Someone Hacked My Forums :(

eliotmateliotmat Join Date: 2002-12-01 Member: 10350Members, Reinforced - Shadow
<div class="IPBDescription">Possibly same person that did these?</div> Someone recently hacked into my forums and deleted my account.

So, if anyone has a list of the names/IPs suspected of corrupting these I would like to cross-reference mine with them.

I hate to be accusational, but the culprit is probably the same person/group who hacked these forums because these boards are the only place you'll find my eEnemies.

If anyone has any info please PM me as soon as possible.

<!--emo&::asrifle::--><img src='http://www.unknownworlds.com/forums/html/emoticons/asrifle.gif' border='0' style='vertical-align:middle' alt='asrifle.gif' /><!--endemo--> -->meanies<--

Comments

  • CommunistWithAGunCommunistWithAGun Local Propaganda Guy Join Date: 2003-04-30 Member: 15953Members
    How did they hack your forums? Are you sure they didn't just find an exploit on the web?
  • eliotmateliotmat Join Date: 2002-12-01 Member: 10350Members, Reinforced - Shadow
    <!--QuoteBegin-CommunistWithAGun+Jul 9 2005, 11:54 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (CommunistWithAGun @ Jul 9 2005, 11:54 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> How did they hack your forums? Are you sure they didn't just find an exploit on the web? <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Whether you want to call it an exploit or hack, someone was able to invade my forums and corrupt the site admin account.
  • GiGaBiTeGiGaBiTe Join Date: 2003-10-07 Member: 21489Members
    its good to have more than one super administrator account in case something like this happens. you should also discuise the 2nd account to look like a normal account thats rarely used.

    if you can manipulate mysql tables, you might be able to recover the corrupted account, otherwise you will probably have to reinstall the board, i hope you made backups...
  • Splinter_SteveSplinter_Steve Join Date: 2005-03-20 Member: 45881Members
    They simply screwed up your admin rather than destroy the whole forum, so if it was hax then someone wanted to keep it personal at least...although being anonymous kind of contradicts that...people who do these things are morons with too much time anyways. I wouldn't have even given them the satisfaction of making this topic to read, really.

    And you're SURE it wasn't something you did? Or if you left an easy to guess password or something...
  • eliotmateliotmat Join Date: 2002-12-01 Member: 10350Members, Reinforced - Shadow
    edited July 2005
    <!--QuoteBegin-Splinter Steve?+Jul 9 2005, 02:03 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Splinter Steve? @ Jul 9 2005, 02:03 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> They simply screwed up your admin rather than destroy the whole forum, so if it was hax then someone wanted to keep it personal at least...although being anonymous kind of contradicts that...people who do these things are morons with too much time anyways.  I wouldn't have even given them the satisfaction of making this topic to read, really.

    And you're SURE it wasn't something you did?  Or if you left an easy to guess password or something... <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    I haven't used any admin features in weeks. I've only read/replied posts.

    I have other master admins, but I was the "site admin". I'm not sure if there were any features that a site admin would have that a master admin wouldn't.

    edit: Now that I think about it. Someone destroyed my account on modns forums recently too, but Depot fixed me back up.

    Why doesn't this community like one of its advocates?
  • DepotDepot The ModFather Join Date: 2002-11-09 Member: 7956Members
    edited July 2005
    <!--QuoteBegin-GiGaBiTe+Jul 9 2005, 02:15 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (GiGaBiTe @ Jul 9 2005, 02:15 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> its good to have more than one super administrator account in case something like this happens. you should also discuise the 2nd account to look like a normal account thats rarely used. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    How do you disguise the second account? With IB you'd have to assign them to a recognizeable group e.g. Forum Admins.

    <!--QuoteBegin-eliotmat Jul 9 2005+ 03:45 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (eliotmat Jul 9 2005 @ 03:45 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->

    edit: Now that I think about it. Someone destroyed my account on modns forums recently too, but Depot fixed me back up.<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    I doubt this was related to your problem on modNS.org Forums eliotmat. For some odd reason you couldn't access your account, and you were not restricted whatsoever. <!--emo&???--><img src='http://www.unknownworlds.com/forums/html/emoticons/confused-fix.gif' border='0' style='vertical-align:middle' alt='confused-fix.gif' /><!--endemo-->
  • Viper_two_nine_AViper_two_nine_A Join Date: 2004-09-29 Member: 31989Members
    using phpbb? there recently was an important update i think 2.0.16 or sth like that
  • eliotmateliotmat Join Date: 2002-12-01 Member: 10350Members, Reinforced - Shadow
    <!--QuoteBegin-Viper two nine A+Jul 9 2005, 04:12 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Viper two nine A @ Jul 9 2005, 04:12 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> using phpbb? there recently was an important update i think 2.0.16 or sth like that <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Thanks, Viper. I'm going to see about updating it tonight.
  • CommunistWithAGunCommunistWithAGun Local Propaganda Guy Join Date: 2003-04-30 Member: 15953Members
  • 2_of_Eight2_of_Eight Join Date: 2003-08-20 Member: 20016Members
    <!--QuoteBegin-CommunistWithAGun+Jul 9 2005, 05:37 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (CommunistWithAGun @ Jul 9 2005, 05:37 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Get an IP logged? <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Yes, and he's asking whoever knows the IP of the hacker from <i>these</i> forums to cross-check.
  • DepotDepot The ModFather Join Date: 2002-11-09 Member: 7956Members
    <!--QuoteBegin-eliotmat+Jul 9 2005, 05:34 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (eliotmat @ Jul 9 2005, 05:34 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-Viper two nine A+Jul 9 2005, 04:12 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Viper two nine A @ Jul 9 2005, 04:12 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> using phpbb? there recently was an important update i think 2.0.16 or sth like that <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Thanks, Viper. I'm going to see about updating it tonight. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    And this raises another interesting question: <b>Given current updates have been applied, which forum is more secure, phpbb or InvisionBoard?</b>
  • SaltzBadSaltzBad Join Date: 2004-02-23 Member: 26833Members
    This just in, because its important breaking news : <b>Your mom hacked your forums.</b>
  • minskminsk Join Date: 2003-01-09 Member: 12077Members
    <!--QuoteBegin-Depot+Jul 10 2005, 10:30 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Depot @ Jul 10 2005, 10:30 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Given current updates have been applied, which forum is more secure, phpbb or InvisionBoard? <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    From the traffic on BugTraq, it really looks like some combination of PHPbb being worse and InvisionBord being less used. There are gaping holes in anything before PHPbb 2.0.16 or InvisionBoard 2.0.4.

    If you are using *any* PHP-based software go into the source and look for *at least* calls to eval and preg_replace with a /e modifier. Either convince yourself they are adequately protected, or get someone else to look at it. These are usually where breaks will occur, because the authors trust PHP's backslashification far too much.

    An easy example is GeekLog, which had a handfull of trivial preg_replace holes. They were "solved" in a newer version through a braindead hack that, among other things, makes it impossible to search for strings containing apostrophes. How hard is it for these people to simply URL-encode incoming strings? Good grief...
  • eliotmateliotmat Join Date: 2002-12-01 Member: 10350Members, Reinforced - Shadow
    <!--QuoteBegin-minsk+Jul 10 2005, 01:13 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (minsk @ Jul 10 2005, 01:13 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-Depot+Jul 10 2005, 10:30 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Depot @ Jul 10 2005, 10:30 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Given current updates have been applied, which forum is more secure, phpbb or InvisionBoard? <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    From the traffic on BugTraq, it really looks like some combination of PHPbb being worse and InvisionBord being less used. There are gaping holes in anything before PHPbb 2.0.16 or InvisionBoard 2.0.4.

    If you are using *any* PHP-based software go into the source and look for *at least* calls to eval and preg_replace with a /e modifier. Either convince yourself they are adequately protected, or get someone else to look at it. These are usually where breaks will occur, because the authors trust PHP's backslashification far too much.

    An easy example is GeekLog, which had a handfull of trivial preg_replace holes. They were "solved" in a newer version through a braindead hack that, among other things, makes it impossible to search for strings containing apostrophes. How hard is it for these people to simply URL-encode incoming strings? Good grief... <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    I wish I knew what any of that meant. <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin-fix.gif' border='0' style='vertical-align:middle' alt='biggrin-fix.gif' /><!--endemo-->
  • 2_of_Eight2_of_Eight Join Date: 2003-08-20 Member: 20016Members
    I'm with eliot <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html/emoticons/smile-fix.gif' border='0' style='vertical-align:middle' alt='smile-fix.gif' /><!--endemo-->
  • DepotDepot The ModFather Join Date: 2002-11-09 Member: 7956Members
    Well, he could have posted in a more user-friendly context. He probably assumes that if you're intelligent enough to install your own forums, you're smart enough to understand what he said. <!--emo&???--><img src='http://www.unknownworlds.com/forums/html/emoticons/confused-fix.gif' border='0' style='vertical-align:middle' alt='confused-fix.gif' /><!--endemo-->
  • GiGaBiTeGiGaBiTe Join Date: 2003-10-07 Member: 21489Members
    <!--QuoteBegin-Depot+Jul 9 2005, 02:54 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Depot @ Jul 9 2005, 02:54 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-GiGaBiTe+Jul 9 2005, 02:15 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (GiGaBiTe @ Jul 9 2005, 02:15 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> its good to have more than one super administrator account in case something like this happens. you should also discuise the 2nd account to look like a normal account thats rarely used. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    How do you disguise the second account? With IB you'd have to assign them to a recognizeable group e.g. Forum Admins.

    <!--QuoteBegin-eliotmat Jul 9 2005+ 03:45 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (eliotmat Jul 9 2005 @ 03:45 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->

    edit: Now that I think about it. Someone destroyed my account on modns forums recently too, but Depot fixed me back up.<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    I doubt this was related to your problem on modNS.org Forums eliotmat. For some odd reason you couldn't access your account, and you were not restricted whatsoever. <!--emo&???--><img src='http://www.unknownworlds.com/forums/html/emoticons/confused-fix.gif' border='0' style='vertical-align:middle' alt='confused-fix.gif' /><!--endemo--> <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    if your using ipb, you can create a group that looks just like members or whatnot, just add a space or something, then hide that group so people dont know its there.

    for phpbb, you can assign people priveleges without giving them a title of admin.

    its not really that hard.
  • minskminsk Join Date: 2003-01-09 Member: 12077Members
    <!--QuoteBegin-Depot+Jul 10 2005, 02:33 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Depot @ Jul 10 2005, 02:33 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->Well, he could have posted in a more user-friendly context. He probably assumes that if you're intelligent enough to install your own forums, you're smart enough to understand what he said.  <!--emo&???--><img src='http://www.unknownworlds.com/forums/html/emoticons/confused-fix.gif' border='0' style='vertical-align:middle' alt='confused-fix.gif' /><!--endemo--><!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    No, not really. I'm more cynical than that, hence the "or get someone else to look at it". Paragraph 3 is really a rant to developers.

    Explaining how the PHP security holes tend to occur in a way that is comprehensible to most people is a little, uhm, rough. Given a few lecture hours I would take a shot at it, but there are a <a href='http://www.ilovejackdaniels.com/php/writing-secure-php/' target='_blank'>lot of</a> <a href='http://www.onlamp.com/pub/a/php/2003/03/20/php_security.html' target='_blank'>other</a> <a href='http://forevergeek.com/programming/writing_secure_php.php' target='_blank'>discussions</a> around already, and I'm not teaching that course.

    A fairly common analogy is that software is like a car: there are a lot of underlying details that you really do not need to know about to operate it. Unfortunately, putting something on the Internet means you are inviting every criminal, whack-job and bot in the world to take a shot at breaking into it. Little errors, both on the part of the original developers and the site administrators *will* leave big holes. PHP (and similar) being easy unfortunately results in a lot of developers that have only half a clue about security; a lot of this code makes Microsoft look good. So, the site administrator needs to be more paranoid...

    (Quick example: GrokLaw, big pseudolegal blog. Was running a customized version of an outdated GeekLog, sysadmin had been too busy to dig through it. An appropriately mangled request could run arbitrary PHP code on the server.)

    If my rant gets one more person to actually think about the security (even in an "I have *no* idea what this means, I'd better get someone to help" way), it means just that many fewer zombies.

    And that was much longer than I originally intended, sorry.
  • DepotDepot The ModFather Join Date: 2002-11-09 Member: 7956Members
    Yeah np minsk, if I need more details I'll pm ya ... thanks.
Sign In or Register to comment.