Author Topic: Q: zomg did the forums get pwned?  (Read 17251 times)

0 Members and 3 Guests are viewing this topic.

Offline FliesLikeABrick

  • Administrator
  • Flamebow Warrior
  • *****
  • Posts: 6144
    • Ultimate 13 Soldat
Q: zomg did the forums get pwned?
« on: August 15, 2007, 10:47:40 am »
A: Yes. 

Q: Do you know how?
A: Not exactly

Q: Do you intend to find out
A: Yes

Q: Do you have ideas?
A: yes

Q: What is to keep them from doing it again, since you just put the forums back without making any changes?
A: Nothing.

Q: What can I do?
A: Be patient, don't bother me.  If you want information, watch this thread or come to #soldat.forums on quakenet.


Q: What backup did you restore from?
A: I was able to restore from a backup approximately 5 hours old.  Some posts and recent changes were lost, but overall this is a very good restore point, few forums that are compromised have such a recent restore point.
« Last Edit: August 15, 2007, 12:18:17 pm by FliesLikeABrick »

Offline blackdevil0742

  • Veteran
  • *****
  • Posts: 1061
  • Don't Panic
Re: Q: zomg did the forums get pwned?
« Reply #1 on: August 15, 2007, 10:51:03 am »
Q: Is like the last time where you adviced us to change password(s)?

OBEY!!!

Offline Spasm

  • Soldier
  • **
  • Posts: 241
  • Elite CTF Owner
    • Elite CTF
Re: Q: zomg did the forums get pwned?
« Reply #2 on: August 15, 2007, 10:54:21 am »
 >:(  We need Battle Eye for the forums now
Owner/Founder- Elite CTF -  http://elitectf.com
OwnedVision - http://ownedvision.com
--An EliteCTF Production.
Snipe & Slice - Saw & Law - One Shots

Offline swebonny

  • Camper
  • ***
  • Posts: 279
  • BUahh...
Re: Q: zomg did the forums get pwned?
« Reply #3 on: August 15, 2007, 10:55:44 am »
But the good this is that it´s back :D

Offline DePhille

  • Flagrunner
  • ****
  • Posts: 623
  • SoldatPage Webmaster
    • SoldatPage
Re: Q: zomg did the forums get pwned?
« Reply #4 on: August 15, 2007, 11:04:19 am »
Thanks for restoring them.
Hope we find the cause soon.
This signature was broken. Feel free to fix it.

Offline miketh2005

  • Soldat Beta Team
  • Flagrunner
  • ******
  • Posts: 668
  • What's the URL for www.microsoft.com?
Re: Q: zomg did the forums get pwned?
« Reply #5 on: August 15, 2007, 11:13:58 am »
HACKERS
Quote from: 'Ando.' pid='12999178' dateline='1309046898'
My new password is secure as shit :)
Mate, I am not sure Shit is even secured nowadays.

Offline Iron Man

  • Soldier
  • **
  • Posts: 224
Re: Q: zomg did the forums get pwned?
« Reply #6 on: August 15, 2007, 11:19:35 am »
yeah, i think it rolled back because i posted, someone else posted, and now both posts are gone..

Offline mar77a

  • Global Moderator
  • Veteran
  • *****
  • Posts: 1295
  • mad
    • random stuffs
Re: Q: zomg did the forums get pwned?
« Reply #7 on: August 15, 2007, 11:23:56 am »
take them down until you find out where the vulnerability is

Offline andrelie

  • Camper
  • ***
  • Posts: 384
  • Im sorry for the spamming...
Re: Q: zomg did the forums get pwned?
« Reply #8 on: August 15, 2007, 11:24:24 am »
im scared :(
Im sorry for the spamming...

Offline DePhille

  • Flagrunner
  • ****
  • Posts: 623
  • SoldatPage Webmaster
    • SoldatPage
Re: Q: zomg did the forums get pwned?
« Reply #9 on: August 15, 2007, 11:58:01 am »
take them down until you find out where the vulnerability is
Chakra's password I think. It has been changed so don't worry.
This signature was broken. Feel free to fix it.

Offline blackdevil0742

  • Veteran
  • *****
  • Posts: 1061
  • Don't Panic
Re: Q: zomg did the forums get pwned?
« Reply #10 on: August 15, 2007, 12:05:13 pm »
Yeah he was the only one online except an other fella that had member color on users online.

OBEY!!!

Offline FliesLikeABrick

  • Administrator
  • Flamebow Warrior
  • *****
  • Posts: 6144
    • Ultimate 13 Soldat
Re: Q: zomg did the forums get pwned?
« Reply #11 on: August 15, 2007, 12:13:41 pm »
I don't want to take it down until the problem is found, that gains very little.  Regardless of whether I take it down or leave it up and it gets screwed again, posts would be lost or never occur at all.  At least if I leave it up, it lets me more easily look into what happened.

I believe the problem was Chakra's password, I have yet to look into the logs at all because I'm at work and busy. 

Yes, everyone please change your passwords ASAP.  It is more than likely that whoever compromised the forums took a database snapshot (I'll be able to look up if he did), and therefore has all of the password hashes... but the way that SMF stores passwords is quite good.  It isn't critical that you change your password unless you're a mod/admin/beta tester.  I still recommend you do, as it is a good practice for when things like this happen.

I might not be able to look into this until later today/tonight, but I'll post any information about what I find here, unless I think it is a danger to the forums or will give the kiddie who did this any kind of advantage.
« Last Edit: August 15, 2007, 12:16:42 pm by FliesLikeABrick »

Offline Daimarus

  • Soldier
  • **
  • Posts: 136
  • Believe me, I can kill you with my Spas...
    • SC forums
Re: Q: zomg did the forums get pwned?
« Reply #12 on: August 15, 2007, 12:29:55 pm »
FLAB, I know some about hacking, but a little about hacking forums.

I think that they may OWN* forums in at least 2 simple ways:

1) Bruteforce'ing the password - Even old BrutusA2 can do that...
2) Cookie-Stealing - Admin may get on ANY site and he may "catch" the bad code, that will steal cookies from SoldatForums and e.g. send them on FTP server. I did that method once on test forums. It works as good as bruteforce'ing, but takes less time.

You cannot defend by any of those methods, except making a limit of logins per 1 minute (anti-bruteforce) and not-opening any links from people (impossible xD)


*- Owning a forum/site means taking control or wrecking the forum/site. In simple words xD
My SPAS-12 doesn't like most of people. He can mistakenly shoot your brain out of your head and splash it on the nearest wall.

Offline andrelie

  • Camper
  • ***
  • Posts: 384
  • Im sorry for the spamming...
Re: Q: zomg did the forums get pwned?
« Reply #13 on: August 15, 2007, 12:34:04 pm »
what will happen to the people that did this?
Im sorry for the spamming...

Offline Flamiex

  • Major(1)
  • Posts: 22
Re: Q: zomg did the forums get pwned?
« Reply #14 on: August 15, 2007, 12:34:19 pm »
Cookie-Stealing will not work on today's standard of forums, the cookie only contains your session id which is linked with your ip/browser/other information sent from your pc, so it wont let you use a session id on a different PC.

but anyway, I suggest you upgrade the forums to the latest version...

Offline Dark Jesus

  • Soldier
  • **
  • Posts: 158
Re: Q: zomg did the forums get pwned?
« Reply #15 on: August 15, 2007, 12:41:24 pm »
What had happened?

Offline DePhille

  • Flagrunner
  • ****
  • Posts: 623
  • SoldatPage Webmaster
    • SoldatPage
Re: Q: zomg did the forums get pwned?
« Reply #16 on: August 15, 2007, 12:56:43 pm »
What had happened?

Someone deleted all the SoldatForums topics, members, style, ...
We do not know exactly or forsure how this happened but most likely someone was able to get into Chakra's account. The forums have been down for approximately 50-60 minutes. FliesLikeABrick used a back-up to restore the forum's content and we only lost 5 hours worth of post. So any posts that were made between 6AM(EST) and 11AM(EST) today (15th of August 2007) are gone.
FliesLikeABrick is currently trying to find out who is responsible for this.

Grtz, DePhille
This signature was broken. Feel free to fix it.

Offline FliesLikeABrick

  • Administrator
  • Flamebow Warrior
  • *****
  • Posts: 6144
    • Ultimate 13 Soldat
Re: Q: zomg did the forums get pwned?
« Reply #17 on: August 15, 2007, 12:59:46 pm »
I found out how they did it, and I have the IP of the person who did it.  If you have access to a large amount of login/user data on your sites and would like to try to look this up for me, send me a PM and I'll give you the IP.

Offline LtKillroy

  • Flagrunner
  • ****
  • Posts: 779
  • Killroy was here
Re: Q: zomg did the forums get pwned?
« Reply #18 on: August 15, 2007, 01:02:58 pm »
I found out how they did it, and I have the IP of the person who did it. If you have access to a large amount of login/user data on your sites and would like to try to look this up for me, send me a PM and I'll give you the IP.
Are you at the liberty of giving up the name, there is an army surplus store down the street and well... In all seriousness, can you keep this from happening again, I mean, who would want to hack a random forum for a small game?
L'audace, l'audace, toujours l'audace

Offline ..::HHH::..

  • Soldier
  • **
  • Posts: 210
  • Dream Theater.. is the F**king best!
Re: Q: zomg did the forums get pwned?
« Reply #19 on: August 15, 2007, 01:04:37 pm »
i think you should tell us who did it.. so we can all hate him togetah..