Gaming World Forums

General Category => General Talk => Topic started by: reko on March 16, 2008, 10:26:31 pm

Title: Just what happened today?
Post by: reko on March 16, 2008, 10:26:31 pm
As some of you noticed, someone attempted to 'hack' GW today.

First of all let me start by saying that overall the attempt was pathetic, and after writing a script to examine that exactly what all the guy tried to do, it became very apparent that whoever he was, he was a complete novice who just got very lucky. I know that some of you are interested in exactly how this attack was possible and I will reveal that information because it can't and won't happen again.

Let's start with what the problem was. The problem was that this new server's Apache is for whatever reason configured in a way that interpreted files such as "file.php.ext" as a PHP script. It only checked the first extension, and not the last one, like it should and does on my own server and all other servers I tried to make double sure that it should. That was how he managed to upload a script called "C99 Shell" or what the fuck ever in pubaccess. This script was basically something that a 6 year old child could use to "hack" a website. It was nothing sort of impressive, the only thing that I'm impressed of is that our provider's Apache was configured in this way.

Anyway, the guy didn't really know what he was doing, I like especially how he didn't try to check any passwords from crucial script files but instead edited our forum index with a stupid message probably thinking I wouldn't have a backup. I also like how he probably tried to check if his IP and actions were logged in a log file because he checked a log file from the logs directory. The funny thing is that instead of checking today's log, he forgot it's the 16th day, not the 6th. Yes that's right. He checked a wrong fucking log file. Had he even been smart enough to get the date right, I couldn't have been able to track everything he did to this extend.

Anyway, most of the things he did were harmless. I found the script he used in pretty much 5-10 minutes within I got noticed that we've been compromised, but I didn't want to remove the guy's access to it before I first had made sure that he didn't make any copies of the script in other places on the filesystem. That's why the whole ordeal took longer than expected, although some people on IRC still think we were pretty quick about the whole situation (it could take hours to pinpoint the problem if the hacker knew what he was doing, but this time it took mere minutes).

I did make one mistake though. I postponed disabling his access a bit too late, because I thought this was some harmless guy trying to have a bit of fun with us, since all he was doing was editing our forums index with a stupid message. That was pretty naive of me. Anyway the instant I saw that he started to delete stuff I disabled his access to the script. I obviously had backups of the files, which is why it didn't take long to recover the forums and the main site (especially since the guy was stupid enough not to get the SQL password even though it was basically given to him on a golden plate.. Not that he would've known what to do with it though). However I only have very ancient version of pubaccess backup. This isn't really a big loss because the guy didn't get to the part that he would've deleted pubaccess, but he wrote the index.php over with some stupid message. That means that essentially some of the code for the web interface was lost. I still have most of it left, like the actual file processing and uploading and image thumbnail generation and whatever. And none of the files of the users' were lost either. So basically this means that I'll have to code the web interface for it again, which isn't a huge job. This also presents a good chance to improve it and fix the few bugs it had. If you have any suggestions feel free to post here.

Another thing that got a bit messed up was the wiki. No articles are lost, but some of the (default) source code files were deleted as well as the local settings. The default source code files are obviously easy to find, but I don't have a backup of the local settings file. While it's very easy to re-configure the wiki, I think this is a good opportunity to update the MediaWiki to the latest version and fix the problem with special characters in the URL. So expect that to be done soonish too.

Also lastly a word for mods, staffers and premiums. The reason you got your Happy Zoo PMs resent was because I changed the MySQL's password as a safety measure. I forgot to change it in Happy Zoo's side, so what happened is that Happy Zoo thought that all the users got removed from the zoo so it deleted them. After I fixed the pass to the new one, it re-added all the users and re-sent PMs. Sorry about that!
Title: Just what happened today?
Post by: dada on March 16, 2008, 10:30:52 pm
First of all, a big thanks to the man who watches over us while we're asleep. Thanks, rami!
Title: Just what happened today?
Post by: bonermobile on March 16, 2008, 10:35:00 pm
Nice work, rami!

Checking the wrong log file is just, wow.
Title: Just what happened today?
Post by: bonzi_buddy on March 16, 2008, 10:35:36 pm
I also like how he probably tried to check if his IP and actions were logged in a log file because he checked a log file from the logs directory. The funny thing is that instead of checking today's log, he forgot it's the 16th day, not the 6th.
hahaha
But glad to hear nothing really bad happened. i guess we should AGAIN pool some money for rami's goodjob-icecream...
Title: Just what happened today?
Post by: Kaworu on March 16, 2008, 10:35:44 pm
Yah seriously thanks rami, I think we should bake you a cake.
Title: Just what happened today?
Post by: bonzi_buddy on March 16, 2008, 10:36:57 pm
Yah seriously thanks rami, I think we should bake you a cake.
Kaworu can you do it
can you take a picture of yourself baking a cake, with a "to rami <3" message or w/e and upload it to this topic
because i think he deserves it

c'mon surely everybody agrees with me on this right??
Title: Just what happened today?
Post by: Sarah on March 16, 2008, 10:38:27 pm
Good thing you didn't really step down...
Title: Just what happened today?
Post by: pburn on March 16, 2008, 10:39:31 pm
I've been blamed for this attack, but it's not me. I was at a HORROR CONVENTION and when I got back I thought everyone was lying to me. :(
Title: Just what happened today?
Post by: Kaworu on March 16, 2008, 10:41:02 pm
Dude I just loved how everybody on there seemed to be singing up with racist names except you (was it really you?) so their members list was like
CHINK nigger psyburn SPIC
Title: Just what happened today?
Post by: Lord Kamina on March 16, 2008, 10:41:24 pm
Yah seriously thanks rami, I think we should bake you a cake.

Make sure it's got plenty of rhubarb...
Title: Just what happened today?
Post by: Liman on March 16, 2008, 10:42:48 pm
I've been blamed for this attack, but it's not me. I was at a HORROR CONVENTION and when I got back I thought everyone was lying to me. :(

Registered Users: bortlet, Chink, cookie, hackerboy, j00 s4l33, Maulin Yo, Meanz, nigger, psyburn, r 3 d h o t, southpark180, SPIC, THE GREAT VAGEYENA

 :hmm:
Title: Just what happened today?
Post by: bonzi_buddy on March 16, 2008, 10:44:32 pm
You can do it Kaworu!!!

well ok don't do it if you don't want to but man that would have been excelent... i can see you in an apron...
Title: Just what happened today?
Post by: Mince Wobley on March 16, 2008, 10:45:49 pm
It's a good thing it wasn't so terrible now this event will be forever remembered
Title: Just what happened today?
Post by: Xeno|Soft on March 16, 2008, 10:46:47 pm
Oh wow, good job Rami.
Title: Just what happened today?
Post by: pburn on March 16, 2008, 10:47:23 pm
Dude I just loved how everybody on there seemed to be singing up with racist names except you (was it really you?) so their members list was like
CHINK nigger psyburn SPIC
I wish I was here when this happened.

Someone framed me man. This is like that one time when someone hacked my account and everyone(including Wishmoo) went ape shit on me. I am INCREDIBLY devoted to GW guys. I don't want to go Jason Bourne.
Title: Just what happened today?
Post by: local_dunce on March 16, 2008, 10:48:19 pm
Man, the work is never over for you.

Thanks.
Title: Just what happened today?
Post by: ase on March 16, 2008, 10:58:12 pm
great job, ramirez

quick question: did we get our old zoo login and passwords or brand new ones (too lazy to check and compare)
Title: Just what happened today?
Post by: bonermobile on March 16, 2008, 10:58:36 pm
Registered Users: bortlet, Chink, cookie, hackerboy, j00 s4l33, Maulin Yo, Meanz, nigger, psyburn, r 3 d h o t, southpark180, SPIC, THE GREAT VAGEYENA

 :hmm:
[01:29:59 ][/01:29:59] <%Sarevok> [20:28:05] <+Sarah> i like how PSYBURN joined <--it was me :(
Title: Just what happened today?
Post by: Finality on March 16, 2008, 11:02:08 pm
So, if he checked the wrong log, you have his IP and know who it is, right?
Title: Just what happened today?
Post by: Madolah on March 16, 2008, 11:14:18 pm
thanks rami.

Did you track this guy and his IP after though?
Title: Just what happened today?
Post by: reko on March 16, 2008, 11:16:14 pm
Yes I have the IPs (actually there's 2).
Title: Just what happened today?
Post by: big ass skelly on March 16, 2008, 11:21:30 pm
Don't mess with the PK project you imbecile.



they'll... player kill you.
Title: Just what happened today?
Post by: Dave on March 16, 2008, 11:23:34 pm
What a fucking idiot.
Title: Just what happened today?
Post by: Ghost_Aspergers on March 16, 2008, 11:24:41 pm
Here I am thinking he may have exploited something in the new blog system... but it was just a mere upload to the pubaccess? How boring.
Title: Just what happened today?
Post by: DS on March 16, 2008, 11:24:56 pm
so basically i hope the hacker reads this

YOU ARE FUCKING DUMB

even dumber than me...
Title: Just what happened today?
Post by: Carrion Crow on March 16, 2008, 11:37:25 pm
I think if your life has reached the level where you're hacking internet forums without any expertise or reason you're gonna kill yourself soon because your life is worthless.
Title: Just what happened today?
Post by: Artis Leon Ivey Jr on March 16, 2008, 11:40:34 pm
i dont care much or think the dude is just SOME BIG LOSER since i bet this was like no work at all, it was just kind of funny for a few minutes and then it was fixed.

basically i love you hacker : )
Title: Just what happened today?
Post by: reko on March 16, 2008, 11:40:42 pm
Here I am thinking he may have exploited something in the new blog system... but it was just a mere upload to the pubaccess? How boring.
I'm experienced enough not to leave any stupid vulnerabilities in my code, but I gotta admit that I never thought of the extension issue that was used against us today. Even if it's badly configured Apache, which I'm not 100% sure of, it's really my mistake in the end.

Edit. Not trying to say that this guy isn't a fucking moron because he is.
Title: Just what happened today?
Post by: ATARI on March 16, 2008, 11:46:50 pm
so basically i hope the hacker reads this

YOU ARE FUCKING DUMB

even dumber than me...

low blow
Title: Just what happened today?
Post by: cowardknower on March 16, 2008, 11:51:38 pm
WELL HACKER YOU FUCKED UP MY WHOLE DAY
i hope you are happy
Title: Just what happened today?
Post by: Sarah on March 16, 2008, 11:55:22 pm
WELL HACKER YOU FUCKED UP MY WHOLE DAY
i hope you are happy
don't be a victim couch....


then the terrorists win.............
Title: Just what happened today?
Post by: WackFiend on March 17, 2008, 12:22:21 am
What was the stupid message?
Title: Just what happened today?
Post by: Rowain on March 17, 2008, 12:30:37 am
Dumb as he is, he still got further than 99% of the people who have actually threatened to hack GW (red archer, Jin Kiyami, etc)
Title: Just what happened today?
Post by: Sarevok on March 17, 2008, 12:32:54 am
too bad rami... first you're fired for being a pedo now you let gw get hacked

it's time to pass the torch on buddy (to me)
Title: Just what happened today?
Post by: Mince Wobley on March 17, 2008, 01:26:29 am
By the way, was the criminal registered on GW? With what username?
Title: Just what happened today?
Post by: The Riddler on March 17, 2008, 01:34:29 am
Oh right I wondered what that PM was about.

Good job in fixing it so fast, btw, rami.
Title: Just what happened today?
Post by: Mateui on March 17, 2008, 01:34:48 am
Wow, I was away today from the forums and I totally missed this, but I'm really happy rami got everything under-control. Kudos to him!
Title: Just what happened today?
Post by: Shepperd on March 17, 2008, 01:37:24 am
whatever rami should be banned because of his kid porn
Title: Just what happened today?
Post by: Trujin on March 17, 2008, 01:42:46 am
Haha and I was just thinking you guys put something immature as a notifier that you were working on the forums.
Title: Just what happened today?
Post by: Dale Gobbler on March 17, 2008, 01:46:47 am
Maybe the staff will reconsider having you step down for uploading child pron. Take that GW![/joke]
Title: Just what happened today?
Post by: ThugTears666 on March 17, 2008, 01:50:37 am
Yes I have the IPs (actually there's 2).


Are you going to do anything or hold onto them just in case?

Quote
What was the stupid message?

Just some dumb OMGFGHAXXOR_21 writing
Title: Just what happened today?
Post by: Sarevok on March 17, 2008, 01:51:22 am
this was just a PR stunt to get rami back in good favour imo
Title: Just what happened today?
Post by: reko on March 17, 2008, 02:28:35 am
I am pretty sure the IPs were just proxies or whatever, but I'll report them to the respective ISPs anyway.
Title: Just what happened today?
Post by: goldenratio on March 17, 2008, 02:43:51 am
(http://motdidr.com/img/gw hacked opps lol.png)

please turn pubaccess back on so this image doesnt kill my server :(
Title: Just what happened today?
Post by: Neophyte on March 17, 2008, 02:50:00 am
Maulin Yo Waz!?!

Anyway, everything is fixed. Good job and thanks, rami.
Title: Just what happened today?
Post by: Moriason on March 17, 2008, 02:58:45 am
rami doing it big!
Title: Just what happened today?
Post by: ATARI on March 17, 2008, 03:00:09 am
we're dealing with a psychopath here
Title: Just what happened today?
Post by: WIP on March 17, 2008, 03:25:34 am
RMN did it!
Title: Just what happened today?
Post by: Ghost_Aspergers on March 17, 2008, 03:34:10 am
Who?
Title: Just what happened today?
Post by: Strangeluv on March 17, 2008, 03:37:00 am
Red Master Ninja
Title: Just what happened today?
Post by: blood hell on March 17, 2008, 03:48:51 am
if only.... you made girlbones lit mod...
Title: Just what happened today?
Post by: Ciel on March 17, 2008, 04:04:19 am
 rockin 'n' rollin in cyberspace
Title: Just what happened today?
Post by: DS on March 17, 2008, 07:16:41 am
RMN did it!
i was saying this on #gamingw when gw got hacked but i don't think anyone believed it :(
Title: Just what happened today?
Post by: fatty on March 17, 2008, 10:18:43 am
hahaha oh man, fuck this, I miss all the great GWevents :(
Title: Just what happened today?
Post by: dicko on March 17, 2008, 10:36:18 am
wow, nice work rami!
Title: Just what happened today?
Post by: Death Gulp on March 17, 2008, 11:46:04 am
i didnt know what was going on, i thought someone was just playing a joke. good job though, thanks a lot man
Title: Just what happened today?
Post by: goldenratio on March 22, 2008, 06:42:15 pm
hate to bump this but when is pubaccess coming back?