Page 1 of 2 12 LastLast
Results 1 to 10 of 18

Thread: How and why the forums were "hacked"

  1. #1
    FLAC
    Join Date
    Jan 2001
    Posts
    1,612

    How and why the forums were "hacked"

    Well, the how part is fairly simple, there are several vulnerabilities in vbulletin and php that allow you to executes malicious commands (such as upping your user status to admin).

    What happened was that the 'hacker' (a.k.a. script kiddie) deleted all of the admin users (Aaron, MooN, and Zip-Lock) and the Moderators (Skippman) leaving the forums in the wrong hands.

    Fortunately, he deleted the 'forum index' (the part of the MySQL DB that contains forum name and description) instead of deleting some 70,000 posts.

    Also all of the private messages sent on or before Sept 6 were lost due to the hacker. In the aftermath, I had to drop all of the custom avatars to allow new ones to work. (if you lost your avatar and don't have a backup LMK and i'll look in the old DB file and see if I can find it.)

    Now I can't elaborate on the how I fixed it part because I used several flaws in the server configuration to gain access to the MySQL database.

    I'm sure I missed several details in this message.


    Discuss if you want.... just don't flame each other.

  2. #2
    Variable Bitrate
    Join Date
    Jul 2000
    Location
    Jackson, MS, USA
    Posts
    233
    Have the vulnerabilities been fixed so that this can't happen again?
    24 y/o w/ Silver/Red
    2000 Honda S2000

    http://www.squeezer.net

  3. #3
    FLAC
    Join Date
    Jan 2001
    Posts
    1,612
    Originally posted by Squeezer
    Have the vulnerabilities been fixed so that this can't happen again?
    to my knowledge they have been.

  4. #4
    Maximum Bitrate
    Join Date
    Jun 2001
    Location
    Boise, ID (USA)
    Posts
    551
    Can you give us a name and address so we can go beat him silly?

  5. #5
    FLAC
    Join Date
    Jan 2001
    Posts
    1,612
    I don't imagine you guys would want to travel to belgium

  6. #6
    Maximum Bitrate 00CericaRuss's Avatar
    Join Date
    Jul 2002
    Location
    San Rafael, CA, USA
    Posts
    682
    that's what i figured happened... remember kids.. keep your software up to date!

  7. #7
    Maximum Bitrate Skippman's Avatar
    Join Date
    Mar 2002
    Location
    St. Louis, MO
    Posts
    762
    Well send Felix after him, he's in the neighborhood.
    Stereo:Alpine IVA-D900 Head Unit | Alpine PXA-H510 DSP | Boston Pro Component Speakers Upfront | Boston Rally Rear Speakers | 2 Polk 10" Subs in the Trunk | Phoenix Gold Ti900.7 Amp

  8. #8
    FLAC
    Join Date
    Jan 2001
    Posts
    1,612
    Originally posted by Skippman
    Well send Felix after him, he's in the neighborhood.

    Good Point *Evil Laugh*

  9. #9
    Variable Bitrate Stine161's Avatar
    Join Date
    Apr 2002
    Location
    Alberta Canada
    Posts
    233
    lol maybe you could post his IP and we could hack him

    just kiddin :P

  10. #10
    Rob
    Rob is offline
    Maximum Bitrate Rob's Avatar
    Join Date
    Aug 2001
    Location
    Missing In Action
    Posts
    779

    Re: How and why the forums were "hacked"

    Originally posted by bgoodman
    How and why the forums were "hacked"
    In your post you covered the how, but not the why, do you know if there was a reason behind the attack? and if so why?

    :edit: spelling error
    And you say people actually pay money for M$ Windows?
    www.mp3mini.co.uk (Does what it says on the URL) www.openclassic.co.uk (The new car, with zero rust!) www.rob-web.co.uk (My other site)
    Total re-design underway: on the whole progress is very slow as the car is taking up too much time :)

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •