Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As I had noted in another comment, this product that this person is using is advertised on hackforums. (https://news.ycombinator.com/item?id=5531500) So I've gone on hackforums, searched for poutinecoutu, and what do you know? This might be him.

http://www.hackforums.net/member.php?action=profile&uid=...

So let's look at their recent posts:

http://www.hackforums.net/search.php?action=results&sid=...

>RE: Bitcoin prices collapse over $100 in a matter of hours

http://www.hackforums.net/showthread.php?tid=3398170&pid...

>RE: Buying 10+ BTC via Bank Transfer / Western Union

http://www.hackforums.net/showthread.php?tid=3392974&pid...

So this person knows what Bitcoin is and has some to sell.

Hmm, let's look much further back in their history.

> RE: Ψ #1 [SILENT JAVA DRIVE BY] FoxxyJava [0/37]★ FREE HOSTING ★ SPREAD FASTER! ★ [$20] Ψ

>Vouch for this amazing jdb. Keep good work. He is ALWAYS disponible for his clients. He helped me alot.

http://www.hackforums.net/showthread.php?tid=3005399&pid...

FoxyJava is a Java Drive-By, similar to this GalaxyJDB the exploit used. I wonder if he has also used GalaxyJDB? I can't see any replies, but it's possible. Let's go to the galaxyjdb site and see if the person who programmed the login was dumb enough to check username and password seperately: http://galaxyjdb.com/index.php?a=Login

...sadly not, it would seem. So I can't prove they use GalaxyJDB, or that this is even the person we're after, but I think it's very likely.



You can easily check if the username is taken via the register form - it is.

Flaw: someone could potentially have tried the same thing before me and accidentally registered it.


Right. I have no clue what to do now, though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: