Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   1843

No, SQLSniper’s database was not breached: Exposing liars.

by CYBER - 30 January, 2022 - 01:33 AM
This post is by a banned member (CYBER) - Unhide
CYBER  
Supreme
149
Posts
25
Threads
6 Years of service
#1
(This post was last modified: 30 January, 2022 - 01:42 AM by CYBER. Edited 1 time in total.)
In short: SQLSniper’s database was not breached. No data was leaked, and all user data is safe. We take extra care to ensure the safety and security of all users, which is exactly why no data was actually breached.

In this thread, I intend to explain further for my customers and for the people who may have seen this so-called breach.

@WindexBoi has posted a thread called "SQLSNIPER DB LEAK | FIXED".

This post contains a ~5MB CSV file titled “sqlsniper-users.csv” containing a list of 40,200 usernames, emails, MD5 hashed passwords, IP addresses plus various other user metadata.
This file has been advertised as a database breach of SQLSniper users. As a side note, I am the owner of SQLSniper.

When I was first alerted of this thread, of course, I downloaded the file immediately to verify the authenticity and severity of this leak.

I noticed that something was off immediately. This CSV file contained the following column names in its first line: username,group_id,vroop_id,password,userid,userlevel,email,timestamp,ip,validate,acceptterms.

My panic was averted. For those who are unaware, the first line in a CSV file defines the columns that the CSV file contains. These columns DO NOT match the ones found inside the legitimate SQLSniper database; the one that only I have access to. The columns inside the legitimate database are quite simply id,username,licence_key,ip_whitelist.

We do store other metadata such as the user's subscription expiry in other tables, though, but this isn’t even present in the fake data breach!

Okay. This was enough for me to stop my investigation immediately. What is this bullshit, "vroop_id, userlevel, acceptterms"? That’s ridiculous. Clearly, this so-called data breach is fake. Purely based on the column names that aren’t even remotely similar to what’s in my real database, I can already conclude that it’s fake, and I can move on with my life - right?

Furthermore, are we going to ignore the ridiculous amount of users in this database? Are you telling me SQLSniper has 40,000 users? If that’s true, I would be a multi-millionaire!
SQLSniper sells for around $100 and if you do $100 * 40,000, you get 4 million. And $100 is the minimum. Absolute madness!

Still don’t believe me? I went around and asked 6 of my customers. None of them - not even one - could find their data in this so-called data breach. It’s complete bullshit!

Screenshot proof:

Show ContentSpoiler:

Obviously I’ve proven this breach is completely bullshit, but could it’ve been a mistake, could he have been mislead himself? Well, I thought so, apart from one detail. @WindexBoi specifically said in an old SQLSniper fake breach thread (which was taken down for malware reasons by staff)
“idk how got it, i got it off a friend a while ago, can confirm some of the usernames”

Here is a full screenshot of the OLD fake data breach thread that @WindexBoi published a couple of days ago.
Show ContentSpoiler:

More specifically, he said  “can confirm some of the usernames” in the thread. So what he’s saying is that he’s cross-checked the usernames in this breach and has “confirmed” it. That’s absolute crap! I’ve proven this data breach is bullshit, yet he’s sitting here lying to everyone saying that essentially the breach contains SQLSniper users, thus saying himself that it’s authentic, when it’s clearly not!

Again, I’m still in disbelief that he saw 40,000 users and didn’t think “wait a minute, isn’t a bit unreasonable for there to be 40,000 users on a small tool that’s only sold for a few months?” I don’t believe that this thought couldn’t come across his mind. Make of this what you will, but this is clearly lying, IMO.

Although, of course, I’m no mind-reader, there are some pretty obvious reasons why @WindexBoi has authored a fake data breach.

1. Polluting my Google search results with threads about a data breach
2. Making downloader’s of the false breach cross-post on other forums.
3. To spread a bad reputation about SQLSniper, based on a complete lie.

Finally, take what you will from this information, but WindexBoi owns a tool called Dorkr which holds some similar functionality to my tool SQLDorks. *shrug*

I take safety and security seriously. This whole situation has caused unease and a commotion amongst the customers who trust us and has understandably made some people view my tool in a bad light, when in reality, they were misled.
I’d like to make clear that all user data is safe and will remain safe, and no data was breached.

Thanks
This post is by a banned member (Moruq) - Unhide
Moruq  
Heaven
5.063
Posts
241
Threads
5 Years of service
#2
Thanks for the clarification.
This post is by a banned member (WindexBoi) - Unhide
WindexBoi  
Supreme
182
Posts
46
Threads
5 Years of service
#3
(This post was last modified: 30 January, 2022 - 02:04 AM by WindexBoi.)
dedupe makes it 3k users for 1, 
2 the db breach occurred in 2020, a lot has happened since then, like sqlsniper has been added and removed off the market, a recode of the infrastructure could have easily occured.
and 3, i didn't breach it, someone else in a telegram group who was associated to the breach did confirm that it was indeed them and i didn't mention them for privacy reasons.

If u have doubts ab the leak dm me on c.io so that way no logs can be removed of messages and fabrication of dms can be confirmed, and i will redirect you to them to query them about the file i was given.
Im back G_G.

DM for inquiries about dorks, potential tools you want made around the field of dorking, hacking, etc. 
DM for inquires about proxies, as I'm looking for prospect clients and their needs to then create a service dedicated for them.
DM for League of Legends based deals, such as cracked accounts, cheap botted accounts in bulk with a sub 1% ban rate, ARAM accs, Hand leveled accounts, boosting, and cashflowing.
This post is by a banned member (CYBER) - Unhide
CYBER  
Supreme
149
Posts
25
Threads
6 Years of service
#4
(This post was last modified: 30 January, 2022 - 02:18 AM by CYBER. Edited 2 times in total.)
(30 January, 2022 - 02:04 AM)WindexBoi Wrote: Show More
dedupe makes it 3k users for 1, 
2 the db breach occurred in 2020, a lot has happened since then, like sqlsniper has been added and removed off the market, a recode of the infrastructure could have easily occured.
and 3, i didn't breach it, someone else in a telegram group who was associated to the breach did confirm that it was indeed them and i didn't mention them for privacy reasons.

If u have doubts ab the leak dm me on c.io so that way no logs can be removed of messages and fabrication of dms can be confirmed, and i will redirect you to them to query them about the file i was given.

1. 6000*100 still equals 600000 and that's assuming everyone purchased the minimum tier (i have performed a dedupe and there are 6000 unique lines, not 3000)
2. customers have *confirmed* that the database breach is false, xc, first sqlsniper customer, has disaproved it.
3.
I love your attempts to shift the blame on to other people. You are the publisher of the thread and you are responsible for verifying that this is authentic information. It doesn't take a genius to see that 6000 users is irrational and for that reason I believe you are lying. No response needed, I am just expressing my opinion there.

You're taking the thread down/have taken the thread down because you got called out.
Show ContentSpoiler:
This post is by a banned member (zex58) - Unhide
zex58  
Supreme
32
Posts
0
Threads
4 Years of service
#5
love u daddy cyber
This post is by a banned member (CYBER) - Unhide
CYBER  
Supreme
149
Posts
25
Threads
6 Years of service
#6
(31 January, 2022 - 01:14 AM)cloudy1337x Wrote: Show More
love u daddy cyber

pepeblush
This post is by a banned member (0x071) - Unhide
0x071  
Registered
174
Posts
33
Threads
3 Years of service
#7
i already tought this...i have the database here but i have no intention to leak this or what soever even its real or fake .. its just a little bit weird yes.... also sql sniper is pro its insane little bit expensive but its wurth it!!!!
This post is by a banned member (Crac4x) - Unhide
Crac4x  
Supreme
666
Posts
489
Threads
5 Years of service
#8
That's unfortunate...Imagine doing something so lame if true. I tried DORKR along with Rusty Dumper and got nowhere. For a noob on dorks and dumping you really need some sort of guide. Neither had support or would show how the tools worked. Do you provide assistance with your tool? I may cop today and take a dive at it again. I wasted so much time on DORKR and Rusty Im hesitant to waste more for shit results. My buddy showed me your server though and says your program is a all in one BEAST. Planning to test it this weekend...

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)