CheapAssGamer, Video Game Deals Website Apparently Hacked

article image

CheapAssGamer.com, a place where gamers can go to share and view video game and product deals online, has apparently been hacked. Twice.

Yesterday, if you were to visit the website, your tab would read, "why are you here," with a message on the home page (please excuse the fowl language) that reads:

All your users belong to us.
We have taken everything and the webmaster is taking a gigantic s*** so f*** off. We're busy.
Yo why you block my twitter @localblackhat mang? I reppin'
Happy Martin Luther King Day Ma N****

It appeared as though the administrators of the website had gotten it back up and running late last night up until earlier today, however, once again, the site is down, this time with a new message appearing on the home page. As of this writing, the message reads:

Okay, it ends here Webmaster. This is now your third warning to MASS RESET ALL PASSWORDS ON THE SITE. THEY ARE COMPROMISED.
We will continue entering untill we see this happen. Also, since you haven't listened to us the first time. We are now releasing your SQL info.

// error_reporting(E_ALL);
$INFO['sql_driver'] = 'mysql';
$INFO['sql_host'] = '192.168.0.11';
$INFO['sql_database'] = 'cag';
$INFO['sql_user'] = 'cag';
$INFO['sql_pass'] = 'v34nf9wfvn';
$INFO['sql_pass'] = 'xfdritch9';
$INFO['sql_tbl_prefix'] = '';
$INFO['sql_debug'] = '0';
$INFO['sql_charset'] = '';
$INFO['board_start'] = '1370298920';
$INFO['installed'] = '1';
$INFO['php_ext'] = 'php';
$INFO['safe_mode'] = '0';
$INFO['board_url'] = 'https://www.cheapassgamer.com';
$INFO['banned_group'] = '5';
$INFO['admin_group'] = '4';
$INFO['guest_group'] = '2';
$INFO['member_group'] = '3';
$INFO['auth_group'] = '1';
$INFO['use_friendly_urls'] = '1';
$INFO['_jsDebug'] = '0';
$INFO['mysql_tbl_type'] = 'INNODB';
@localblackhat ~CMD

CheapAssGamer has yet to reach out again to its users on Twitter following the second take down of the site. If you have an account with the website, your information could very well be comprised. If you use the same password on CAG as you do with other websites, you might want to change it.

    back to top
    x