Please login or register.

Login with username, password and session length
 

News:

Don't forget you can find us in #soldat.forums on the Quakenet IRC server.
A large portion of the community is on IRC, including many clans, server channels, and the popular Soldat Gather!
Don't know how to use IRC, or have no clue about what the hell i'm talking about? Try this link: http://wiki.soldat.nl/IRC_tutorial

Forum Misc Forum News and Support
Topic:
Q: zomg did the forums get pwned?
Pages: [1] 2 3  All

Author Topic: Q: zomg did the forums get pwned?  (Read 10314 times)

0 Members and 1 Guest are viewing this topic.

FliesLikeABrick

  • Administrator
  • Flamebow Warrior
  • *****
  • Offline Offline
  • Posts: 5957
    • WWW
Q: zomg did the forums get pwned?
« on: August 15, 2007, 10:47:40 am »
A: Yes. 

Q: Do you know how?
A: Not exactly

Q: Do you intend to find out
A: Yes

Q: Do you have ideas?
A: yes

Q: What is to keep them from doing it again, since you just put the forums back without making any changes?
A: Nothing.

Q: What can I do?
A: Be patient, don't bother me.  If you want information, watch this thread or come to #soldat.forums on quakenet.


Q: What backup did you restore from?
A: I was able to restore from a backup approximately 5 hours old.  Some posts and recent changes were lost, but overall this is a very good restore point, few forums that are compromised have such a recent restore point.
« Last Edit: August 15, 2007, 12:18:17 pm by FliesLikeABrick »
Logged

blackdevil0742

  • Veteran
  • *****
  • Offline Offline
  • Posts: 1061
  • Don't Panic
Re: Q: zomg did the forums get pwned?
« Reply #1 on: August 15, 2007, 10:51:03 am »
Q: Is like the last time where you adviced us to change password(s)?
Logged


OBEY!!!

Spasm

  • Soldier
  • **
  • Offline Offline
  • Posts: 241
  • Elite CTF Owner
    • WWW
Re: Q: zomg did the forums get pwned?
« Reply #2 on: August 15, 2007, 10:54:21 am »
 >:(  We need Battle Eye for the forums now
Logged

Owner/Founder- Elite CTF -  http://elitectf.com
OwnedVision - http://ownedvision.com
--An EliteCTF Production.
Snipe & Slice - Saw & Law - One Shots

swebonny

  • Camper
  • ***
  • Offline Offline
  • Posts: 277
  • BUahh...
Re: Q: zomg did the forums get pwned?
« Reply #3 on: August 15, 2007, 10:55:44 am »
But the good this is that itīs back :D
Logged

DePhille

  • Flagrunner
  • ****
  • Offline Offline
  • Posts: 623
  • SoldatPage Webmaster
    • WWW
Re: Q: zomg did the forums get pwned?
« Reply #4 on: August 15, 2007, 11:04:19 am »
Thanks for restoring them.
Hope we find the cause soon.
Logged

miketh2005

  • Flagrunner
  • ****
  • Offline Offline
  • Posts: 624
  • Why aren't leechers banned? Cause they don't post!
Re: Q: zomg did the forums get pwned?
« Reply #5 on: August 15, 2007, 11:13:58 am »
HACKERS
Logged

Sign up at our forums: www.soldatboards.com
Servers:
|Fu| Race: 69.65.34.137:23075  - 10 Slots
|Fu| eXtreme Zombies: 69.65.34.137:23073  - 12 Slots

XFactor Soldat Servers 49c /player 24/7 Uptime+Super Fast - 6 locations! GREAT ping! Click here!
My servers are hosted with them.

Iron Man

  • Soldier
  • **
  • Offline Offline
  • Posts: 224
Re: Q: zomg did the forums get pwned?
« Reply #6 on: August 15, 2007, 11:19:35 am »
yeah, i think it rolled back because i posted, someone else posted, and now both posts are gone..
Logged

mar77a

  • Global Moderator
  • Veteran
  • *****
  • Offline Offline
  • Posts: 1292
  • mad
    • WWW
Re: Q: zomg did the forums get pwned?
« Reply #7 on: August 15, 2007, 11:23:56 am »
take them down until you find out where the vulnerability is

andrelie

  • Camper
  • ***
  • Offline Offline
  • Posts: 384
  • Im sorry for the spamming...
Re: Q: zomg did the forums get pwned?
« Reply #8 on: August 15, 2007, 11:24:24 am »
im scared :(
Logged

Im sorry for the spamming...

DePhille

  • Flagrunner
  • ****
  • Offline Offline
  • Posts: 623
  • SoldatPage Webmaster
    • WWW
Re: Q: zomg did the forums get pwned?
« Reply #9 on: August 15, 2007, 11:58:01 am »
take them down until you find out where the vulnerability is
Chakra's password I think. It has been changed so don't worry.
Logged

blackdevil0742

  • Veteran
  • *****
  • Offline Offline
  • Posts: 1061
  • Don't Panic
Re: Q: zomg did the forums get pwned?
« Reply #10 on: August 15, 2007, 12:05:13 pm »
Yeah he was the only one online except an other fella that had member color on users online.
Logged


OBEY!!!

FliesLikeABrick

  • Administrator
  • Flamebow Warrior
  • *****
  • Offline Offline
  • Posts: 5957
    • WWW
Re: Q: zomg did the forums get pwned?
« Reply #11 on: August 15, 2007, 12:13:41 pm »
I don't want to take it down until the problem is found, that gains very little.  Regardless of whether I take it down or leave it up and it gets screwed again, posts would be lost or never occur at all.  At least if I leave it up, it lets me more easily look into what happened.

I believe the problem was Chakra's password, I have yet to look into the logs at all because I'm at work and busy. 

Yes, everyone please change your passwords ASAP.  It is more than likely that whoever compromised the forums took a database snapshot (I'll be able to look up if he did), and therefore has all of the password hashes... but the way that SMF stores passwords is quite good.  It isn't critical that you change your password unless you're a mod/admin/beta tester.  I still recommend you do, as it is a good practice for when things like this happen.

I might not be able to look into this until later today/tonight, but I'll post any information about what I find here, unless I think it is a danger to the forums or will give the kiddie who did this any kind of advantage.
« Last Edit: August 15, 2007, 12:16:42 pm by FliesLikeABrick »
Logged

Daimarus

  • Soldier
  • **
  • Offline Offline
  • Posts: 136
  • Believe me, I can kill you with my Spas...
    • WWW
Re: Q: zomg did the forums get pwned?
« Reply #12 on: August 15, 2007, 12:29:55 pm »
FLAB, I know some about hacking, but a little about hacking forums.

I think that they may OWN* forums in at least 2 simple ways:

1) Bruteforce'ing the password - Even old BrutusA2 can do that...
2) Cookie-Stealing - Admin may get on ANY site and he may "catch" the bad code, that will steal cookies from SoldatForums and e.g. send them on FTP server. I did that method once on test forums. It works as good as bruteforce'ing, but takes less time.

You cannot defend by any of those methods, except making a limit of logins per 1 minute (anti-bruteforce) and not-opening any links from people (impossible xD)


*- Owning a forum/site means taking control or wrecking the forum/site. In simple words xD
Logged

My SPAS-12 doesn't like most of people. He can mistakenly shoot your brain out of your head and splash it on the nearest wall.

andrelie

  • Camper
  • ***
  • Offline Offline
  • Posts: 384
  • Im sorry for the spamming...
Re: Q: zomg did the forums get pwned?
« Reply #13 on: August 15, 2007, 12:34:04 pm »
what will happen to the people that did this?
Logged

Im sorry for the spamming...

Flamiex

  • Major(1)
  • Offline Offline
  • Posts: 22
Re: Q: zomg did the forums get pwned?
« Reply #14 on: August 15, 2007, 12:34:19 pm »
Cookie-Stealing will not work on today's standard of forums, the cookie only contains your session id which is linked with your ip/browser/other information sent from your pc, so it wont let you use a session id on a different PC.

but anyway, I suggest you upgrade the forums to the latest version...
Logged

Dark Jesus

  • Soldier
  • **
  • Offline Offline
  • Posts: 158
Re: Q: zomg did the forums get pwned?
« Reply #15 on: August 15, 2007, 12:41:24 pm »
What had happened?

DePhille

  • Flagrunner
  • ****
  • Offline Offline
  • Posts: 623
  • SoldatPage Webmaster
    • WWW
Re: Q: zomg did the forums get pwned?
« Reply #16 on: August 15, 2007, 12:56:43 pm »
What had happened?

Someone deleted all the SoldatForums topics, members, style, ...
We do not know exactly or forsure how this happened but most likely someone was able to get into Chakra's account. The forums have been down for approximately 50-60 minutes. FliesLikeABrick used a back-up to restore the forum's content and we only lost 5 hours worth of post. So any posts that were made between 6AM(EST) and 11AM(EST) today (15th of August 2007) are gone.
FliesLikeABrick is currently trying to find out who is responsible for this.

Grtz, DePhille
Logged

FliesLikeABrick

  • Administrator
  • Flamebow Warrior
  • *****
  • Offline Offline
  • Posts: 5957
    • WWW
Re: Q: zomg did the forums get pwned?
« Reply #17 on: August 15, 2007, 12:59:46 pm »
I found out how they did it, and I have the IP of the person who did it.  If you have access to a large amount of login/user data on your sites and would like to try to look this up for me, send me a PM and I'll give you the IP.

LtKillroy

  • Flagrunner
  • ****
  • Offline Offline
  • Posts: 779
  • Killroy was here
Re: Q: zomg did the forums get pwned?
« Reply #18 on: August 15, 2007, 01:02:58 pm »
I found out how they did it, and I have the IP of the person who did it. If you have access to a large amount of login/user data on your sites and would like to try to look this up for me, send me a PM and I'll give you the IP.
Are you at the liberty of giving up the name, there is an army surplus store down the street and well... In all seriousness, can you keep this from happening again, I mean, who would want to hack a random forum for a small game?
Logged

L'audace, l'audace, toujours l'audace

..::HHH::..

  • Soldier
  • **
  • Offline Offline
  • Posts: 210
  • Dream Theater.. is the F**king best!
Re: Q: zomg did the forums get pwned?
« Reply #19 on: August 15, 2007, 01:04:37 pm »
i think you should tell us who did it.. so we can all hate him togetah..
Logged

Pages: [1] 2 3  All

 

Page created in 0.241 seconds with 21 queries.