So Like, The Site Just Got Hacked Eh?

2

Comments

  • GigabaneGigabane Join Date: 2005-04-02 Member: 47263Members
    <!--QuoteBegin-daidalos+Jun 4 2005, 01:43 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (daidalos @ Jun 4 2005, 01:43 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Brute Force or Dictionary attack can't be called hacking, really. A cracker uses brute force if he really don't know anymore how he can hack a server. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Im glad that someone else picked up on it.
    It's hardly hacking, he's basically just being a script kiddie.
    Brute forcing = The easiest thing in the world.

    To be honesty Im a little disapointed at the forum staff that they didnt notice that.
    To brute force something like a forum password should take quite a while (Unelss the password is like "aaa")

    The stress it should of caused on the servers should of been a big enough red flag, let alone the logs must of been going nuts.

    Im curious to ask though, how long was he brute forcing for? And did anyone notice the boards going extremely slow while it was going on?

    Also, did he mask his ip? If not there legal action the staff can be taking.
  • eliotmateliotmat Join Date: 2002-12-01 Member: 10350Members, Reinforced - Shadow
    It would have been nice had the hacker changed properties to allow public viewing of the constellation forums.
  • YashYash Join Date: 2004-09-07 Member: 31501Members, Constellation
    Lol man, you're not missing out on anything, we know as much as you guys do.

    =/
  • ProfLiebstromProfLiebstrom Join Date: 2004-09-04 Member: 31292Members, Constellation
    <!--QuoteBegin-Yash+Jun 5 2005, 02:38 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Yash @ Jun 5 2005, 02:38 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Lol man, you're not missing out on anything, we know as much as you guys do.

    =/ <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Good work vash making them think we know nothing <!--emo&;)--><img src='http://www.unknownworlds.com/forums/html/emoticons/wink-fix.gif' border='0' style='vertical-align:middle' alt='wink-fix.gif' /><!--endemo-->
  • YashYash Join Date: 2004-09-07 Member: 31501Members, Constellation
    edited June 2005
    <!--QuoteBegin-ProfLiebstrom+Jun 4 2005, 10:45 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (ProfLiebstrom @ Jun 4 2005, 10:45 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--><!--QuoteBegin-Yash+Jun 5 2005, 02:38 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Yash @ Jun 5 2005, 02:38 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Lol man, you're not missing out on anything, we know as much as you guys do.

    =/ <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Good work vash making them think we know nothing <!--emo&;)--><img src='http://www.unknownworlds.com/forums/html/emoticons/wink-fix.gif' border='0' style='vertical-align:middle' alt='wink-fix.gif' /><!--endemo--><!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Shh!!


    <span style='font-size:8pt;line-height:100%'>I'm not Vash... <!--emo&:(--><img src='http://www.unknownworlds.com/forums/html/emoticons/sad-fix.gif' border='0' style='vertical-align:middle' alt='sad-fix.gif' /><!--endemo--></span>
  • locallyunscenelocallyunscene Feeder of Trolls Join Date: 2002-12-25 Member: 11528Members, Constellation
    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->That's impossible
    For that to happen, Nexus
    Would have to exist <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->


    haiku post?
  • urinalcakeurinalcake Can&#39;t work a sound card United States Join Date: 2002-11-08 Member: 7799Members
    great, pjs got me on a rhyme
    so now i have to waste some time
    talking about how much we love
    not to see forces above
    come crashing down on our great place
    in which we've made our own base.

    love ns we do
    oh, so why must you
    ruin it too?

    dont hack our lovely forums
    or there be less quorum
    to decide the fate of the force
    that will become, NS source
  • Asal_The_UnforgivingAsal_The_Unforgiving Join Date: 2003-03-26 Member: 14903Members
    Oh, what dark recesses of the mind
    Would create such a monster
    that in their heart they yearn
    To destroy that which others cherish.

    The light of true men may yet shine through
    But first must mind and heart entwine
    To create in one what must be echoed
    A peace of self, to flow and grow.

    Such peace will find a home in all minds,
    And in such growth, strengthen the resolve of all those
    True to the reasons of that to which they hold.

    And by being such a thing,
    The NS community is a world all its own.





    ....because I can. It sucks, but why not?
  • PetcoPetco Join Date: 2003-07-27 Member: 18478Members, Constellation
    edited June 2005
    <!--QuoteBegin-ProfLiebstrom+Jun 4 2005, 07:45 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (ProfLiebstrom @ Jun 4 2005, 07:45 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-Yash+Jun 5 2005, 02:38 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Yash @ Jun 5 2005, 02:38 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Lol man, you're not missing out on anything, we know as much as you guys do.

    =/ <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Good work vash making them think we know nothing <!--emo&;)--><img src='http://www.unknownworlds.com/forums/html/emoticons/wink-fix.gif' border='0' style='vertical-align:middle' alt='wink-fix.gif' /><!--endemo--> <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Yeah, they must not know of the "Supar sekrat gore gee land" in the constellation forums!

    Oh yeah the Dev forums are revealed!
    <img src='http://img190.exs.cx/img190/2739/devforumrevealed5tx.jpg' border='0' alt='user posted image' />
  • SkySky Join Date: 2004-04-23 Member: 28131Members
    <!--QuoteBegin-locallyunscene+Jun 4 2005, 11:49 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (locallyunscene @ Jun 4 2005, 11:49 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->That's impossible
    For that to happen, Nexus
    Would have to exist <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->


    haiku post? <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    You're just picking up on this?
  • FromThisSoilFromThisSoil Join Date: 2004-08-24 Member: 30859Members, Constellation
    <!--QuoteBegin-TychoCelchuuu+Jun 4 2005, 01:07 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (TychoCelchuuu @ Jun 4 2005, 01:07 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-surprise+Jun 4 2005, 09:44 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (surprise @ Jun 4 2005, 09:44 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> he knows what the nexus is  <!--emo&:0--><img src='http://www.unknownworlds.com/forums/html/emoticons/wow.gif' border='0' style='vertical-align:middle' alt='wow.gif' /><!--endemo--> <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    That's impossible
    For that to happen, Nexus
    Would have to exist <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    What is this? NS haiku?
  • FromThisSoilFromThisSoil Join Date: 2004-08-24 Member: 30859Members, Constellation
    <!--QuoteBegin-daidalos+Jun 4 2005, 12:41 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (daidalos @ Jun 4 2005, 12:41 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Well, that's not exactly what I've meant. Let's pretend there is a corporation who develops a completly new project, like a game, someone hacks their server and gets the sources etc. and delete them. The corporation would lose very much money. But you don't have to steal it, you can just steal the idea.
    Since Natural Selection is free, it wouldn't work. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    If this pretend company keeps one copy of their source on one computer which is always connected to the internet....they deserve to lose money.
  • CageyCagey Ex-Unknown Worlds Programmer Join Date: 2002-11-15 Member: 8829Members, Retired Developer, NS1 Playtester, Constellation
    edited June 2005
    <!--QuoteBegin-Gigabane+Jun 4 2005, 06:10 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Gigabane @ Jun 4 2005, 06:10 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--><!--QuoteBegin-daidalos+Jun 4 2005, 01:43 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (daidalos @ Jun 4 2005, 01:43 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Brute Force or Dictionary attack can't be called hacking, really. A cracker uses brute force if he really don't know anymore how he can hack a server. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Im glad that someone else picked up on it.
    It's hardly hacking, he's basically just being a script kiddie.
    Brute forcing = The easiest thing in the world.
    <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Yeah, that's why I put hacked in quotes in the site outage announcement... I didn't find out it was a simple brute force until I looked at the logs this morning; I decided to sleep rather than troubleshoot while exhausted and stressed.

    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->To be honesty Im a little disapointed at the forum staff that they didnt notice that.
    To brute force something like a forum password should take quite a while (Unelss the password is like "aaa")

    The stress it should of caused on the servers should of been a big enough red flag, let alone the logs must of been going nuts.

    Im curious to ask though, how long was he brute forcing for? And did anyone notice the boards going extremely slow while it was going on?<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->

    The traffic from his attempts was actually knocking down the server every three minutes (I have a software watchdog that was restarting it after each crash; I disabled the watchdog when I took the site down overnight). Unfortunately, I wasn't around at the time to notice the spike.

    I think it took about 60 minutes for him to guess the password--it must have been chronically weak, possibly a dictionary word (I haven't asked and don't care, and I forwarded instructions to get a strong password to the offending account). I've recommended a cap to consecutive failed logins with a timed reset to address the problem; if a system only allows a few missed attempts per day, the time required to force it becomes impractical.

    Since we're running the website on a single box, we're still subject to DDoS, but that's not going to change until there's economic incentive to scale up to multiple servers. We've gotten some offers for free hosting on other systems using a DNS round robin, but I think we want to keep things central for the time being.

    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->Also, did he mask his ip? If not there legal action the staff can be taking.<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->

    It appears he didn't... but he was using a Russian dialup service, and I really think that what he did isn't worth the effort of attempting to pursue him there. There was little (arguably no) economic damage done--it was more of a prank than a malicious attack; I think he was bored. If he had decided to delete a chunk of the forum posts or published items from the dev or moderator forums, I'd feel differently.

    <!--QuoteBegin-FromThisSoil+Jun 4 2005, 09:42 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (FromThisSoil @ Jun 4 2005, 09:42 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-TychoCelchuuu+Jun 4 2005, 01:07 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (TychoCelchuuu @ Jun 4 2005, 01:07 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-surprise+Jun 4 2005, 09:44 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (surprise @ Jun 4 2005, 09:44 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> he knows what the nexus is  <!--emo&:0--><img src='http://www.unknownworlds.com/forums/html/emoticons/wow.gif' border='0' style='vertical-align:middle' alt='wow.gif' /><!--endemo--> <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    That's impossible
    For that to happen, Nexus
    Would have to exist <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    What is this? NS haiku? <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    According to Off Topic, it's "Tyku".

    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->DID THEY STOLZ UR MEGAHURTZ?! <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    YES ITZ ALL GONE NOW.
  • DC_DarklingDC_Darkling Join Date: 2003-07-10 Member: 18068Members, Constellation, Squad Five Blue, Squad Five Silver
    Its not like some things can be helped.

    * if admins say there pw is good, but its not, you will never know
    * the latest DDoS attack (DRDoS) is so freaking overpowered that I never saw anything not down by it. (no counter there aswell)


    Also we indeed have nothing on the CM forums. After all, we all already know that CMs have building SOF/MT, right.
  • ikirikir Join Date: 2003-07-19 Member: 18265Members, Constellation, Reinforced - Gold
    <!--QuoteBegin-Garet Jax+Jun 4 2005, 04:38 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Garet Jax @ Jun 4 2005, 04:38 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> DID THEY STOLZ UR MEGAHURTZ?! <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    LOOOL!
  • Garet_JaxGaret_Jax Join Date: 2003-02-23 Member: 13870Members, Constellation
    <!--QuoteBegin-Yash+Jun 5 2005, 03:38 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Yash @ Jun 5 2005, 03:38 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> (RE: CM forums)

    Lol man, you're not missing out on anything, we know as much as you guys do.

    =/ <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Not true.

    Cagey has posted some stuff about Nexus (nothing concrete, but you can gleam some things from it).
  • GigabaneGigabane Join Date: 2005-04-02 Member: 47263Members
    Thank you verymuch Cagey, that literally answered all my questions and more.
    Glad to hear you've thrown in some better countermeasures as well, we're lucky he didnt do any serious damage to the forums with the temporary powers he had.
  • BadMouthBadMouth It ceases to be exclusive when you can have a custom member titl Join Date: 2004-05-21 Member: 28815Members
    wonders who comes up with the "infestation thing and nanites are enroute to fix the problem"...
  • urinalcakeurinalcake Can&#39;t work a sound card United States Join Date: 2002-11-08 Member: 7799Members
    Sounds like something Nem or Zunni would think of.
    I think DOOManiac set it as the topic on IRC.

    I still like my poem. <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin-fix.gif' border='0' style='vertical-align:middle' alt='biggrin-fix.gif' /><!--endemo-->
  • DepotDepot The ModFather Join Date: 2002-11-09 Member: 7956Members
    If I overlooked this Cagey I'm sorry, but how often do you perform backups of these forums?
  • coriscoris Join Date: 2003-07-08 Member: 18034Members, Constellation
  • CageyCagey Ex-Unknown Worlds Programmer Join Date: 2002-11-15 Member: 8829Members, Retired Developer, NS1 Playtester, Constellation
    edited June 2005
    <!--QuoteBegin-BadMouth+Jun 5 2005, 06:40 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (BadMouth @ Jun 5 2005, 06:40 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> wonders who comes up with the "infestation thing and nanites are enroute to fix the problem"... <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    I'm pretty sure it was Comprox who initially took the forums offline, so he probably created the message.

    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->Glad to hear you've thrown in some better countermeasures as well, we're lucky he didnt do any serious damage to the forums with the temporary powers he had. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    More accurate to say they're in the process of being thrown in--I don't believe they're active yet, but will be ASAP.

    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->If I overlooked this Cagey I'm sorry, but how often do you perform backups of these forums? <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Flayra wrote a backup script that runs every other day.
  • ZaggyZaggy NullPointerException The Netherlands Join Date: 2003-12-10 Member: 24214Forum Moderators, NS2 Playtester, Reinforced - Onos, Subnautica Playtester
    edited June 2005
    Heh, a lookup of "SanyaX" on google shows that this forum wasn't the only one hacked by this person.

    <a href='http://www.google.nl/search?hl=nl&q=sanyax&meta=' target='_blank'>Google search</a>
  • TheJimTheJim Join Date: 2005-01-09 Member: 34080Members, Constellation
    <!--QuoteBegin-Zaggy+Jun 6 2005, 08:00 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Zaggy @ Jun 6 2005, 08:00 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Heh, a lookup of "SanyaX" on google shows that this forum wasn't the only one hacked by this person.

    <a href='http://www.google.nl/search?hl=nl&q=sanyax&meta=' target='_blank'>Google search</a> <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    He enjoys his spare time lol

    I dont have time for anything other than the following:

    Work

    Natural selection

    Women

    Coffee

    Pizza

    Burgers

    Alcohol

    Don't have time for anything else... he must get really bored... perhaps he hasn't found a gd game to play shame he didn't take time to take up NS while waisting an hour attacking some forums <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html/emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo-->
  • [Deleted User][Deleted User] Join Date: 2003-11-28 Member: 23688
    pretty simple, hes a NERD.
  • CrispyCrispy Jaded GD Join Date: 2004-08-22 Member: 30793Members, Constellation
    Please, don't tarnish the good name of NERD with his inclusion.
  • CheeseCheese Lork on the Clorf Join Date: 2003-12-15 Member: 24396Members, Constellation
    i blame this guy for not telling us everything about Nexus in General Disscussions!

    SHAME ON YOU Mr. Hacker!!11!! WE WANT TO FINALLY KNOW
  • ZaggyZaggy NullPointerException The Netherlands Join Date: 2003-12-10 Member: 24214Forum Moderators, NS2 Playtester, Reinforced - Onos, Subnautica Playtester
    <!--QuoteBegin-Cheese+Jun 6 2005, 04:35 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Cheese @ Jun 6 2005, 04:35 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> i blame this guy for not telling us everything about Nexus in General Disscussions!

    SHAME ON YOU Mr. Hacker!!11!! WE WANT TO FINALLY KNOW <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Yep, bring on the good stuff !

    Full training map for noobs, stats system.
  • Steel_TrollSteel_Troll Join Date: 2004-02-12 Member: 26455Members
    <b>N</b>o <b>O</b>ne <b>E</b>ver <b>R</b>ealy <b>D</b>ies
  • SLizerSLizer Join Date: 2003-11-07 Member: 22363Members, Constellation
    W0w we got raped ^__^ 2 gorges for it <!--emo&::gorge::--><img src='http://www.unknownworlds.com/forums/html/emoticons/pudgy.gif' border='0' style='vertical-align:middle' alt='pudgy.gif' /><!--endemo--> <!--emo&::gorge::--><img src='http://www.unknownworlds.com/forums/html/emoticons/pudgy.gif' border='0' style='vertical-align:middle' alt='pudgy.gif' /><!--endemo-->
Sign In or Register to comment.