I found a way to inject bash commands on realstresser.com. I used it to dump the website and the database.
They quickly removed my PHP backdoor that I put and "fixed" (disabled) the exploit.
Here's what the leak contains:
- realstresser.sql : the whole database, passwords are hashed with...