Welcome!

Join our community of MMO enthusiasts and game developers! By registering, you'll gain access to discussions on the latest developments in MMO server files and collaborate with like-minded individuals. Join us today and unlock the potential of MMO server development!

Join Today!

Myself and BitTorrent (Source/DNS and a reward)

Joined
Nov 14, 2001
Messages
29,441
Reaction score
21,661
Update (02/08/13)
I can now confirm that I have received $500 (actually less when you take into consideration local exchange rates) from BitTorrent as a thank you for saving them millions a year and by not leaking / releasing or sharing the source code, financial documents , introductory salary offers and more (including a lot of embarrassing material stored on their servers that would get them into a lot of trouble). Having reviewed all the press postings, user comments and more I think its the general consensus that a find of this magnitude is worth more than $500 and I should just be grateful to get anything at all.


(Original post is below).


I kept this private for a long time but a few months ago I managed to accidentally stumble upon a system that contained some crucial and private information and having reviewed what it was ... it turns out it was access to the network of the company "BitTorrent" including sources codes / builds and private unreleased goodies too, such as financial documents and more.

I checked further to see what was at hand and was surprised to find I was able to push public builds on all data such as utorrent and more. I had master keys to everything, including DNS level material. Once I sat down, reviewed what was on my screen I concluded it was in the best interest to notify the company immediately.

Once notified they said thank you and wanted to give me a reward (Cheque) to which I gladly accepted but to this day nothing has been sent/received on my part. I emailed them further and was given some rather rude replies and was told that I would need to 'invoice' them in order to get my reward. To me, this seems absurd. A hacker recently found a bug in which he was able to reset passwords and got £20,000 reward, me? I got the entire source of ALL products / webpages / DNS / Fincial documents and more and in the end they offered me $500, I felt insulted.

So, this is where I am at. I felt I wanted to share and express my annoyance regarding the matter. They make millions a year in ad revenue alone and I never released, tweaked, sent fake builds or nothing out to any user and I feel insulted. Below, I've attached some screenshots authenticating all I've said above.

3wRUm3Sh - Myself and BitTorrent (Source/DNS and a reward) - RaGEZONE Forums


VZNLBphh - Myself and BitTorrent (Source/DNS and a reward) - RaGEZONE Forums


HgobghDh - Myself and BitTorrent (Source/DNS and a reward) - RaGEZONE Forums



NtsU0Qeh - Myself and BitTorrent (Source/DNS and a reward) - RaGEZONE Forums


kKksd17h - Myself and BitTorrent (Source/DNS and a reward) - RaGEZONE Forums



aCsATMUh - Myself and BitTorrent (Source/DNS and a reward) - RaGEZONE Forums



u4jR9H3h - Myself and BitTorrent (Source/DNS and a reward) - RaGEZONE Forums



bRa0eYRh - Myself and BitTorrent (Source/DNS and a reward) - RaGEZONE Forums



Note: no data is physically located on any of my workstations / servers or anything related. I kept screenshots of the data for myself as verification and web page saved dumps only, so... sorry guys, nothing can be released, will be released or anything at all because I no longer have it.
 

Attachments

You must be registered for see attachments list
Custom Title Activated
Loyal Member
Joined
Mar 26, 2009
Messages
1,778
Reaction score
1,209
Well they're lucky that you didn't release this to the public, yet they only give you 500$? cunts.
 
Ask me about Daoism
Loyal Member
Joined
Nov 6, 2010
Messages
1,560
Reaction score
393
Pretty sweet.

How could a company put all of that stuff up at GitHub? Do companies do that? If so, I need to go through a few records.

Second, mind giving us backstory into how you found it? What were you doing? What were you surfing? What other tabs did you have open at the time? What kind of porn did you watch during or afterwards? We must know.
 
Junior Spellweaver
Joined
Aug 24, 2007
Messages
106
Reaction score
7
Wow, you had them by their balls. Not sure how you 'accidentally stumbled upon' the heart of their business but if you've already disclosed this to the company, you should totally release the details about your stumble.

And the fact that they're not going to reward you for your admirable actions, that's pathetic of them. Kudos to you, MentaL.
 
Divine Celestial
Joined
Aug 29, 2011
Messages
857
Reaction score
453
You should have copied this files and saved them somewhere and if they pay you delete it and if they don't release it. Win Win
 
Everything is possible~
Loyal Member
Joined
Jan 9, 2008
Messages
818
Reaction score
847
GG on that, MentaL. You should've been part of the Hackers Conference here in Holland.
 
Joined
Nov 14, 2001
Messages
29,441
Reaction score
21,661
You should have copied this files and saved them somewhere and if they pay you delete it and if they don't release it. Win Win

Why would I do that? That's extortion and I'm not an idiot. It's people like you with an attitude like that which gives people bad names.

Wow, you had them by their balls. Not sure how you 'accidentally stumbled upon' the heart of their business but if you've already disclosed this to the company, you should totally release the details about your stumble.

And the fact that they're not going to reward you for your admirable actions, that's pathetic of them. Kudos to you, MentaL.

This was never intended to go public as they said I would get a reward and obviously I told them about my daughter being due in a few months (Who was born on Thursday) the funds would go towards her. Now, fast forward a few months, still nothing. Although they did ask me to invoice them again but I still dont understand that part.
 
Divine Celestial
Joined
Aug 29, 2011
Messages
857
Reaction score
453
Why would I do that? That's extortion and I'm not an idiot. It's people like you with an attitude like that which gives people bad names.



This was never intended to go public as they said I would get a reward and obviously I told them about my daughter being due in a few months (Who was born on Thursday) the funds would go towards her. Now, fast forward a few months, still nothing. Although they did ask me to invoice them again but I still dont understand that part.

It is very fair honestly. If you keep thinking like this people will always fool you Mental all your life.
 
Joined
Nov 14, 2001
Messages
29,441
Reaction score
21,661
Pretty sweet.

How could a company put all of that stuff up at GitHub? Do companies do that? If so, I need to go through a few records.

Second, mind giving us backstory into how you found it? What were you doing? What were you surfing? What other tabs did you have open at the time? What kind of porn did you watch during or afterwards? We must know.

A friend was looking for a hosting provider and wanted it all secure, I checked a network range and found the Jenkins panel of BitTorrent. This was all 100% accidental, truth! At the end of the day If I wanted to 'hack' BitTorrent I wouldn't even know where to begin. I mean, there is no real skill or talent involved in what I did to find the information on BitTorrent. They forgot to set a user/pass to the admin panel, that had access to github from a master account. Github accounts had user/passes that was linked to everything.

No hacking, just random find. Mad huh?

PS:

If anyone can share this I would appreciate it.
 
Newbie Spellweaver
Joined
Sep 3, 2012
Messages
30
Reaction score
7
This was never intended to go public as they said I would get a reward and obviously I told them about my daughter being due in a few months (Who was born on Thursday) the funds would go towards her. Now, fast forward a few months, still nothing. Although they did ask me to invoice them again but I still dont understand that part.

I'm not sure if this is what they mean by 'invoice' But, I think your best bet would be to try and send them an invoice through PayPal. Here's a link to it Just get there PayPal email and do that.
 
Junior Spellweaver
Joined
Aug 24, 2007
Messages
106
Reaction score
7
This was never intended to go public as they said I would get a reward and obviously I told them about my daughter being due in a few months (Who was born on Thursday) the funds would go towards her. Now, fast forward a few months, still nothing. Although they did ask me to invoice them again but I still dont understand that part.

Wow, that's even worse. You opened up a piece of your life to them and told them what you wanted to use the reward for and by their actions, they completely blew you off. With the apparent disregard for security (forgetting to set a user/pass for an admin panel? Really now? I'm sorry but that's just sad. Just with that detail alone, their reputation is ruined in my mind) and the power you possessed over their company, you could have done much damage (i.e. pushing malicious code with public builds, etc) but you chose not to. They should have taken your actions a little more seriously. I hope this PR blows up in their face.

I don't understand the invoicing part neither. Are they too lazy to send the cheque to you themselves like they we're to setup a user/pass for a critical panel of their business? It appears so. Did you ever send them the invoice?
 
Joined
Nov 14, 2001
Messages
29,441
Reaction score
21,661
Wow, that's even worse. You opened up a piece of your life to them and told them what you wanted to use the reward for and by their actions, they completely blew you off. With the apparent disregard for security (forgetting to set a user/pass for an admin panel? Really now? I'm sorry but that's just sad. Just with that detail alone, their reputation is ruined in my mind) and the power you possessed over their company, you could have done much damage (i.e. pushing malicious code with public builds, etc) but you chose not to. They should have taken your actions a little more seriously. I hope this PR blows up in their face.

I don't understand the invoicing part neither. Are they too lazy to send the cheque to you themselves like they we're to setup a user/pass for a critical panel of their business? It appears so. Did you ever send them the invoice?

I'm not sending any sort of invoice until they tell me exactly why an invoice is required on my part?

# Update

Invoice is required for accounting as they will not release any funds until an invoice has been sent. I'm unsure how to approach this.
 
Back
Top