|
Joined: Dec 1999
Posts: 158
Enthusiast
|
Enthusiast
Joined: Dec 1999
Posts: 158 |
it says []Hello there, your system got hacked. Fix your system instantly, before you're putting your website back. Some useful urls for you: www.net-security.orgsecunia.com www.zone-h.orgwww.securityfocus.comCheers, effdee[/] weird. lotsa 404´s, seems a little bit destrucive for "hackers". not good, I need a place to rant about bugs ...
|
|
|
|
Joined: Dec 1999
Posts: 158
Enthusiast
|
Enthusiast
Joined: Dec 1999
Posts: 158 |
damn, they´re quick!  Everything up and running again!
|
|
|
|
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
|
Admin Emeritus
Joined: Jan 2000
Posts: 5,073 |
Yes, we noticed shortly after the defacement. It was an automated thing. They just moved the site into another directory.
We're working on locating the actual method that he used. Rather, we know what he did, we're just not entirely sure how he was able to do it.
This does not appear to be a security issue with any of our products.
UBB.classic: Love it or hate it, it was mine.
|
|
|
|
Joined: Nov 2001
Posts: 10,369
I type Like navaho
|
I type Like navaho
Joined: Nov 2001
Posts: 10,369 |
I think alot of issues have been related to the phpBB and PHP thing. I've had some sites hacked (on Vertex Servers) - usually some message in russian or something. Hopefully now that school is back in session the script kiddies will have homework to do instead. 
|
|
|
|
Joined: Nov 2001
Posts: 10,369
I type Like navaho
|
I type Like navaho
Joined: Nov 2001
Posts: 10,369 |
Bah - shortly after hearing from navaho about this, we got hacked too  . Same thing, kind of harmless, they moved this whole site into a directory and made a new index page.
|
|
|
|
Joined: Jun 2001
Posts: 356
Junior Member
|
Junior Member
Joined: Jun 2001
Posts: 356 |
Is this anything to worry about for the rest of us?
|
|
|
|
Joined: Nov 2001
Posts: 10,369
I type Like navaho
|
I type Like navaho
Joined: Nov 2001
Posts: 10,369 |
No - I think somehow our FTP password here was comprimised, they had specificially logged into the web hosting control panel.
|
|
|
|
Joined: Jun 2001
Posts: 356
Junior Member
|
Junior Member
Joined: Jun 2001
Posts: 356 |
hmmmm, intresting. If anyone finds out how it got compromised, could you let us know? Would be intresting to know if it was a dictonary/bruteforce attack or something more cunning....
|
|
|
|
Joined: Nov 2001
Posts: 10,369
I type Like navaho
|
I type Like navaho
Joined: Nov 2001
Posts: 10,369 |
Yeah, still investigating. Navaho is a sharp cookie and helped solve it.
|
|
|
|
Joined: Oct 2000
Posts: 2,223
Veteran
|
Veteran
Joined: Oct 2000
Posts: 2,223 |
The "hacker" used a flaw in a piece of software (not .threads or anyting else Infopop produces) running on a customer's site that had a vulnerability posted earlier in the week. The customer had not yet updated and the "hacker" was allowed to upload a file he should not have been able to upload. As it happened the FTP password matched the MySQL password and all that he needed to do was read config.inc. Same for this site.
The vulnerability is one that existed but was fixed in threads long long ago. It didn't check file extensions properly and a .jpg.php file got by it's checks. The software in question, while good I'm sure, is no where as mature as .threads. As it gains in popularity it'll be subjected to the same things threads has been subjected to and I'm sure the author will do a fine job keeping it as secured as can be.
Moral of the story here - keep your software up to date and keep your passwords all different and difficult, when ever possible.
Picture perfect penmanship here.
|
|
|
|
Joined: Jun 2001
Posts: 356
Junior Member
|
Junior Member
Joined: Jun 2001
Posts: 356 |
Thanks for the headsup! I think I know what software we are talking about here....lol
|
|
|
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
|
|
Posts: 417
Joined: November 2001
|
|
Forums63
Topics37,575
Posts293,930
Members13,823
|
Most Online6,139 Sep 21st, 2024
|
|
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
|
|
|
|