Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Mike 03

(16,616 posts)
Tue Nov 24, 2020, 07:23 PM Nov 2020

More on the Parler Hack. (Miscellaneous chaos)



Parler has been compromised. DM's as well as SSN's and other ID leaked (twitter.com/kevinabosch)
4 points by fooey 37 minutes ago | hide | past | favorite | 6 comments

fooey 36 minutes ago [–]

Here's an additional source with an ENV dump



reply


slondr 21 minutes ago [–]

Am I missing something? I don't see anything about SSNs here
reply


newacct583 10 minutes ago [–]

Someone posted a link to a Parler influencer agreement document which said they would ask for things like government IDs. It's entirely unclear if they ever took that data or if was available via this database. But... yeah, this is the whole Parler site it looks like.
reply


ev1 25 minutes ago. [–]

Why in the absolute fuck is Parler requesting any form of PII/PCI data?
reply


fooey 22 minutes ago. [–]

For "Verified" accounts
reply



https://news.ycombinator.com/item?id=25203846




Text: BREAKING: There was just a #parlerhack, this was publicly available and unencrypted on their public API endpoint. Not sure what they've changed yet, although expect a ton of data shortly, we will post updates. #ParlerLeaks

Link to something called an ENV Dump (DU computer and tech experts needed here!)

https://archive.ph/Mll5H

Sample from the ENV Dump:

# Database Configuration
define( 'DB_NAME', 'wp_parler' );
define( 'DB_USER', 'parler' );
define( 'DB_PASSWORD', 'hIP9PEV6u1GXfG4F8jEA' );
define( 'DB_HOST', '127.0.0.1' );
define( 'DB_HOST_SLAVE', '127.0.0.1' );
define('DB_CHARSET', 'utf8');
define('DB_COLLATE', '');
$table_prefix = 'wp_';

# Security Salts, Keys, Etc
define('AUTH_KEY', '@,*9_voP3sKC3z&&P}[(-h2#UOM_0]*[02%]MW:h7}L,G.IN1j@bKY0ohOqH');
define('NONCE_KEY', 'E@V!WK#Z0h%ZRs5dRg?7!orCFbGAUWLXxf3|:55g(++`$CQVc53n7]U}}]ck5{;l');
define('AUTH_SALT', '+!5MfxQ7]x >FNiuS|/c:nX yG=ksoW)+jZbgjogXQar)*,&HY>{|*v8pBA;$|-w');
define('SECURE_AUTH_SALT', '+bq>0u,c^1#[7l1#|R+7-[;$iw>3sQ@N|^l>x7-eci(>}');


# Localized Language Stuff

define( 'WP_CACHE', TRUE );

define( 'WP_AUTO_UPDATE_CORE', false );

define( 'PWP_NAME', 'parler' );

define( 'FS_METHOD', 'direct' );

define( 'FS_CHMOD_DIR', 0775 );

define( 'FS_CHMOD_FILE', 0664 );

define( 'PWP_ROOT_DIR', '/nas/wp' );

define( 'WPE_APIKEY', 'a1495db2888c2a21d556a9d9d0617935fbb5be57' );

define( 'WPE_CLUSTER_ID', '151738' );

define( 'WPE_CLUSTER_TYPE', 'pod' );

define( 'WPE_ISP', true );

define( 'WPE_BPOD', false );

define( 'WPE_RO_FILESYSTEM', false );

define( 'WPE_LARGEFS_BUCKET', 'largefs.wpengine' );


21 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
More on the Parler Hack. (Miscellaneous chaos) (Original Post) Mike 03 Nov 2020 OP
Cambridge Analytica people who are running this for the Mercers are octoberlib Nov 2020 #1
Thank you underpants Nov 2020 #2
I hope those posting here bragging about joining that site to stir shit have not done so. cwydro Nov 2020 #3
I don't think anyone here was considered an "influencer" over there... brooklynite Nov 2020 #9
Well, that's good to hear. cwydro Nov 2020 #15
Isn't that crazy? Mike 03 Nov 2020 #4
My only though is that its a russian site collecting data.... ace3csusm Nov 2020 #5
"What is PCI and PII data?" - Answered Mike 03 Nov 2020 #6
These are the kinds of people who won't give a phone number to a restaurant for contact tracing gollygee Nov 2020 #7
... Mike 03 Nov 2020 #8
Who said that their decision-making made any sense? Blue_true Nov 2020 #18
Remember they'll trust anything that is a part of their own tribe. ego_nation Nov 2020 #19
Gee. I don't think anybody could have predicted that these hackers Eugene Nov 2020 #10
Looks like a site built with WordPress turtleblossom Nov 2020 #11
Maybe left it at BumRushDaShow Nov 2020 #14
Why would there be SSNs on Parler??? n/t Ms. Toad Nov 2020 #12
I wish I understood one word of this BigmanPigman Nov 2020 #13
It's not Russian, but domestic skulduggery Brother Buzz Nov 2020 #20
I actually understood that! BigmanPigman Nov 2020 #21
Are these people being hacked on Perilous Parler the same people concerned with their abqtommy Nov 2020 #16
I don't think it's real LeftInTX Nov 2020 #17

octoberlib

(14,971 posts)
1. Cambridge Analytica people who are running this for the Mercers are
Tue Nov 24, 2020, 07:27 PM
Nov 2020

datamining. Who in the hell would give this site their SSN ?

 

cwydro

(51,308 posts)
3. I hope those posting here bragging about joining that site to stir shit have not done so.
Tue Nov 24, 2020, 07:30 PM
Nov 2020

Seems a very poor decision.

brooklynite

(94,792 posts)
9. I don't think anyone here was considered an "influencer" over there...
Tue Nov 24, 2020, 07:34 PM
Nov 2020

...when I set up my account, it was just the usual name and email address.

 

cwydro

(51,308 posts)
15. Well, that's good to hear.
Tue Nov 24, 2020, 07:44 PM
Nov 2020

I didn’t know you were one of those who joined.

I was thinking of some others, but at any rate, that’s good to hear that no one was giving SSN info etc.

These “reports” of a hack all seem to imply that people had to provide extensive personal info.

Mike 03

(16,616 posts)
4. Isn't that crazy?
Tue Nov 24, 2020, 07:30 PM
Nov 2020

I've never been asked for my SSN by a website, never, not Amazon, Twitter, etc...

ace3csusm

(969 posts)
5. My only though is that its a russian site collecting data....
Tue Nov 24, 2020, 07:30 PM
Nov 2020

Why in the absolute fuck is Parler requesting any form of PII/PCI data?
reply?

Because they are a russsian site ....

Mike 03

(16,616 posts)
6. "What is PCI and PII data?" - Answered
Tue Nov 24, 2020, 07:32 PM
Nov 2020
What is PCI and PII data?
Two key areas of data compliance revolve around Payment Card Industry (PCI) and Personally Identifiable Information (PII). ... PII data includes such things as social security numbers, date of birth, personal health information, and other data that can identify an individual.


https://sherpasoftware.com/blog/finding-pci-pii-in-your-organization/

I didn't know either; I had to look it up.

gollygee

(22,336 posts)
7. These are the kinds of people who won't give a phone number to a restaurant for contact tracing
Tue Nov 24, 2020, 07:32 PM
Nov 2020

and they're giving their social security numbers out for a social networking site?

Blue_true

(31,261 posts)
18. Who said that their decision-making made any sense?
Tue Nov 24, 2020, 07:51 PM
Nov 2020

They are screwball that got their asses in a sling now.

Eugene

(61,965 posts)
10. Gee. I don't think anybody could have predicted that these hackers
Tue Nov 24, 2020, 07:36 PM
Nov 2020

would come for a site with social security numbers.

turtleblossom

(504 posts)
11. Looks like a site built with WordPress
Tue Nov 24, 2020, 07:38 PM
Nov 2020

Did they forget to chmod something????

If the IP hosting address was given, one could determine who's hosting this website.

BigmanPigman

(51,642 posts)
13. I wish I understood one word of this
Tue Nov 24, 2020, 07:41 PM
Nov 2020

but it really is like Russian to me. Can someone explain this like you're are speaking with a three year old since that is my level of tech lingo.

Brother Buzz

(36,478 posts)
20. It's not Russian, but domestic skulduggery
Tue Nov 24, 2020, 07:58 PM
Nov 2020

Parler has a direct link to the defunct Cambridge Analytica founded by Robert Mercer for the sole purpose of data mining. Mercer's daughter started Parler, and undoubtedly used a bootleg copy of Cambridge Analytica's software.

abqtommy

(14,118 posts)
16. Are these people being hacked on Perilous Parler the same people concerned with their
Tue Nov 24, 2020, 07:46 PM
Nov 2020

freedumb to go maskless since the virus is a hoax? Yeah, there's definitely a hoax involved
but it's not the virus!

Latest Discussions»General Discussion»More on the Parler Hack. ...