00:00
00:00
Wurfel-Waffles
Just a super geeky guy who composes music in spare times.

Age 41, Male

Software Developer

TUM

Canada

Joined on 2/9/12

Level:
2
Exp Points:
20 / 50
Exp Rank:
> 100,000
Vote Power:
1.98 votes
Audio Scouts
2
Rank:
Civilian
Global Rank:
> 100,000
Blams:
0
Saves:
1
B/P Bonus:
0%
Whistle:
Normal
Medals:
22
Supporter:
11m 29d

Comments

How the fuck did you get my scripts...? Nevermind.

Good tutors but not enough. You cannot depend on G-Dork all the time. It's inaccurate.

Google dork, duh!

I'm a boss when come to doxing.

You dumped it on Cryptome. I remember once you talked about you wrote a script that cover wide range of SQL attacks but unwilling to share it. You even challenged Don and cr22ck to find it.

So here we go. ;)

What are you up to currently? Why is the serverâEUTMs bandwidth so high? I can't upload anything.

Stress test at this moment?

Sorry...

Netsparker is running. I gotta scan and confirm something. If I success, we are going to have a Skype's conference party tomorrow right away!

http://www.madrid11.com/en

Check this out and you'll know more why I do this: http://www.imperva.com/download.a sp?id=312

Also, I don't know what kind of SQL scanner did Anon used, I found at least 5 medium SQL bugs. I'm confirming them.

You're gonna laugh your ass out when I'm done.

Wow you are fucking quick responser. Greasemonkey?

Are you giving my tools to the enemy? I'm gonna fucking kill you when I discover Anon and 4chan cunts use my scripts.

Yeah. Greasemonkey.

Nope! But it's about time when they find out. Lol.

Injecting now. I think Anon really fucked up in some way. They are probably a bunch of dumbfuck wits and script thieves. I think Imperva was right about them.

My FTP server is on now. You are free to up stuff.

Still slow as hell, but it's going.

Accessed to database! Don't fucking trust Netsparker, that piece of shit is killing my laptop. Try <a href="http://www.madrid11.com/?id=43">http://www.madrid11.com/?id=43</a> and id=56

Yeah, and you can use my/our scripts too.

Anyway, they use honeypot, apparently IPS filtered. Traced back to East Vatican. Cloud computing. Can't believe cross huggers actually have access to cloud servers. Fuck the Pope.

So now you know where the money flows to from the Italy gov!

Also proxy your tracks. There are some active detectors and honeypots.

Eh? I didn't detect any pot at all. Quite heavily firewalled. I used stealth scans for Nmap.

Am I the only hacker that find path traversal is getting more and more scarier? You request with item=../../../../ and get access to the IIS servers.

So item=%5/%5/5%/5%/5%/winnt/system3 2/cmd.exe and u get a fucking access to server.

item=%5/%5/5%/5%/5%/winnt/system3 2/cmd.exe?/c+dir+c:\ now you access to C directory, equivalent of root.

item=%5/%5/5%/5%/5%/winnt/system3 2/cmd.exe?/c+powershell?/c+rm%2-r %2c:\

Rooted!!!

You see my point? Fuck the SQL, you spend hours to inject one line of code.

Alright I gonna post these goddamn bugs to PacketStorm before some asshole discover our conversations. I'm adding them to Offensive Sec server too.

I like path traversal. Unfortunately it can only perform on limited access. Never try on image files but I assume it works too.

Good game, bro. Cheer.

About DEFCON, are you gonna be there? I'm gonna have a booth. Guess what? GPU hack and demoscene!

Cool! I love it! Yeah I'm getting ticket too.

:o Do you know that people actually download the latest track?

Did you compress it?

Heh, I thought no one gave a shit about it. Well it's 196 kbps. The original 256 is 35 MB!