACKERS ON ESTRADIOL" PRESENT GRAND REVEAL

I love how this is a tongue-in-cheek reference to the "hackers on steroids" piece from 2007 https://www.youtube.com/watch?v=DNO6G4ApJQY

◧◩◪◨⬒
33. common+VA[view] [source] [discussion] 2021-09-15 03:02:53
>>nebula+HA
The screenshot from one of the replies to the tweet (https://twitter.com/pompompur_in/status/1437905607273635847) seems to be of qBittorrent. It's open source and cross-platform, just like Deluge.

https://www.qbittorrent.org/download.php

◧◩◪◨⬒⬓
34. nebula+uB[view] [source] [discussion] 2021-09-15 03:08:00
>>common+VA
Not available on my server unfortunately. Otherwise qBitorrent is the client of choice. I have found magnet links from DdosSecrets here: https://ddosecrets.com/wiki/Epik

Edit: Turns out I didn't give enough attention to Transmission as it handled the file. Very impressive.

As a side note: this has got me pondering about testing edge cases on open source software. Wonder how much of that actually gets done.

◧◩◪◨
46. Lammy+tF[view] [source] [discussion] 2021-09-15 03:48:11
>>Syonyk+tv
> Epik has, at least as far as I can tell, a reputation for simply hosting domain registrations, not asking questions, and ignoring just about every request for information.

Give https://www.nearlyfreespeech.net/services/domains a shot.

I'm not affiliated aside from being a happy customer for over a decade. You can read their abuse-handling terms here: https://www.nearlyfreespeech.net/help/abuse

47. Thorre+oG[view] [source] 2021-09-15 03:56:54
>>cbtacy+(OP)
Lest anyone be confused, this is Epik the web hosting company[1], not Epic Games the videogame company[2], or Epic Systems the healthcare software company[3].

[1] https://en.wikipedia.org/wiki/Epik_(company)

[2] https://en.wikipedia.org/wiki/Epic_Games

[3] https://en.wikipedia.org/wiki/Epic_Systems

◧◩◪◨
50. syysil+BI[view] [source] [discussion] 2021-09-15 04:17:53
>>Syonyk+tv
I've heard https://njal.la is pretty good.
◧◩◪◨⬒⬓⬔⧯
61. smt88+fN[view] [source] [discussion] 2021-09-15 05:17:29
>>shiftp+tL
Very few people reading your comment have high-value domains.

Also, every registrar sends you scary emails before and after a domain expires and enter the redemption period [1].

That means you failed to:

- register for 10 years in advance

- pay attention to your email for at least 60 days (including your redemption period)

- enable auto-pay

If you had done any one of those very normal measures for a high-value domain, you would have kept your domain.

1. https://www.icann.org/resources/pages/domain-name-renewal-ex...

◧◩
70. LewisV+UP[view] [source] [discussion] 2021-09-15 05:47:33
>>Thorre+oG
Nor is it Epic! the digital reading platform for kids[1], not EPIC the Electronic Privacy Information Center[2], or EPIC Provisions the company behind high protein meat snacks[3].

[1] https://www.getepic.com/

[2] https://epic.org/

[3] https://epicprovisions.com/

◧◩
76. schlec+DU[view] [source] [discussion] 2021-09-15 06:41:24
>>kgeist+zK
Not infrastructure related, but on monday the german anonymous collective managed to get a former IT admin of one of the largest covid conspiracy theorists to hand over his credentials, transferred all domains (he had ~ 10 aliases) and deleted his telegram channels

he still hasn't regained control -> https://www.attilahildmann.de/

82. mcinty+fX[view] [source] 2021-09-15 07:07:22
>>cbtacy+(OP)
Looks like they had access to their CDN at some point too: https://archive.is/traih
◧◩
87. southe+6Z[view] [source] [discussion] 2021-09-15 07:26:04
>>jungle+hX
Implementing security guidelines is not as easy as paying a security expert. You then have to follow their advice, which means security practice for all employees. It can be costly and cumbersome.

Of course, it would have reduced damaged, such as pointing out that unhashed or unsalted MD5 passwords in a database is... what we've stopped doing 20 years ago for good reasons? :)

But well, if you're a big hosting provider tailoring to white supremacist content, you usually don't need so much security, since apart from anonymous-adjacent antifascists pretty much everyone is licking your boots, including law enforcement. The biggest neonazi forums have been around for decades, and their biggest proponents are well hidden behind the walls of our police stations, banks and parliaments.

Love the reference to Woody Guthrie, too https://en.wikipedia.org/wiki/This_machine_kills_fascists

◧◩◪
90. southe+cZ[view] [source] [discussion] 2021-09-15 07:27:30
>>petert+RP
Today on HN: https://news.ycombinator.com/item?id=28532531

Microsoft bundling a super-insecure root daemon in all their Linux VMs. They developed it, published it on Github, embedded it everywhere, but when it turned out to be a security nightmare blamed "open source supply chain".

◧◩◪◨
95. ohashi+HZ[view] [source] [discussion] 2021-09-15 07:31:09
>>desine+Gs
I wouldn't support this borderline nutjob. Making employees watching a video of christchurch shooting and saying it was fake? Yeah, no. He has a lot of ties to extremist right wing too.

https://en.wikipedia.org/wiki/Rob_Monster#Views

◧◩◪
112. FDSGSG+P51[view] [source] [discussion] 2021-09-15 08:32:09
>>LewisV+UP
>[2] https://epic.org/

https://epic.org/privacy/surveillance/prg-scorecard/basis.ph...

Only two left to go?

◧◩◪
131. capabl+Cd1[view] [source] [discussion] 2021-09-15 09:50:50
>>qetern+b71
Could you share something damning instead of referring people to search, as we probably will find different information.

As far as I can tell, Epik focused on hosting and DNS management for marginalized/excluded groups on the internet, so naturally they attract a lot of groups. Not sure why that'd be bad though.

Things like this also makes me actually like the company more:

> Pharmaceutical watchdog website LegitScript reported in 2018 that they had alerted Epik to the sale of illegal drugs and counterfeit medications on websites registered by Epik, and that Epik had refused to act upon the information without a court order

That's exactly how I want my hosting company to act, and any that don't are actively fragile.

From https://en.wikipedia.org/wiki/Epik_(company)

◧◩◪
143. Hackbr+Qi1[view] [source] [discussion] 2021-09-15 10:40:42
>>LewisV+UP
Neither is it Epyx, Inc., the venerable videogame company [1].

[1]: https://en.wikipedia.org/wiki/Epyx

◧◩◪◨
147. leland+Ql1[view] [source] [discussion] 2021-09-15 11:17:04
>>capabl+Cd1
Remember when a guy murdered 11 people in a Pittsburgh synagogue? When it was revealed the shooter had posted about it on Gab beforehand, every service powering the social network pulled the plug. Epik was who brought them back online.[0]

The hero of hate speech is not exactly a sterling reputation to have.

[0] https://www.wired.com/story/how-right-wing-social-media-site...

174. ollybe+9I1[view] [source] 2021-09-15 13:54:06
>>cbtacy+(OP)
Not a great day for this HostBill to be announcing their new Epik integration.. https://twitter.com/hostbillappcom/status/143811349497348915...
175. vmoore+HI1[view] [source] 2021-09-15 13:57:07
>>cbtacy+(OP)
Are they currently writing up a blogpost about this? Their blog has nothing: https://www.epik.com/blog/

And this is a megadump of a hack.

But you can buy a .MONSTER TLD For $1.49: https://www.epik.com/promos/monster

◧◩◪
180. vmoore+7L1[view] [source] [discussion] 2021-09-15 14:09:19
>>schlec+PJ1
Looks registered to me, but seems like it's parked:

https://whois.domaintools.com/rob.monster

    Domain Name: ROB.MONSTER
    Registry Domain ID: D98633729-CNIC
    Registrar WHOIS Server: whois.psi-usa.info
    Registrar URL: https://www.internetx.com/
    Updated Date: 2021-06-05T01:19:43.0Z
    Creation Date: 2019-04-01T14:00:01.0Z
    Registry Expiry Date: 2022-04-01T23:59:59.0Z
    Registrar: InternetX GmbH    
    Registrar IANA ID: 151
    Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
    Registrant Organization:
    Registrant State/Province: nrw
    Registrant Country: DE
    Registrant Email: Please query the RDDS service of the Registrar of Record identified in this 
    output for information on how to contact the Registrant, Admin, or Tech contact of the queried 
    domain name.
    Admin Email: Please query the RDDS service of the Registrar of Record identified in this 
    output for information on how to contact the Registrant, Admin, or Tech contact of the queried 
    domain name.
    Tech Email: Please query the RDDS service of the Registrar of Record identified in this output 
    for information on how to contact the Registrant, Admin, or Tech contact of the queried domain 
    name.
    Name Server: NS1.WESELLTHISDOMAIN.COM
    Name Server: NS2.WESELLTHISDOMAIN.COM
    Name Server: NS3.WESELLTHISDOMAIN.COM
    DNSSEC: unsigned
    Billing Email: Please query the RDDS service of the Registrar of Record identified in this 
    output for information on how to contact the Registrant, Admin, or Tech contact of the queried 
    domain name.
    Registrar Abuse Contact Email: 
    Registrar Abuse Contact Phone:
    URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
◧◩◪◨⬒⬓⬔⧯▣▦
200. burkam+aX2[view] [source] [discussion] 2021-09-15 20:16:21
>>shiftp+q22
To add some circumstantial evidence, Namecheap currently has 52 job openings, of which 47 are in Ukraine, 1 each are in Portugal and India, and 3 are remote: https://www.namecheap.com/careers/openings/
◧◩◪◨⬒
204. gambas+zm3[view] [source] [discussion] 2021-09-15 22:47:42
>>Lammy+tF
Actually they revealed a few months ago that if you aren't politically aligned with them at nearlyfreespeech.net, they treat you differently as a customer.

https://blog.nearlyfreespeech.net/2021/01/19/free-speech-in-...

They will "*not* lift one finger to help you [host your site here]" (emphasis theirs)

If you are not politically to their taste, they will look for a reason to kick you off as opposed to their other customers, "we *will* kick you off the instant you give us a reason".

In that same post, they revealed they will cooperate with police requests without any court documents or warrants being provided, putting them in the 'fragile' class of hosting providers.

◧◩◪◨⬒
214. chroem+W34[view] [source] [discussion] 2021-09-16 04:38:49
>>crocod+ST3
https://www.seattletimes.com/seattle-news/crime/man-shot-in-...
◧◩
215. genr8+p44[view] [source] [discussion] 2021-09-16 04:44:20
>>genr8+n81
I can't believe [What do they have to hide?] was even seriously spoken here. Im not the only one who believes this glows exactly like a state-sanctioned hitjob. This was cyber-warfare. https://www.youtube.com/watch?v=f5a42XuzPLk An average fair video on the hack - but Read the comments.

Anonymous is not bashing the fash, they now do the bidding of the far-left Establishment, enforce state-approved Censorship and Cancel Culture of any dissidents against the monoculture cathedral regime - who now just are your average regular independents, libertarians, and freedom loving populists.

Anyone who still falls for "but they're nazis and fascism is bad mmk" is either dishonest or not following this subject matter. Just because you don't like someone doesnt mean they're nazis.

I doubt this is even Anonymous. The real Anonymous would not be hacking companies providing free speech (no matter how bad the security).

◧◩◪◨⬒⬓⬔
222. pure_s+fV4[view] [source] [discussion] 2021-09-16 13:19:49
>>qetern+D73
> I doubt that there are many (any?) Epik customers who I would consider good people (there’s simply no logical reason to host with them otherwise)

This is an incredibly shortsighted / insular perspective. We live in a world where conservative orthodox Jews (e.g. Ben Shapiro) are called Nazi's and conservative Black folks (Larry Elder) are being called white supremacists, simply for being conservative. Likewise, progressives and other left leaning individuals that dare utter criticism of the left are met with the milder insult of being called conservative (e.g. Tim Pool, Glenn Greenwald, Bill Maher). People are deliberately shifting the overton window to a ridiculous degree and the scary thing is that they are getting away with it.

I can imagine a lot of regular conservatives worry about censorship and may find Epik to be a safer bet than, say, Google who blocks pro-life ads [1]. I can understand that maybe from your perspective (assuming you're left leaning) you are not aware of how hostile society has become to mainstream conservatism, but you should try to see things from the perspective of a regular conservative who sees prominent mainstream conservatives being slandered, lied about, and cancelled all around them.

Aside from that, Epik did have a few differentiating features like offering single purchase lifetime Domain ownership that I haven't seen elsewhere, which by itself could be sufficient motivation for people to host with them, without the necessarily knowing anything about potential controversy surrounding the business.

[1] https://www.nationalreview.com/corner/google-blocks-ad-for-s...

[go to top]