Good news

Forum rules and nettiquette, along with other items of general interest.

Important information about this forum is contained here, and members MUST familiarise themselves with the posts here, as well as what is contained within the FAQ.

Please do not complain if you ask a question regarding a topic covered here or in the FAQ and in response you get a rather brusque, obtuse or sarcastic response. We get sick and tired of answering the same questions, day in, day out, when the answers are clearly published, in plain view, and all that is required is for you to open your eyes and read them!

Moderator: Moderators

Forum rules
Please ensure that you have a meaningful location included in your profile. Please refer to the FAQ for details of what "meaningful" is.

Good news

Postby gstark on Tue Dec 21, 2004 8:06 pm

And a bit of bad

First of all, I've identified the hack, and I have the IP address as well.

The attack was, in fact, the phpbb vulnerbility; I'll post more details shortly.

In the meantime, I'm going to be pulling the server down temproarily for a few minor upgrades. It may be intermittent over the next hour or two as I have a few things to do, so please, bear with me, and thanx all for your patience and help.

If you find you can't get access for a while, please just wait a few minutes and try again.
Last edited by gstark on Thu Oct 20, 2005 4:55 pm, edited 1 time in total.
g.
Gary Stark
Nikon, Canon, Bronica .... stuff
The people who want English to be the official language of the United States are uncomfortable with their leaders being fluent in it - US Pres. Bartlet
User avatar
gstark
Site Admin
 
Posts: 22918
Joined: Thu Aug 05, 2004 11:41 pm
Location: Bondi, NSW

Postby xerubus on Tue Dec 21, 2004 8:07 pm

Well done Gary.
http://www.markcrossphotography.com - A camera, glass, and some light.
User avatar
xerubus
Senior Member
 
Posts: 2740
Joined: Fri Oct 22, 2004 3:33 pm
Location: Nth Brisbane

Postby sirhc55 on Tue Dec 21, 2004 8:16 pm

I’ll second that - well done Gary

Chris
Chris
--------------------------------
I started my life with nothing and I’ve still got most of it left
User avatar
sirhc55
Key Member
 
Posts: 12930
Joined: Fri Sep 17, 2004 6:57 pm
Location: Port Macquarie - Olympus EM-10

Postby Raydar on Tue Dec 21, 2004 8:22 pm

Thanks mate :D

We'd be lost with out you :wink:

Cheers
Ray :P
>> All of us could take a lesson from the weather. It pays no attention to criticism<<
User avatar
Raydar
Senior Member
 
Posts: 1366
Joined: Sun Aug 08, 2004 7:57 am
Location: Lismore, Northern - NSW

Postby fozzie on Tue Dec 21, 2004 8:23 pm

Gary,

If I was you I would lodged an official complaint with the Frederal Police and supply hacker's IP address for follow up. He/She has invaded your space, see how he/she likes a knock at the front door by the Federal Police. BTW: well done to getting the site up and running so quickly.

Cheers,
Last edited by fozzie on Tue Dec 21, 2004 10:08 pm, edited 1 time in total.
fozzie

When people ask what equipment I use - I tell them my eyes.
User avatar
fozzie
Key Member
 
Posts: 2806
Joined: Tue Oct 12, 2004 9:19 pm
Location: AUADA : Nikon D3/D2x - JPG Shooter

Postby birddog114 on Tue Dec 21, 2004 8:36 pm

Well done Gary, I'll come up with other after that moron! :evil:
Birddog114
VNAF, My Beloved Country and Airspace
User avatar
birddog114
Senior Member
 
Posts: 15881
Joined: Sat Aug 07, 2004 8:18 pm
Location: Belmore,Sydney

Postby Onyx on Tue Dec 21, 2004 9:01 pm

Would it be bad if... that IP address was to say, be leaked out into the public, and we could gang up and organise a ddos attack on it?!

Anyway, I noticed the forum logo has reverted back to pre xmas themed too. No more reindeer and pressie...
User avatar
Onyx
Senior Member
 
Posts: 3631
Joined: Sat Aug 07, 2004 6:51 pm
Location: westsyd.nsw.au

Postby mudder on Tue Dec 21, 2004 9:27 pm

G'day,

Just logged in and found out about the hack... I tips me hat to you guys for working so hard getting this great forum back on the air for all of us who enjoy it so much... A big thanks...

Re: the hacker, I'd certainly be lodging something official with the relevant authorites, wonder if the ISPs would be interested??? I would imagine the ISP that IP comes from would be very interested... What makes these feeble little minds get a buzz from this sort of rubbish amazes me... Wonder if they wreck phone boxes on their night's off?

Cheers and thanks for your work, tis appreciated by all of us...
Mudder
Aka Andrew
User avatar
mudder
Senior Member
 
Posts: 3020
Joined: Fri Oct 29, 2004 5:58 pm
Location: Melbourne - Burwood East

Postby Nnnnsic on Tue Dec 21, 2004 9:54 pm

Onyx wrote:Would it be bad if... that IP address was to say, be leaked out into the public, and we could gang up and organise a ddos attack on it?!

Anyway, I noticed the forum logo has reverted back to pre xmas themed too. No more reindeer and pressie...


I don't think the ip will help, after looking at it.

I'll get that logo changed soon though.
Producer & Editor @ GadgetGuy.com.au
Contributor for fine magazines such as PC Authority and Popular Science.
User avatar
Nnnnsic
I'm a jazz singer... so I know what I'm doing
 
Posts: 7770
Joined: Sun Aug 08, 2004 12:29 am
Location: Cubicle No. 42... somewhere in Bondi, NSW

Postby mudder on Tue Dec 21, 2004 10:04 pm

G'day,
was the IP provided by some form of proxy?
Aka Andrew
User avatar
mudder
Senior Member
 
Posts: 3020
Joined: Fri Oct 29, 2004 5:58 pm
Location: Melbourne - Burwood East

Postby Geoff on Tue Dec 21, 2004 11:21 pm

Gary - my sincere thanx too. When I woke up this morning (as usual) I logged on to the site to see that it had been hacked and something was wrong...I got a big lump in my throat and my day wasn't the same without my d70users 'fix' in the morning..who needs coffee? :). Anyway, thanx from me too for getting it all sorted so promptly. You're a champ. Merry Christmas.


Geoff.
User avatar
Geoff
Moderator
 
Posts: 7791
Joined: Sat Aug 07, 2004 12:08 am
Location: Freshwater - Northern Beaches, Sydney.

Postby gstark on Tue Dec 21, 2004 11:57 pm

There were three separate attacks, each using a different, and I suspect spoofed, IP address. I've isolated the relevant parts of my log files where the attacks occurred, and I have also retaind a copy of the perl script that this script kiddie ran.

Fairly basic, but it was enough to cause quite some damage.

I still have some damage here that needs rectification, but my primary sites are back up and, hopefuly, any future risk has now been minimized.
g.
Gary Stark
Nikon, Canon, Bronica .... stuff
The people who want English to be the official language of the United States are uncomfortable with their leaders being fluent in it - US Pres. Bartlet
User avatar
gstark
Site Admin
 
Posts: 22918
Joined: Thu Aug 05, 2004 11:41 pm
Location: Bondi, NSW

Postby dooda on Wed Dec 22, 2004 3:51 am

Yeah, this really freaked me out as well. I emailed Birddog (only address I have) and asked what was up. We decided that the problem be addressed outside of cyberworld with his 200-400 VR.

Great job Gary, good to see it back up.
love's first sighs are wisdom's last

Dave
http://www.flickr.com/photos/elton/
User avatar
dooda
Party Animal
 
Posts: 1591
Joined: Fri Oct 01, 2004 11:47 am
Location: Vancouver, B.C. Canada

Postby gstark on Wed Dec 22, 2004 7:14 am

I think I've found the last remnants of this miserable cretin's handiwork this morning; my email is now back to normal as well.

You have to wonder about these sorts of idiots - looking at the code that it used, it's really quite nice. Makes you wonder what sort of work this person could get if they only had a life?

Thanx all for your support and help.
g.
Gary Stark
Nikon, Canon, Bronica .... stuff
The people who want English to be the official language of the United States are uncomfortable with their leaders being fluent in it - US Pres. Bartlet
User avatar
gstark
Site Admin
 
Posts: 22918
Joined: Thu Aug 05, 2004 11:41 pm
Location: Bondi, NSW

Postby skippy on Wed Dec 22, 2004 10:04 am

Seen this?
http://www.pcworld.idg.com.au/index.php ... 3&eid=-108

Sounds like it may be linked:
"Once Santy infects servers running the phpBB software, it scans directories on the infected site and overwrites files with the extensions HTM, PHP, ASP, SHTM, JSP and PHTM with the text "This site is defaced!!! This site is defaced!!! NeverEverNoSanity WebWorm generation," according to an alert from Kaspersky Labs."
Dopeler Effect: The tendency of stupid ideas to seem smarter when they come at you rapidly.
User avatar
skippy
Member
 
Posts: 300
Joined: Tue Dec 14, 2004 11:57 pm
Location: Berowra, Sydney

Postby gstark on Wed Dec 22, 2004 10:14 am

werble wrote:Sounds like it may be linked


Thanx for this. That's exactly what hit us, and the article is correct in that it uses Google to find the vulnerable websites.

Interesting that this article says that it started in the US on Tuesday morning; are they saying Tuesday morning US time, or in the US, Tuesday morning our time? The latter is clearly the case in our situation, with the first hit coming in at around3:45 am Tuesday.
g.
Gary Stark
Nikon, Canon, Bronica .... stuff
The people who want English to be the official language of the United States are uncomfortable with their leaders being fluent in it - US Pres. Bartlet
User avatar
gstark
Site Admin
 
Posts: 22918
Joined: Thu Aug 05, 2004 11:41 pm
Location: Bondi, NSW

Postby xerubus on Wed Dec 22, 2004 10:25 am

The interesting thing is this... a lady we shall call 'Jess' found the poor coding quite a few weeks ago and warned phpbb about the consequences and that it would only be a matter of time before an exploit was written... and no... she did not write the exploit.... she gave the phpbb coders guidelines on how to fix the vulnerability and a full summary of the bug so that they could 'pretty it up' when letting the public know, however they ignored her. sometimes it makes you wonder....
http://www.markcrossphotography.com - A camera, glass, and some light.
User avatar
xerubus
Senior Member
 
Posts: 2740
Joined: Fri Oct 22, 2004 3:33 pm
Location: Nth Brisbane

Postby Nicole on Wed Dec 22, 2004 5:42 pm

You guys did an awesome job getting it all back and running again. Obviously these people aren't into photography as I'm sure if they were they wouldn't have time for anything else. :x
Nicole
Web Site
Nicole
Senior Member
 
Posts: 569
Joined: Wed Nov 03, 2004 9:54 pm
Location: Melbourne

Postby skippy on Thu Dec 23, 2004 11:16 am

Should be better now - Google's blocking the search feature used by the worm:

Google smacks down Santy worm
Web search engine company Google is blocking efforts by a new Internet worm to use its search engine to find vulnerable computers on the Internet, the company announced late Tuesday.
http://www.pcworld.idg.com.au/index.php ... 7&eid=-108
Dopeler Effect: The tendency of stupid ideas to seem smarter when they come at you rapidly.
User avatar
skippy
Member
 
Posts: 300
Joined: Tue Dec 14, 2004 11:57 pm
Location: Berowra, Sydney


Return to Information