..--------------------------------------..
..    MAny-m4ny  lamahz on RU scene     ..
..______________________________________..


                                          dorks. they looks like a dorks
                                                        (C) pulp fiction


   We  wanna  do it in 5 issue, but we left this information  for internal
   usage cuz social engenering so cewl with thiz trash. Well, now its time
   to show it. No more secretz, no fake. jmp 00w00w


00w00w (aka m00) <0x00>: 
------------------------

   fag0tz,   security   sexpertz,   pseudo   blackhatz   and coauthorz  of
   defaced6.txt.   You   can   read   their   w0rk   on   russian   here:
   http://defaced666.narod.ru.  Sorry  m00,  you  wrong  with dstaff  list
   (you knew it). Now we'r hit you back.

   supa-m00  (er337  m4d  c0ws  attacks!) membaz: d4rkg4y, 0verg, rashray,
   dr.Ganjubas, h0snp, akul4


########################

Nick:         D4rkgr3y (aka d4rkg4y aka duffy d4rk)
Real name:    Sergey Doronin
Address:      Russia, Klin, Mendeleeva st. 2
Achievements: lame ops on #el8, #c/c++ :
 
02:08:10 ---	[d4rkgr3y] (~death@blackhat.ru) : m00
02:08:10 ---	[d4rkgr3y] @#el8 @#c/c++ #dumped 
02:08:10 ---	[d4rkgr3y] efnet.demon.co.uk :Be excellent to each other.

   Lame  knowledges of C (only with fuckin tutorialz),  many contactz (cuz
   gay) and etc. No one personal *good* sploit:  only with ``some c3w1 man
   form Uhagr'' or from ``priv8 security''. Main achievements:

   - HL exploitz (70% of code and idea by Uhagr)
   - ShoutCast explz ( 80% of code by priv8 sec )
   - 2 interviewz to "XAKEP" (hacker) pop paper magazine (none disclosure,
     ya?)   
   - friendship  with  0x333  aka  Outsiders  Security  Labs (dunno, maybe
     l000sers suicide club?)
   - contacts with russian gays from securitylab.ru (Positive Tech. corp)
    
   Recommendations: kick'em from #el8 asap !!
    


########################

Nick:         drG4njubas
Real name:    Saveliy Tretyakov
Address:      Russia, Moscow, Novosibirskaya st. 8-254
Phone:        +7 095 4696523
Achievements: he thinkz he's best win-x86 asm coder ))

   - interview to "XAKEP" magazine

   Recommendations: call  him  and  tell what ure from FSB, now write nice
   prank ))

je nerf    


########################

   Their famous 1337 w4hrezz:

  m00-apache-w00t.tar.gz        - omfg, i can't got w00t with it )) U need
                                  this trash?

  m00-mod_gzip.c                - the REALLY G00D ware, but it's not their
                                  code, huh. Need repeat ;)

  Some nice posts about it:

From: Jordan T. 
Subject: [exploits] [Fwd: m00-mod_gzip.c] 
Date: 22 Nov 2003 20:31:35 -0000 

> Exploit for mod_gzip in apache, binds remote root shell to a user
> specifiable shell (default port 2003)
>
> Has return address for mdk 9.1, compiles OK but i dont have any mod_gzip
> webservers to test it on, i believe its been patched already (can anyone
> confirm?). Time to upgrade if you havn't already done so.
>
> Jordan.


From: Hicham A. 
Subject: Re: [exploits] [Fwd: m00-mod_gzip.c] 
Date: 25 Nov 2003 16:50:38 -0000 

> Don't compile and run this "exploit".
> I think Jordan T. is reinstalling his machine now ;/

  ^^^^^^^ It's boobys from Mandrake-Linux Security Team ;))


  m00-dskinf.c                  - 0verg masturbating on r00t-promt  in his
                                  freebsd, but can't got w00t. Need +s!

  m00-shoutcast-sex.c           - Lets look at banner:

/*
 *  Pretty lame universal SHOUTcast <=1.9.2 local exploit
 *    for Linux/x86 and FreeBSD
 *
 *  Non-disclosure bof ;D Quickly post it to bugtraq!!!
 *

  Haha, u knew why he doesn't post it to bugfuck? Let's look below:

<* skipped *>
	   execl("./sc_serv","b0f",buffer,NULL);
}

   Ohhnly shit!! Got root is easy... if root setuid bit seted.  If they'll
   post it to bq,  it'll  means what they are  stupid assholez,  cuz  only
   mega-lame ppl sets suid bit on shoutcast.



nerf <0x01af>:
--------------

   Another  one lame "security team". It`s not interesting.  Some of their
   cewl achievements:

   - lkm what hidez filez from tripwire (code very huge and ugly)
   - textz for newbiez (CEWL... if its your first day in da internet ))

   Membaz: v1pee, r00teX,  D0minator, grange, tANDm,  b1lli_k1d (??), btr,
   haxie.


Nick:            v1pee
Real name:       Maxim Shumaev
Address:         Russia, Moscow. Detect phone via ATS base
Phone:           +7 095 6883422
Achievements:

   - some stupid advisories'n'exlpz (ifenslave == /dev/zerouid ?)
   - sexy-scanners kit: cgi,port,filefinder,cgi_from_list
   - ereet bindshell backd00r 4 *BSD

Recommendations: hot sex  via phone for free!!! all callz form any country
                 of the world got reverse charge!!


########################

   Their famous 1337 w4hrezz:

  hlfsd-xp.c                    -  r00terX  is  another  one  masturbating
                                   monkey, who wanna overflow  SOME FUCKIN
                                   prog 2 gain r00t access in FreeBSD, but
                                   dunno which. Arghh.. again neeed +s.

  websxpl.pl                    -  w00w!! Hey,  l00k!!  Its  leet  xpl for
                                   WebBBS 5.0... damn, u re UNIX GOD man..

  spoof.c                       -  wtf, ip-spoofin demonstration prog?


jnz DHG




DHG (aka Damage Hack Group) <0x070c>:
-------------------------------------

   And  another  one  it-sex  team (clones  attack? nope  - clownz) Nothin
   interesting, as  a  previous  groups of  loosers, they are  also "proud
   supportaz" of project mayhem and none-disclosure + WebMon(k)ey accepted
   on their pursez.

   (brain) Damaged Hippinin' Gayz Membaz:  DethSpirit,  j0k3r,  /dev/null,
   ChoiX.


Nick:            DethSpirit
Real name:       Vitaliy Kebin
Address:         Russia, Moscow, 40 9 Energeticheskaia st.
Phone:           +7 095 3620332
Achievements:  uh.. well, dunno =)
Recommendations: hmm... maybe fuckup DHG project?


########################

   Their famous 1337 w4hrezz:

  bdnb.c                        - stupid backdoor, without password (choix
                                  forgot write check_pass() func.. huh)




ANOTHER STUPID/LAME/GAY PROJECTZ:
---------------------------------

   www.securitylab.ru /* it-sex portal of ru  corp  Positive  Tech,  where
                      works(?)   duffy    d4rk.    Anyway,    his     mail
                      d4rk@securitylab.ru tells to us something. */

   security.nnov.ru   /* 3APA3A's  lame  site.  1.000.000   script  kidd0z
                      visitorz  per  day!!  give  them  0hd4y  w4r3zzz and
                      they'll crack the planet */

   ust.icqinfo.ru     /* UST  -  UKR  security team. m0f0z, wh0 wanna make
                      money on stupid consultations.xbip had wrote article
                      to x25zine #4, but looks like its a big mistake */

   void.ru            /* Another one script kiddoz favorite site.H3re l0tz
                      of young  clownz register their "1337-defacez".  ESP
                      shouts 2  whitehat krok (we h0pe you die, need  pipe
                      bomb!!) */

   xakep.ru           /* site  of  lame russian   paper  magazine   called
                      "hacker" about script kidding,  interviewz with fake
                      "blackhatz"  like  m00 (uh, mouthw0rk?), cogitations
                      about  scene  future,  etc. Edited  by  the bunch of
                      l00sers, wh0z calls themself X-crew. */

   npoison.ru         /* Oh, its  now a well-known phorum of ex  NetPoison
                      hacka team.  here you can find lotz of shit,  MBz of
                      stupid flame about everything on scene,including our
                      zine and more.  Do u wanna it?  NO? we too.

                      Hey, UPDATEZ! Project is dead! Sayonara ch00r!   */

   nerf.ru            // Crappy gayhats, wh0z selled themself.

   www.bugtraq.ru     // no commentz

   lbyte.void.ru      // white/gay hat team

   blackhat.ru        /* domain was registered by duffy d4rk and now m00'n
                      nerf use it to chatting in irc like this: "u suckeR,
                      l00k@ ma 3r337-host!!" */

e0f?
