LIVE - Saudi Arabia, UAE, Oman - Zain, Mobily, STC, ooredoo_oman Live MVAS SMS Advertisements logs & Phone Numbers, API Keys

vax42

New member
Messages
1
Reaction score
0
Points
0
Company Sector: Telecom / Advertisements
Revenue: $248M/Annually.
Employees: ~400
Service: They partner with companies to sell SMS ads for their customers for the MENA region.

Access type:
  1. Live URLs to their SMS Logs from of all of their Telecom operators. (Client name, customer-number, sms-content, api-key, balance, endpoint, etc.)
  2. Mobily (Saudi Arabia) SMS/OTP endpoint, api_key, and authentication number(api_secret).
  3. Multiple DB Dumps, mostly their settings and API keys(untested), their url shortern data, their admin portal passwords in md5 (2 of them are unhashable)(not-tested), logins and passwords for their ISP connectors (untested)
  4. random client related XSLX files and telecom / backend MVAS related settings/files/.. stuff that i don't understand (could be useful for a company wide breach?
  5. thousands of phone numbers.
  6. a lot of backend stuff that I don't understand, related to telecom/sms-gateway settings/files.

Спойлер: Mobily SMS Checker/Sender API Logs
[2024-02-19 06:32:26] [api] [xxxxxxxxxxxxxxxxxxxxxx27f] mobily.DEBUG: params [{"userIdentifier":"966xxxxxxx25","userIdentifierType":"REAL","productId":"23278","mcc":"420","mnc":"03","entryChannel":"WEB"}] []
[2024-02-19 06:32:26] [api] [65d2f5fa479619d250beb27e] mobily.DEBUG: check_status_response [{"response":"{\"inError\":false,\"requestId\":\"xxxxxxxxx\",\"code\":\"SUCCESS\",\"responseData\":{\"subscriptionStatus\":\"SUSPENDED\",\"nextRenewalDate\":\"2024-02-19T13:38:51\"}}","httpCode":"200"}] []
[2024-02-19 06:32:26] [api] [xxxxxxxxxxxxxxxxxxxxxx27f] mobily.DEBUG: check_status_by_msisdn [{"msisdn":"966xxxxxxx25","service_connection_id":"2905"}] []
[2024-02-19 06:32:27] [api] [xxxxxxxxxxxxxxxxxxxxxx27f] mobily.DEBUG: check_status_url [["
https://mobily-ma.xxxxx.xxxx.xxx/xxx/api/external/v1/subscription/status/xxxxx

"]] []
[2024-02-19 06:32:27] [api] [xxxxxxxxxxxxxxxxxxxxxx27f] mobily.DEBUG: header [["Content-Type: application/json","apiKey: xxxxxxxxxxxxxb3c","authentication: kjxxxxxxxxxxxxxxxCo=","external-tx-id: xxxxxxxxxxxxxxxxxxxx.7839"]] []


Спойлер: Zain KSA SMS Logs
[2024-02-19 06:27:12] [api] [65d2f4bd479619c54fbeb26b] zainksa.DEBUG: params [["<soapenv:Envelope xmlns:soapenv=\"http://schemas.xmlsoap.org/soap/envelope/\" xmlns:loc=\"http://www.sdp.com/schema/subscription/v1_0/local\"> <soapenv:Header> <tns:RequestSOAPHeader xmlns:tns=\"http://www.huawei.com.cn/schema/common/v2_1\"> <tns:spId>001518</tns:spId> <tns:spPassword>xxxxxxxxxxx</tns:spPassword> <tns:timeStamp>20240219062709</tns:timeStamp> </tns:RequestSOAPHeader> </soapenv:Header> <soapenv:Body> <loc:getSubScriptionListReq> <loc:userID> <ID>966xxxxxxxxxxxx0</ID> <type>0</type> </loc:userID> <loc:actionType>1</loc:actionType> </loc:getSubScriptionListReq> </soapenv:Body> </soapenv:Envelope>"]] []
[2024-02-19 06:27:12] [api] [xxxxxxxxxxxxxx6b] zainksa.DEBUG: check_status_response [{"response":"<?xml version=\"1.0\" encoding=\"utf-8\" ?><soapenv:Envelope xmlns:soapenv=\"http://schemas.xmlsoap.org/soap/envelope/\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\"><soapenv:Body><ns1:getSubScriptionListRsp xmlns:ns1=\"http://www.sdp.com/schema/subscription/v1_0/local\"><ns1:recordSum>2</ns1:recordSum><ns1:subScriptionInfos><ns1:subScriptionInfo><ns1:orderKey>xxxxxxxxxxx6</ns1:orderKey><ns1:userID>966xxxxxxxxxxx0</ns1:userID><ns1:productID>100xxxxxxxx9</ns1:productID><ns1:productNames><ns1:productName><langInfo><language>ar</language><country>SA</country></langInfo><name>ProductName</name><value>نمبلاي</value></ns1:productName><ns1:productName><langInfo><language>en</language><country>US</country></langInfo><name>ProductName</name><value>Numplay</value></ns1:productName></ns1:productNames><ns1:productDescs><ns1:productDesc><langInfo><language>ar</language><country>SA</country></langInfo><name>ProductDesc</name><value>هي خدمة لتقديم العاب متنوعة|بالنسبة لمستخدم المجموعة Ø§Ù„Ø§ÙØªØ±Ø§Ø¶ÙŠØ©ØŒ سيكون الإيجار بـ 1.5 ر.س لكل يوم، يتم تجديد الاشتراك تلقائيًا.</value></ns1:productDesc><ns1:productDesc><langInfo><language>en</language><country>US</country></langInfo><name>ProductDesc</name><value>it is a service that offers a multi type of games |For Default Group, rental 1.5 SR per day(s), automatic renew.</value></ns1:productDesc></ns1:productDescs><ns1:parentID>001xxxxxxx35</ns1:parentID><ns1:parentType>1</ns1:parentType><ns1:parentNames><ns1:parentName><langInfo><language>ar</language><country>SA</country></langInfo><name>relateObjectName</name><value>نمبلاي</value></ns1:parentName><ns1:parentName><langInfo><language>en</language><country>US</country></langInfo><name>relateObjectName</name><value>Numplay</value></ns1:parentName></ns1:parentNames><ns1:spID>001518</ns1:spID><ns1:spNames><ns1:spName><langInfo><language>ar</language><country>SA</country></langInfo><name>name</name></ns1:spName><ns1:spName><langInfo><language>en</language><country>US</country></langInfo><name>name</name><value>Abxxxxxxx Abxxxxx Almxxxxx Trade EST (xxxxxxx)</value></ns1:spName><ns1:spName><langInfo><language>ur</language><country>PK</country></langInfo><name>name</name></ns1:spName></ns1:spNames><ns1:subTime>20230310211947</ns1:subTime><ns1:nextChargeTime>20240218210000</ns1:nextChargeTime><ns1:isAutoExtend>1</ns1:isAutoExtend><ns1:subScriptionState>7</ns1:subScriptionState><ns1:payType>0</ns1:payType><ns1:srcProductID>-1</ns1:srcProductID><ns1:channelID>1</ns1:channelID><ns1:subApplyTime>20230310211947</ns1:subApplyTime><ns1:subExpireTime>20361231220000</ns1:subExpireTime><ns1:amountInfos><ns1:amountInfo><objectID>0015182000035035</objectID><objectType>1</objectType><totalAmount>-1</totalAmount><unit>3</unit><usableAmount>-1</usableAmount></ns1:amountInfo></ns1:amountInfos></ns1:subScriptionInfo><ns1:subScriptionInfo><ns1:orderKey>9xxxxxxxxx1</ns1:orderKey><ns1:userID>966xxxxxx0</ns1:userID><ns1:productID>1xxxxxxxx1</ns1:productID><ns1:productNames><ns1:productName><langInfo><language>ar</language><country>SA</country></langInfo><name>ProductName</name><value>VMS Service</value></ns1:productName><ns1:productName><langInfo><language>en</language><country>US</country></langInfo><name>ProductName</name><value>VMS Service</value></ns1:productName></ns1:productNames><ns1:productDescs><ns1:productDesc><langInfo><language>ar</language><country>SA</country></langInfo><name>ProductDesc</name><value>VMS Service|بالنسبة لمستخدم المجموعة Ø§Ù„Ø§ÙØªØ±Ø§Ø¶ÙŠØ©ØŒ سيكون الإيجار بـ 0 ر.س لكل شهر، يتم تجديد الاشتراك تلقائيًا.</value></ns1:productDesc><ns1:productDesc><langInfo><language>en</language><country>US</country></langInfo><name>ProductDesc</name><value>VMS Service|For Default Group, rental 0 SR per month(s), automatic renew.</value></ns1:productDesc></ns1:productDescs><ns1:parentID>0xxxxxxxxxx0</ns1:parentID><ns1:parentType>1</ns1:parentType><ns1:parentNames><ns1:parentName><langInfo><language>

Спойлер: ooredoo Oman Telecom api log.
[2024-02-19 14:40:15] [sync] [xxxxxxxxxxxxxxx84] ooredoo_oman.DEBUG: partnerRoleId: [["6921"]] []
[2024-02-19 14:40:15] [sync] [xxxxxxxxxxxxxxx84] ooredoo_oman.DEBUG: response: {"requestId":"xxxxxxxxxxx","code":"SUCCESS","inError":false,"message":"Request processed successfully","responseData":{}} [[]] []
[2024-02-19 15:10:09] [api] [xxxxxxxxxxxxxxx84] ooredoo_oman.DEBUG: send_otp_by_msisdn [{"msisdn":"968xxxxxxx4","service_connection_id":"3066","message":"","mt_id":""}] []
[2024-02-19 15:10:10] [api] [xxxxxxxxxxxxxxx84] ooredoo_oman.DEBUG: send_pin_url [["
https://ooma.xxxxxx.xxxxx/xxxx/external/v3/subscription/xxxxx/xxxxxx

"]] []
[2024-02-19 15:10:10] [api] [xxxxxxxxxxxxxxx84] ooredoo_oman.DEBUG: header [["Content-Type: application/json","apikey: exxxxxxxxxxxxxx54","authentication: zxxxxxxxxxxxxxxLek=","external-tx-id: xxxxxxxxxx.xxxxxxx"]] []

All transactions should be done here. If you're interested, just PM me. I'm moving forward.
 

Back
Top