Albion Online Database - Leaked, Download!
by - Thursday, January 1, 1970 at 12:00 AM
Hello BreachForums Community,
Today I have uploaded the Albion Online Database for you to download, thanks for reading and enjoy!



In October 2020, the forum for the popular fantasy MMORPG Game Albion Online suffered a data breach that impacted 292k users. The breach included Usernames, Email addresses and Passwords stored as Double Bcrypt (bcrypt rehashed in bcrypt again) hashes. The website was breached by @donjuji.

Compromised data: Usernames, Email addresses, Passwords
The .7z File's MD5 Hash is C205257B03E2C9494FEB888B2BA9D1D4. In total, there are 292587 records. The file is 74.52MB uncompressed and 27.31MB compressed.
Hidden Content
You must register or login to view this content.
Reply
Thank for sharing. Dobule Bcrypt is hard to crack. :(
Reply
(July 26, 2022, 04:31 AM)Challenger Wrote: Thank for sharing. Dobule Bcrypt is hard to crack. :(


yes i managed to crack about 21k lines
Reply
(July 26, 2022, 04:32 AM)donjuji Wrote:
(July 26, 2022, 04:31 AM)Challenger Wrote: Thank for sharing. Dobule Bcrypt is hard to crack. :(


yes i managed to crack about 21k lines


Hope to find the password.  :D
Reply
Original Post:

[quote=donjuji]I would have got the main game db but just as i was about to get it i lost my shell due to me having trusted instakilla with it and him using it to try and extort the company that developed it.
Thats right. He tried to blackmail them before i even finished dumping the main db.
I even found the postgresql creds for the mian db later after i lost rce because i had backed up almost the entire server. (Yes i still have that if anyone wants it you can dm me and tell me why and i may oblige.
Anyways here is this forums that i did dump.
I was able to get rce by exploiting a mistake in their upgrading from smf to their current db cms. It broke extension checks for the avatar upload function.
Unfortunately they had an extra layer of protection in which the site checks the image being uploaded to see if its a legit image and if it is it stamps it with a line of code that says is okay to upload.
I simply uploaded a regular image, it got stamped, and then i reuploaded it again after hex editing in a php oneliner to download a shell.
Their patch for this was to make all php files 403 besides ones that end in index.php.
This means you can still upload html to the server, shtml and many other ext types. I think its quite possibly still vulnerable with some creativity.[/quote]

Sample: https://pastehub.net/7a78ce23be3

https://pompur.in
Reply
(July 26, 2022, 04:27 AM)donjuji Wrote:
Hello BreachForums Community,
Today I have uploaded the Albion Online Database for you to download, thanks for reading and enjoy!



In October 2020, the forum for the popular fantasy MMORPG Game Albion Online suffered a data breach that impacted 292k users. The breach included Usernames, Email addresses and Passwords stored as Double Bcrypt (bcrypt rehashed in bcrypt again) hashes. The website was breached by @donjuji.

Compromised data: Usernames, Email addresses, Passwords
The .7z File's MD5 Hash is C205257B03E2C9494FEB888B2BA9D1D4. In total, there are 292587 records.

solid appreciate it.
Reply
Thx bro :D
Reply


 Users viewing this thread: Albion Online Database - Leaked, Download!: No users currently viewing.