Renewbuy.com
by Sanggiero - Thursday June 15, 2023 at 11:25 AM
#11
(Jun 22, 2023, 12:59 PM)general0x00 Wrote: thanks you for sharing it.

You're welcome. Cool

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Suspected to be involved with Law Enforcement.
Reply
#12
(Jun 17, 2023, 02:41 PM)Sanggiero Wrote:
(Jun 17, 2023, 01:44 PM)RavishKumarOfficial Wrote:
(Jun 15, 2023, 11:25 AM)Sanggiero Wrote: Format - JSON
Size RAR file - 285MB
Date - 2023
All Rows - 890412
Website - renewbuy.com

An example with only one username, imagine with 1M. Cool

Did you leak this? If yes, did you manage to download the S3 linked files too?

Unfortunately, I didn't bother to install the images from S3, there was a large amount of data. These are the kind of developers that generate signatureless JWT tokens, you know?
After a few months of attack I went back just now to see if the vulnerability is still present, turns out yes, they left publicly the AWS credentials allowing access to S3 and SQS in the API no authentication required.  Cool
The lesson I learned, never trust Indian infrastructure, they are usually not protected at all.

https://i.postimg.cc/QN6CbPp6/Screenshot-6.png

Very interesting. Could you share a bit more about the vulnerability? Was this info present in the jwt?
Reply
#13
(Jun 22, 2023, 04:38 PM)cateye84 Wrote:
(Jun 17, 2023, 02:41 PM)Sanggiero Wrote:
(Jun 17, 2023, 01:44 PM)RavishKumarOfficial Wrote:
(Jun 15, 2023, 11:25 AM)Sanggiero Wrote: Format - JSON
Size RAR file - 285MB
Date - 2023
All Rows - 890412
Website - renewbuy.com

An example with only one username, imagine with 1M. Cool

Did you leak this? If yes, did you manage to download the S3 linked files too?

Unfortunately, I didn't bother to install the images from S3, there was a large amount of data. These are the kind of developers that generate signatureless JWT tokens, you know?
After a few months of attack I went back just now to see if the vulnerability is still present, turns out yes, they left publicly the AWS credentials allowing access to S3 and SQS in the API no authentication required.  Cool
The lesson I learned, never trust Indian infrastructure, they are usually not protected at all.

https://i.postimg.cc/QN6CbPp6/Screenshot-6.png

Very interesting. Could you share a bit more about the vulnerability? Was this info present in the jwt?

I explained it above, the JWT token had no signature which allowed me to do an account takeover and access any account without authorization and steal information. Since when do developers forget to put a JWT signature, it's essential, you only have Indians to do this kind of bullshit. Dodgy
I found about 20 vulnerabilities in a few days in the company, finding IDORs, SSRFs, misconfigurations and so on. Most of the vulnerabilities in criticality ranged from P3 to P1 (so that's pretty serious).

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Suspected to be involved with Law Enforcement.
Reply
#14
nice one! good

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Suspected Scamming | Contact us via http://breachedmw4otc2lhx7nqe4wyxfhpvy32ooz26opvqkmmrbg73c7ooad.onion/contact if you feel this is incorrect.
Reply
#15
Can you please upload it to another server? Anonfiles is down
Reply
#16
Can you put on another site while anonfiles is down? I appreciate it!
Reply
#17
thanks you so much!
Reply
#18
The link in this thread is dead. Please reply to the PM you were sent to get your thread moved back to the Databases section.
Telegram: @d6413e5c
[Image: al-Py701-X-2718763177.png]
Reply
#19
Hello,

The link on this thread has been updated as of this post.
Telegram: @d6413e5c
[Image: al-Py701-X-2718763177.png]
Reply
#20
Good!!~~I want it!!~~~
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Coriolis Scrape - Leaked, Download! near 33 1,161 4 hours ago
Last Post: pentester062
  Zéphir Database - Leaked, Download! aaa 6 650 4 hours ago
Last Post: pentester062
  AUTOSUR Database - Leaked, Download! placenta 52 3,986 4 hours ago
Last Post: pentester062
  FBI+DHS Database - Leaked, Download! Automation 56 15,684 4 hours ago
Last Post: spoiledbrat
  BitMart Database - Leaked, Download! Sythe 17 1,225 5 hours ago
Last Post: M0N3YH4CK3R

Forum Jump:


 Users browsing this forum: 1 Guest(s)