🌐 Website Issue | That One Privacy Site Compromised? #975

Closed
opened 2019-06-05 14:22:32 +00:00 by jingofett · 9 comments
jingofett commented 2019-06-05 14:22:32 +00:00 (Migrated from github.com)

Description

It seems that the "Simple VPN Comparison" has been compromised. There are a ton of VPN services now with green across the board, that I've never heard of. Such as "Fastestvpn" and "MinecraftVPN". F-secure and Norton are also green across the board.

Screenshots

image
image
image
image

## Description It seems that the "Simple VPN Comparison" has been compromised. There are a ton of VPN services now with green across the board, that I've never heard of. Such as "Fastestvpn" and "MinecraftVPN". F-secure and Norton are also green across the board. ## Screenshots ![image](https://user-images.githubusercontent.com/8313249/58963554-eea5c500-879c-11e9-9ad6-6c2434715cb6.png) ![image](https://user-images.githubusercontent.com/8313249/58963677-21e85400-879d-11e9-9cbf-e25caeb62ac5.png) ![image](https://user-images.githubusercontent.com/8313249/58963781-4ba17b00-879d-11e9-854b-9621dcdd46f5.png) ![image](https://user-images.githubusercontent.com/8313249/58963813-59570080-879d-11e9-97b8-80ebab8ca07b.png)
danarel commented 2019-06-05 21:26:07 +00:00 (Migrated from github.com)

That does appear to be the case. unless it's a coding error with something he's working on and it shouldn't be live yet. But I would say he's been compromised from the looks of it.

That does appear to be the case. unless it's a coding error with something he's working on and it shouldn't be live yet. But I would say he's been compromised from the looks of it.

I reached out to him via email about this issue, and I'll give him some time to respond.

I reached out to him via email about this issue, and I'll give him some time to respond.
ghost commented 2019-06-20 18:55:58 +00:00 (Migrated from github.com)

15 days after making this issue, the comparison still has sketchy entries. I suggest we consider removing the link to his site on our VPN information section.

If he is merely AFK and comes back to fix it, we can re-add.

15 days after making this issue, the comparison still has sketchy entries. I suggest we consider removing the link to his site on our VPN information section. If he is merely AFK and comes back to fix it, we can re-add.
danarel commented 2019-06-20 18:57:58 +00:00 (Migrated from github.com)

Yeah, and he's been MIA on Twitter since May 1. I hope he's okay, but his site is certainly compromised at this point.

Yeah, and he's been MIA on Twitter since May 1. I hope he's okay, but his site is certainly compromised at this point.
ghost commented 2019-06-20 20:04:39 +00:00 (Migrated from github.com)

I ran a vuln scan on the site, it appears the plugin version used to manage the data tables has an SQL injection vulnerability, and unauthenticated shell upload. So yeah the site is definitely fully compromised.

I ran a vuln scan on the site, it appears the plugin version used to manage the data tables has an SQL injection vulnerability, and unauthenticated shell upload. So yeah the site is definitely fully compromised.
ghost commented 2019-06-20 20:07:34 +00:00 (Migrated from github.com)

https://gist.github.com/beardog108/49063994ec0ae71c1c83d5c6f875599a

Normally i wouldn't publish something like that publicly without warning, but since we have attempted to contact him and its a trivial publicly known exploit caught by a scanner I think its fine...

https://gist.github.com/beardog108/49063994ec0ae71c1c83d5c6f875599a Normally i wouldn't publish something like that publicly without warning, but since we have attempted to contact him and its a trivial publicly known exploit caught by a scanner I think its fine...
ghost commented 2019-06-20 20:17:30 +00:00 (Migrated from github.com)
https://www.reddit.com/r/privacy/comments/c30ycv/that_one_privacy_site_compromised_june_2019/
ghost commented 2019-06-21 23:40:11 +00:00 (Migrated from github.com)

He responded on reddit, we can close this issue now as the site is fine and will be fixed:

https://www.reddit.com/r/privacy/comments/c30ycv/that_one_privacy_site_compromised_june_2019/erqbcq9

He responded on reddit, we can close this issue now as the site is fine and will be fixed: https://www.reddit.com/r/privacy/comments/c30ycv/that_one_privacy_site_compromised_june_2019/erqbcq9

maybe PM them next time

Maybe respond to your emails next time 😝

Looks good to me.

> maybe PM them next time Maybe respond to your emails next time 😝 Looks good to me.
This repo is archived. You cannot comment on issues.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#975
No description provided.