Page 1 of 2

We have been hacked

Posted: Fri Nov 26, 2004 2:19 pm
by snoopdog
We had a nice little hacker stop by this morning and exploit some script. I am still looking into the problem so all i can do until i get some time is back up everything. Time is a thing i do not have alot of.

Posted: Fri Nov 26, 2004 7:09 pm
by snoopdog
I am finally going to update to the newest version of the BB as soon as everything is backed up. I expect this to take less than an hour but giving it an hour as worse case scenerio. I know i said this would be done months ago but since the BB was working fine i never messed with it. Anyway away with the old, in with the new. I expect this upgrade to be done by 8:30pm. If the BB says it is down then you know what is going on.

Posted: Fri Nov 26, 2004 7:47 pm
by admin
We are up to 2.11 phpBB now, which is the current release. Tomorrow morning i will getting 'everything else' working. What is not working is.

1) Attachments
2) Chatbox
3) Gallery
4) Statistics
5) Webmail

Now I know for sure that everyone wants the Gallery and Attachment mod back operational. BUT if no one uses the Chatbox and Statistic I would strongly suggest us not putting them back in there. Excess scripts are just another way for a hacker to get back into our BBS. I will leave it to you guys though, give me some feedback. I will start again in the morning and get our Webmail, Attachments and Gallery operational.

Posted: Fri Nov 26, 2004 8:33 pm
by ShagMan
yeah, noticed the /index.php wasn't working... the subforums were working tho!

Posted: Fri Nov 26, 2004 8:35 pm
by snoopdog
Yeah he was not worried about alot of stuff. I guess he was just making a point, which is fine. I needed updating anyway.

Posted: Fri Nov 26, 2004 8:42 pm
by snoopdog
Wow, i guess i am flattered. They have hacked over 6k web pages here is there website.

http://www.zone-h.com/en/defacements/fi ... r=un-root/

We are not on the cover yet but look at all of the ones that when you click still say un-root. I doubt anyone is fully protected against this guy. I can at least say i had ours back up and running in a few hours. The other hundred hacked today are still back up which leads me to believe they did not have a backup or did not make there pages themselves.

Posted: Fri Nov 26, 2004 9:09 pm
by snoopdog
BTW anyone having problems staying logged in do this.

Delete all of your browser cache, ALL of it.
Delete all of your cookies...ALL of it.

Close all of your browsers, log in and close you browser again.

Open your browser and you should be logged in with your credentials retained.

Posted: Fri Nov 26, 2004 9:10 pm
by Jahdiel
I for one don't mind if the chat is left out, tried it and it got frustrating that night anyways. Could be because the captain was by my side :? And as for the stats, sorry, but that does not teach me anything about reef keeping. Sorry if I offend anyone, just my personal opinion.

Posted: Fri Nov 26, 2004 9:18 pm
by snoopdog
Ahh Captains, woman after my own heart. I can say that stuff will be my downfall. On a good note our redirects are picking up, I guess the webcrawlers are finally finding us. While i was looking at the raw logs tonight i noticed that www.bet.com is even spidering to find stuff about snoopdog on our site.

Image

Posted: Sat Nov 27, 2004 6:39 am
by KrazyPlace
Snoop, wasn't BET your original goal anyways? :lol:

The chat isn't used by anyone... I think. The stats are intresting, but I agree with Karen... not really needed.

BTW... how do I get back into my gallery? My username and password quit working a few months back.

Posted: Sat Nov 27, 2004 7:22 am
by Phisher
Nice job rooting it out Snoop.

Joe

Posted: Sat Nov 27, 2004 9:25 am
by ShagMan
I personally enjoyed the stats page... but if it's a security hole, it's gotta go :)

Posted: Sat Nov 27, 2004 9:31 am
by snoopdog
You need to just PM me with what you want your password to be. When we upgraded Gallery, it did not retain some of the information.

Posted: Sat Nov 27, 2004 11:33 am
by snoopdog
<------------------ Attachment mod test ------------------->

Posted: Sat Nov 27, 2004 12:14 pm
by snoopdog
Ok the webmail icon is back, remember the proper format is

Login: snoopdog@mbrk.com
Password: XXXXXX

The attachment mod is back kicking agagin. The gallery icon is back now.