A hacker using the alias Revolver (@1×0123 on Twitter) said he was selling access to Pornhub servers, asking $1,000 for shell access and command injection capabilities.
In less than 20 hours, Revolver announced that someone had contacted him, and he was selling the exploit (this tweet has since been deleted).
According to data reported on Twitter, Revolver discovered a vulnerability in the script that handles additions to a user's profile picture, which he used to upload a webshell to Pornhub's servers.
The exploit came a week after the ImageTragick vulnerability was announced, but Revolver said it did not use that particular exploit.
Pornhub responded on Twitter 15 hours later, stating that after investigations, “it does not appear that any production servers were accessed.”
Pornhub has between 30 and 60 million daily visitors and the service would be a valuable target for any hacker.
Revolver only asked for $1,000 to sell the exploit, while four days ago, Pornhub launched a bug bounty program that pays exploits like Revolver's much more than $1,000. However, the hacker wrote that he no longer participates in bug bounty programs.
https://twitter.com/1×0123/status/731627800814321664
Revolver is already well-known when he discovered a vulnerability that allowed SQL injection in one of the servers of Mossack Fonseca, the company from which the Panama Papers originated.
