Website that lets you send poop through the post gets hacked


A known threat actor has hacked his way into notorious revenge website ShitExpress and leaked the company’s secure data, including customer email addresses and the messages they sent through the platform.
ShitExpress is an online service that allows people to send actual faeces, through the post, to whomever they desire. It’s designed to be a prank site, where people can purchase a piece of animal faeces and have it delivered to someone’s door, in a box, together with a personalized message.
You can imagine the type of messages someone would send together with a piece of animal dung to their cheating former partners, horrible ex boss, or noisy neighbor – hence why this leak might be troubling to many customers.
SQL Injection flaw
As reported by BleepingComputer, a user going by the name “pompompurin” visited the site in order to send a box to his long-time arch-nemesis, cybersecurity researcher, Vinny Troia. The two go way back, pranking and harassing each other for quite some time, the publication reported.
Upon opening the site, he realized that it was vulnerable to SQL Injection, and soon Mr pompompurin was soon sifting through email addresses, customer messages, and other private data (opens in new tab) associated with the orders.
A day after successfully compromising the site, he leaked the database on a hacking forum. Speaking to the publication about it, pompompurin said the database was surprisingly small: “It’s honestly not that big… There’s about 29,000 orders in the data,” he said.
He also said that he didn’t do it for ransom or anything similar. “I gained access a day before I leaked it, and I notified the website owner after dumping the data. [I’m] not sure if they’ve acknowledged or anything as of yet,” he confirmed.
In response to the incident, ShitExpress acknowledged the breach, and took responsibility, saying: “It’s purely our fault — a human error that could happen to anyone. It was found by one of our customers. We fixed the error immediately.”
As this is a prank site, that gathers almost no customer data at all, there was nothing particular to leak from the compromised endpoints (opens in new tab). Payment data was left with the payment provider, meaning pompompurin never got it.
Via: BleepingComputer (opens in new tab)
Audio player loading… A known threat actor has hacked his way into notorious revenge website ShitExpress and leaked the company’s secure data, including customer email addresses and the messages they sent through the platform. ShitExpress is an online service that allows people to send actual faeces, through the post, to…
Recent Posts
- Rumor suggests Nvidia’s had difficulties to iron out with chips for RTX 5070 and 5060 GPUs, seemingly leading to delays and possibly low stock levels
- Apple’s Murderbot series starts streaming in May
- Amazon MGM Studios acquires the license to thrill as its gains full creative control of the entire James Bond franchise in landmark deal
- The 3 Best Essential Oil Diffusers (and One to Avoid)
- Why OpenAI is trying to untangle its ‘bespoke’ corporate structure
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010