In solidaridad with #OpCatalonia and the ongoing Supreme Court trials of political dissidents being held at the hands of Spanish authorities, “Al1ne3737” of “Pryzraky” unleashed a massive round of hacks, leaks and defaces targeting various businesses and organizations around Spain. More specifically, Al1ne3737 announced a data leak effecting FAIN Elevators in Spain, along with the websites of Astigarraga Kit Line, a high end Spanish furniture retailer, Flins & Piniculas, a online digital media retailer, as well as Dragados S.A., an international business conglomerate basing their operations out of Spain. Al1ne3737 also released the SQLi points of failure of 6 additional websites, offering to give the website owners consultation to patch their vulnerabilities with the release – lulz.
Stepping a bit outside their norm, Al1ne3737 also defaced several of the websites and released a message in Indonesian attached to the leaks reading: “A child will be born today and grow old with no conception of privacy. They will never know what it means to have a private moment to themselves, or thoughts which aren’t registered and analyzed. And this is a problem because privacy is important; privacy and peace of mind is what we all need to determine who we are and who we want to be.”
Targets via Data Breach:
FAIN FRANCE: hxxps://fain.es/
Astigarraga kit line: http://astikitline.es/
Flins y Piniculas: hxxp://flinsypiniculas.com/
Dragados S.A: hxxps://dragados.es/
Deface Mirror: http://www.zone-h.org/mirror/id/32273657?hz=1
Leak: https://www.hastebin.com/avasimehek.nginx
Leak Backup: https://pastebin.com/36Wa6J6g
Screen Shot of Deface:
Additional SQLi Target Locations:
http://www.ordisi.es/index.php?id=Y29uOzQ=1
http://www.listadotren.es/motor/series.php?id=3
http://www.astikitline.es/fr/blog_detalle.php?id=5
http://www.flinsypiniculas.com/ficha.php?id=226
https://www.dragados.es/en/contentdetail.php?id=19
https://fain.es/fr/obras-emblematicas-detalle.php?id=99
@al1ne3737 alcançou proporções épicas nessa semana com (ao menos!) 46 publicações/ataques diferentes.
Ações na #OpCopyWrong, #OpCatalonia, #OpSpain, #OpNicaragua, #SOSNicaragua, #GritoPorNicaragua, #Argentina, #OpAlgeria e #OpDZ#leaks #vazamento #defacehttps://t.co/ds9GgpaevV— DefCon Lab (@LabDefCon) March 17, 2019
Deface!
Accion #Anonymous #OpCatalonia y #OpSpain
Hacked by @al1ne3737 https://t.co/hwtmNxh2F0
— ©halecos Amarillosᴳᴸᴼᴮᴬᴸ 🍀ʷAͤNͣOͬNͤYˡMͤOᵍUͥSͦⁿ (@ChalecosAmarill) March 16, 2019