Operation Epik Fail: Host of Parler, 8kun, Gab, etc. supposedly hacked. - Accusations of pedophillia, SQL dumps, and everything else you could want from an anonymous info dump!

They should've used 1776 Hosting, what can I say?

A web hosting service is totally different from a domain registrar. Also, Josh said on the MATI stream that he might have to cut off 1776 Hosting from the public due to network attacks and the difficulty they create for maintaining steady service.
 
Did this turn out to actually be anything? I tried downloading it but the torrent moves slow as shit and would take months. The files that downloaded before I gave up seemed to be a dump of the epik.com public website which is absolutely nothing interesting. The website for the leak seems to be offline.

I wouldn't be hugely surprised if this was not really legit but rather an attempt to hurt Epik's credibility, or even just scam some crypto donations from cancel-hungry Twitter leftists.
 
I got this email:

At Epik, we take security and the privacy of your information very seriously. Therefore as a precautionary measure, I am writing to inform you of an alleged security incident involving Epik.

Our internal team, working with external experts, have been working diligently to address the situation. We are taking proactive steps to resolve the issue. We will update you on our progress. In the meantime please let us know if you detect any unusual account activity. I am proud of our team’s efforts as we do our part to empower a thriving internet for the benefit of our customers around the world.

You are in our prayers today. We are grateful for your support and prayer. When situations arise where individuals might not have honorable intentions, I pray for them. I believe that what the enemy intends for evil, God invariably transforms into good.

Blessings to you all.

Regards,

Rob Monster
Founder and CEO
Epik Holdings Inc
 
Did this turn out to actually be anything? I tried downloading it but the torrent moves slow as shit and would take months. The files that downloaded before I gave up seemed to be a dump of the epik.com public website which is absolutely nothing interesting.
I managed to snatch a copy of the files, it looks like a few 10+gb (uncompressed lol) SQL dumps and a whole shitload of WordPress installations that just take up useless space. I'll zip the SQL files and put them on Mega once I get home for those interested.
 
Did this turn out to actually be anything? I tried downloading it but the torrent moves slow as shit and would take months. The files that downloaded before I gave up seemed to be a dump of the epik.com public website which is absolutely nothing interesting. The website for the leak seems to be offline.

I wouldn't be hugely surprised if this was not really legit but rather an attempt to hurt Epik's credibility, or even just scam some crypto donations from cancel-hungry Twitter leftists.
DDoS Secrets has a torrent file, they kinda seem sketch (tranny black hacker wiki???? what???) but the torrent file there does work, just leave it overnight or wait until someone else uploads it to another filehosting if you're suspicious.
Kinda feel bad for everyone else who just wanted a cheap domain and got dragged into this unwillingly, not all domains hosted are "nazi sites" or whatever people think of.
But also yeah fuck Epik for taking down 9chan domain so lol

I managed to snatch a copy of the files, it looks like a few 10+gb (uncompressed lol) SQL dumps and a whole shitload of WordPress installations that just take up useless space. I'll zip the SQL files and put them on Mega once I get home for those interested.
MEGA isn't 100% safe solution because they take down files a lot more frequently than they used to, at least rename the zip and give it a password so it doesn't look questionable to their eyes.
 
Kinda feel bad for everyone else who just wanted a cheap domain and got dragged into this unwillingly, not all domains hosted are "nazi sites" or whatever people think of.
I made the mistake of looking around for 'normie' opinions on this Epik hack, and the mongoloids at Hacker News had some absolutely soy takes about this shit (not sure what I was expecting, but I'm still somehow disappointed):
Screenshot 2021-09-16 at 16-12-01 Anonymous Hacks Epik Hacker News.png


But even among these soyjacks there were those willing to admit that there's bound to have been some 'decent' customers caught up in this hack. Customers who were burnt out on Google, GoDaddy, etc, and just wanted a host that actually (at least sometimes) demands a court-ordered warrant when some ne'er-do-well wants to send threatening letters trying to fuck with your shit. And that people considering those customers "acceptable collateral damage" just to own the Nazis is pretty shitty and probably sets a scary precedent.
 
I made the mistake of looking around for 'normie' opinions on this Epik hack, and the mongoloids at Hacker News had some absolutely soy takes about this shit (not sure what I was expecting, but I'm still somehow disappointed):
View attachment 2543056

But even among these soyjacks there were those willing to admit that there's bound to have been some 'decent' customers caught up in this hack. Customers who were burnt out on Google, GoDaddy, etc, and just wanted a host that actually (at least sometimes) demands a court-ordered warrant when some ne'er-do-well wants to send threatening letters trying to fuck with your shit. And that people considering those customers "acceptable collateral damage" just to own the Nazis is pretty shitty and probably sets a scary precedent.
Keep in mind, some of them are script kiddies or weirdo furries.
 
Is the source code for the 8kun CAPTCHA there? I wanted to create a training set one time to piss of Dysnomia by spamming /b/ but I never could cus despite the site being supposedly open source they used a different CAPTCHA on the real service
 
This is so fucking larpy lmao also its funny to see Anonymous go super left leaning when they got their start on /pol/ fucking with Scientology people.
It's pretty well-known that any of these "Official Anonymous Operations" done these days is a glowie op.

Certain federal agencies have been using the 'chans as both a honeypot and for astroturfing "Grass roots" campaigns for years now.
 
So, did you catch Mr. Monster’s crazy babel, clocked at around 4-5 hours, last night? He tried to pray the “demon hackers” away, live on stream, & later on his Twitter. Daily Dot has started parsing through the data, creating write ups on the nazi-est sites included in the Epik Fail leak, like daily stormer. (So far there’s only the write up linked below, & one about daily stormer from about a day ago, you can find on the DD twitter below.)

Rundown via DD.
(Archive: https://archive.md/7Lyzr)
4CCD261D-C117-4D6C-BCA8-D7441241EC02.jpeg
From Rob (full tweet):
67A478C4-312E-48CA-8264-288AB51DF915.jpeg
Here’s more
(Archive: https://archive.md/VGPi6)
from Rob Monster’s twitter response. He apparently nuked a doxing site, “Demon Hackers,” at one dudes request during his psycho-babel live stream. He goes on to claim Yom Kippur & maybe even sweet, rich, baby, jesus, will set all things right & correct.

Letting it all hang out.
(Eta: format)
 
Last edited:
Some updates:

New Torrent​

DDOSecrets has released a better version of the original torrent with data gzipped and duplicate/extraneous files removed. If you want a copy of the data for yourself, this is probably the best option.
[Wiki Page] [Direct Torrent Link] [Wiki Page Archive] [Torrent Archive]

#OperationJane​

This was something I saw mentioned in the initial post but didn't look into. Operation Jane is an "Anonymous" effort to rebel against the new Texas abortion law. Warning: the glow from this vid will blind you.
https://twitter.com/OperationJane/status/1433941937049018377

@EpikFailSnippet​

Twitter account mining the data leak. Not much to say.
https://twitter.com/epikfailsnippet

Steven's Revenge​

Steven Monacelli (reporter from the OP) is now bragging about deplatforming the doxing website also mentioned in the OP
1631915472868.png
[Link] [Archive]

In the same thread, he states:
Up until this evening, it was an "alleged" security breach. But now Rob has confirmed that some keys to their Coinbase account were compromised and $100k was nearly stolen.

He also clipped and uploaded his appearance on Monster's livestream:

Articles About the Hack​

There's of course a million articles about this, I'll link a few I've found posted by people originally mentioned in the OP.

Daily Dot​

Analysis of the data by the Daily Dot revealed the names, addresses, phone numbers, and email addresses of those who registered web domains for a range of sites related to everything from the QAnon conspiracy theory to forums for supporters of former President Donald Trump.
[Link] [Archive]

TechCrunch​

TechCrunch has since learned that Epik was warned of a critical security flaw weeks before its breach.

Security researcher Corben Leo contacted Epik’s chief executive Monster over LinkedIn in January about a security vulnerability on the web host’s website. Leo asked if the company had a bug bounty or a way to report the vulnerability. LinkedIn showed Monster had read the message but did not respond.

Leo told TechCrunch that a library used on Epik’s WHOIS page for generating PDF reports of public domain records had a decade-old vulnerability that allowed anyone to remotely run code directly on the internal server without any authentication, such as a company password.

“You could just paste this [line of code] in there and execute any command on their servers,” Leo told TechCrunch.
[Link] [Archive]
 
Last edited:
Back