|
|
Search
|
|||||||
| Home | Register | Downloads | FAQ | Members List | Calendar | Arcade | Mark Forums Read |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Emu author
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Nov 2002
Location: Austria (originally from Dominican Republic)
Posts: 2,381
|
Ok my forum got hacked lol
it seems like somebody with lots of free time on his hands managed to hack the forums and write some stupid text on it.. i hope admins of the CG can fix that. Here the link: http://aruantec.ngemu.com/forums/ Regards @ruantec
__________________
Current development tools: Visual C++.net, Visual C#.net Visual VB.net, Visual Webdeveloper.net Bloodshed Dev C++, Borland C++ Visual Basic 6 |
|
|
|
| Advertisement | [Remove Advertisement] | ||
|
|
|
|
#3 (permalink) |
|
AEON'S HERITAGE
![]() ![]() ![]() ![]() ![]() Join Date: Apr 2006
Location: Tamazgha
Posts: 2,042
|
Damn ... thats some serious **** out there :/
__________________
العرب بدو الفلاة، رعاة النوق اكتشفوا الصفر وظل لصيقاً بهم وفياً لهم حتى تمنوا التبرء منه وعيروني بالواحد الأحد 1 = Aothem, 0 = Thaothemth ^_^ | Markunda Princess of Tamazgha(^_^) | Tinariwen | General Emulation | Xtemulation | |
|
|
|
|
|
#5 (permalink) |
|
T-5000 Modenator
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Aug 2005
Location: Here, there, everywhere, even in your couch cushions..
Posts: 3,139
|
Seems like the permissions issue on the aruantec subdomain finally came back to bite them. When I was performing some work for @ruantec, I noticed that some/most/all of the files in the forum directory had improper permissions, it seems a hacker exploited this and hacked the forums. Either that or the hacker got in through another back door. When something like this happens it needs to be figured out exactly what they exploited, fix the issue that was exploited, re-upload all files and a database backup from before it was hacked. However @ruantec can't re-upload the files unless he has FTP access. In order to fix this he needs FTP access so he can set proper permissions on the files and patch up the holes. From what I could gather, the aruantec forum was using Mybb 1.4.2. Since then a security audit was done on Mybb 1.4.x and some security issues fixed in the later versions of Mybb 1.4.x. It could of been either of those things or an unknown backdoor that was exploited by these low life scumbags.
__________________
![]() | Xtemulation Forums | Dolphin SVN Builds | | XTemulation Wiki | PCSX2 SVN Builds | Download the free Xtemulation Toolbar If you like Xtemulation, please Digg Us |
|
|
|
|
|
#6 (permalink) | |
|
Emu author
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Nov 2002
Location: Austria (originally from Dominican Republic)
Posts: 2,381
|
Thanks God we moved the forums thanks to Xtreme2damax ![]() Quote:
__________________
Current development tools: Visual C++.net, Visual C#.net Visual VB.net, Visual Webdeveloper.net Bloodshed Dev C++, Borland C++ Visual Basic 6 |
|
|
|
|
|
|
#7 (permalink) | |
|
T-5000 Modenator
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Aug 2005
Location: Here, there, everywhere, even in your couch cushions..
Posts: 3,139
|
Quote:
Someone from CG might want to remove the affected page in question, find out how it was exploited, patch the issue and upload a backup from before the hack occurred. I hope these low life scumbag hackers get a taste of their own medicine some day, I hate idiots that get off on ruining others hard work, hacking and plastering their own crap up. We should start a movement to hack the flocking hackers. ![]() Hopefully they will see this thread upon browsing and take note of the problem, or an administrator can contact one of them. In fact I will contact one of them right now to take care of this.
__________________
![]() | Xtemulation Forums | Dolphin SVN Builds | | XTemulation Wiki | PCSX2 SVN Builds | Download the free Xtemulation Toolbar If you like Xtemulation, please Digg Us |
|
|
|
|
|
|
#8 (permalink) | |
|
Emu author
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Nov 2002
Location: Austria (originally from Dominican Republic)
Posts: 2,381
|
Quote:
__________________
Current development tools: Visual C++.net, Visual C#.net Visual VB.net, Visual Webdeveloper.net Bloodshed Dev C++, Borland C++ Visual Basic 6 |
|
|
|
|
|
|
#9 (permalink) | ||
|
Resident Baka
![]() ![]() ![]() ![]() Join Date: Dec 2008
Location: No where Now here
Posts: 875
|
Quote:
ahhh i love irony.
__________________
Quote:
|
||
|
|
|
|
|
#10 (permalink) |
|
T-5000 Modenator
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Aug 2005
Location: Here, there, everywhere, even in your couch cushions..
Posts: 3,139
|
It seems it was only the index page that was hacked as far as I could see. Other pages such as threads load normally, I was able to check since I had a couple threads bookmarked.
__________________
![]() | Xtemulation Forums | Dolphin SVN Builds | | XTemulation Wiki | PCSX2 SVN Builds | Download the free Xtemulation Toolbar If you like Xtemulation, please Digg Us |
|
|
|
|
|
#11 (permalink) | |
|
I tell you what.
![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Aug 2006
Location: Ohio, USA
Posts: 2,273
|
Quote:
__________________
Arrogance and ignorance go hand in hand
|
|
|
|
|
|
|
#13 (permalink) |
|
T-5000 Modenator
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Aug 2005
Location: Here, there, everywhere, even in your couch cushions..
Posts: 3,139
|
I just wanted to issue an update, I was able to log into the ACP here is what was done: Once I logged in, I viewed the administrative logs.. 1. Hacker was possibly able to delete some language files 2. Hacker was able to gain admin access, once in he/it/she modified the index template to the hacked page. 3. I'm not absolutely sure if any files were affected, it just seems like a lame index page/template hack. On second thought it seems the hacker was able to gain administrative access through some vulnerability, then proceeded to edit the index template for the forum and possibly change some other things in addition to modifying the index template. 4. Hacker is registered under the guise khodam, last user to register was khodam, and khodam was listed in the administrative logs as the one who modified the index template to the hacked page. Here is what I did: Banned the khodam account, in banning options both the hackers name "khodam", it's email address and IP address were banned in the ACP from being allowed to access the forum. I also ensured the account was no longer able to be logged into by changing the email and password. I then proceeded to restore the index page/template back to what it was originally. Index page is able to be loaded normally, not sure how much else was affected. The rest can be left up to the CG folks to patch up and fix this issue, I'm not sure if the hacker was able to gain access due to improper permissions on the files or if it was an SQL vulnerability exploit that allowed them to gain access. In any case after the vulnerability is patched, an upgrade on the Mybb install should be performed to bring it up to the latest version. Files and directories that are in need of write permissions: ![]() Permissions for other files may need to be tweaked as well. I can provide the IP address of the hacker as well if it is needed. May I also suggest changing the name of the admin directory to something more difficult to guess?
__________________
![]() | Xtemulation Forums | Dolphin SVN Builds | | XTemulation Wiki | PCSX2 SVN Builds | Download the free Xtemulation Toolbar If you like Xtemulation, please Digg Us Last edited by Xtreme2damax; July 1st, 2009 at 01:32.. |
|
|
|
|
|
#15 (permalink) | |
|
Behind ur girlfriend :D
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Feb 2006
Location: Sydney, Australia
Posts: 18,910
|
Quote:
__________________
![]() ![]() VBA-M | Xtemu | NGOHQ | Post Impact Productions | TNHW | XBCD 0.2.6 | Satanic666's Emulator Compiles Don't be a NOOB, READ THE NGEmu/EmuForums Rules of Conduct Need Help with ePSXe? This is your first stop!. If you don't post all the required information, you don't get help. Everytime someone posts a romsite, God kills a beautiful woman. |
|
|
|
|
|
|
#16 (permalink) |
|
T-5000 Modenator
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Aug 2005
Location: Here, there, everywhere, even in your couch cushions..
Posts: 3,139
|
Looks like I'll be upgrading a Mybb forum tonight. :o
__________________
![]() | Xtemulation Forums | Dolphin SVN Builds | | XTemulation Wiki | PCSX2 SVN Builds | Download the free Xtemulation Toolbar If you like Xtemulation, please Digg Us Last edited by Xtreme2damax; July 1st, 2009 at 02:14.. |
|
|
|
|
|
#18 (permalink) | |
|
Emu author
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Nov 2002
Location: Austria (originally from Dominican Republic)
Posts: 2,381
|
Quote:
Regards @ruantec
__________________
Current development tools: Visual C++.net, Visual C#.net Visual VB.net, Visual Webdeveloper.net Bloodshed Dev C++, Borland C++ Visual Basic 6 |
|
|
|
|
|
|
#20 (permalink) |
|
Emu author
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Join Date: Nov 2002
Location: Austria (originally from Dominican Republic)
Posts: 2,381
|
well as far as i know the hacker just changed the main file but didnīt deleted any data and now everything is there so i would say i just need a backup of today
__________________
Current development tools: Visual C++.net, Visual C#.net Visual VB.net, Visual Webdeveloper.net Bloodshed Dev C++, Borland C++ Visual Basic 6 |
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|