First, here's the old hidden directory tests just to refresh memories - Comet Ping Pong and Buck's Fishing and Camping.
The general judgment I received was that there was too much specificity. The test not only had hidden directory results but also "Custom extensions, Common configuration files, Configuration files, Source code files, Archives, Database files, Logs, Backup files, Documents, and Web files".
(as declared by jackthebutholeripper). And I get that, I do.
So here's the thing, I had only 50 points left. That's the way pentest-tools does things. I used it to do another scan on bucksfishingandcamping.com (I chose this and not cpp because this is where the password protected section was allegedly found) and this time, I deselected all the other options and only wanted the test to detect directories. Here are the results.
Doing this, results went down from 1100 to 200. But we still have interesting results for a small domain (we're talking 5 links here) such as:
/benefits
/delicious
/feeds
/lsold/
/memberlist (10 of these with varying names)
No /military, /iraq.bat, /asia, /jacob, /anal.java, /military etc.- I'm sorry but I still don't believe these were default squarespace or java pieces, wouldn't a quick google search confirm this?
What I'm taking away from all of this is, even if we cannot get to what was once there, this is like a footprint. Now I know the directories I mentioned came from Comet Ping Pong's website but we are talking about a pizza place here. There is no reason to have a directory called asia or military connected to your website.
Anyway, now onto the new stuff. First off, if what I'm about to post is not allowed for whatever reason, let me know and off it goes.
Another testing website and another experiment. Dehashed.com
A website where they compile all the dumps that they can find and put it into one place. Late nights of searching and surfing led me here.
Searching for BucksFishingandCamping brings me no hits. Searching for James Alefantis doesn't really bring me anything either.
But searching for Comet Ping Pong brings me a couple of things.
We have a dropbox - [email protected] - pass is bigcheese5
We also have a yahoo email account - [email protected] - pass is 4greenwood
The most interesting thing is we also have a Zoosk account. Zoosk is a pay to play dating app. (After the first message to the person you're attracted to, you have to pay to contact them any further.)
The username for the account is supposedly cometpingpong.
The email address connected to the account is [email protected]. I don't think we've ever heard of a Janet Jimenez before. When dehased using a free online tool, the password is/was tootie.
And that's where it ends for now. I'm not up to try and get into the accounts with the passwords given. They might work or they've might been changed when all of this originally broke.
But I will leave one thing for all of us to chew on:
Zoosk -> the dating app
tootie -> the password that once belonged to the zoosk account
Joola -> ping pong tables
What's with the one letter, then two o's, then two letter words? I'm not sure if there's a significance but it just struck me for some reason.
view the rest of the comments →
carmencita ago
pass is bigcheese5
Remember Cesar Sayoc the guy that supposedly sent those packages to Democrats? He worked at a pizza place in Fla. and there was a bigcheeseLLC connection to that pizza place. I am searching for it now. Someone posted it in the comments. New River Pizza & Fresh Kitchen I found this PDF but don't know how to copy. https://abra.dc.gov/sites/default/files/dc/sites/abra/publication... This appeared below the link to the PDF in the copy it stated a connection of Alefantis to Big Cheese LLC.
dicedtomatoes55-2 ago
The link you give says "Page Not Found". I don't know if it said anything before. So the password is the name of the LLC, gotcha.
What was the connection?
carmencita ago
Here it is http://anc3f.com/wp-content/uploads/2016/04/5037-Conn-Ave-NW-3-12-2014-Comet-Pizza.pdf
carmencita ago
It was there and now gone. Today I found it again but am lousy at archive. Now it has disappeared again. Who's doing this? Super Fishy imo. @NOMOCHOMO I saw it. Never been more sure of anything. It also had a place you could click on states, etc. and it listed who was with Big Cheese LLC in that state. If you clicked on DC well James Alefantis came up and his agent. Dang can't remember his name Jack something I think. Checking some more right now.
Yuke ago
That's one that I don't buy and I said at the time that it was revealed that it could simply be the use of the same phrase, "Big Cheese" as in, I'm the top dog, the head honcho, the big cheese, i.e; the boss.
carmencita ago
Hmm. Yes and exactly why it may be used. A great way to hide it.
Yuke ago
Yeah but it doesn't mean that it has anything to do with Alefantis or Pizzagate. I think that was just a lazy case of trying to link multiple conspiracies together. In reality they would likely keep them very separate otherwise it'd be easier to crack the case and bring it all down.