Funny Just what happened today? (Read 1154 times)

  • Avatar of reko
  • PipPipPipPipPipPip
  • Group: Member
  • Joined: Jun 11, 2002
  • Posts: 883
As some of you noticed, someone attempted to 'hack' GW today.

First of all let me start by saying that overall the attempt was pathetic, and after writing a script to examine that exactly what all the guy tried to do, it became very apparent that whoever he was, he was a complete novice who just got very lucky. I know that some of you are interested in exactly how this attack was possible and I will reveal that information because it can't and won't happen again.

Let's start with what the problem was. The problem was that this new server's Apache is for whatever reason configured in a way that interpreted files such as "file.php.ext" as a PHP script. It only checked the first extension, and not the last one, like it should and does on my own server and all other servers I tried to make double sure that it should. That was how he managed to upload a script called "C99 Shell" or what the fuck ever in pubaccess. This script was basically something that a 6 year old child could use to "hack" a website. It was nothing sort of impressive, the only thing that I'm impressed of is that our provider's Apache was configured in this way.

Anyway, the guy didn't really know what he was doing, I like especially how he didn't try to check any passwords from crucial script files but instead edited our forum index with a stupid message probably thinking I wouldn't have a backup. I also like how he probably tried to check if his IP and actions were logged in a log file because he checked a log file from the logs directory. The funny thing is that instead of checking today's log, he forgot it's the 16th day, not the 6th. Yes that's right. He checked a wrong fucking log file. Had he even been smart enough to get the date right, I couldn't have been able to track everything he did to this extend.

Anyway, most of the things he did were harmless. I found the script he used in pretty much 5-10 minutes within I got noticed that we've been compromised, but I didn't want to remove the guy's access to it before I first had made sure that he didn't make any copies of the script in other places on the filesystem. That's why the whole ordeal took longer than expected, although some people on IRC still think we were pretty quick about the whole situation (it could take hours to pinpoint the problem if the hacker knew what he was doing, but this time it took mere minutes).

I did make one mistake though. I postponed disabling his access a bit too late, because I thought this was some harmless guy trying to have a bit of fun with us, since all he was doing was editing our forums index with a stupid message. That was pretty naive of me. Anyway the instant I saw that he started to delete stuff I disabled his access to the script. I obviously had backups of the files, which is why it didn't take long to recover the forums and the main site (especially since the guy was stupid enough not to get the SQL password even though it was basically given to him on a golden plate.. Not that he would've known what to do with it though). However I only have very ancient version of pubaccess backup. This isn't really a big loss because the guy didn't get to the part that he would've deleted pubaccess, but he wrote the index.php over with some stupid message. That means that essentially some of the code for the web interface was lost. I still have most of it left, like the actual file processing and uploading and image thumbnail generation and whatever. And none of the files of the users' were lost either. So basically this means that I'll have to code the web interface for it again, which isn't a huge job. This also presents a good chance to improve it and fix the few bugs it had. If you have any suggestions feel free to post here.

Another thing that got a bit messed up was the wiki. No articles are lost, but some of the (default) source code files were deleted as well as the local settings. The default source code files are obviously easy to find, but I don't have a backup of the local settings file. While it's very easy to re-configure the wiki, I think this is a good opportunity to update the MediaWiki to the latest version and fix the problem with special characters in the URL. So expect that to be done soonish too.

Also lastly a word for mods, staffers and premiums. The reason you got your Happy Zoo PMs resent was because I changed the MySQL's password as a safety measure. I forgot to change it in Happy Zoo's side, so what happened is that Happy Zoo thought that all the users got removed from the zoo so it deleted them. After I fixed the pass to the new one, it re-added all the users and re-sent PMs. Sorry about that!
Last Edit: March 16, 2008, 10:32:08 pm by ramirez

big thanx to dragonslayer for sig!
  • Avatar of dada
  • VILLAIN
  • PipPipPipPipPipPipPipPip
  • Group: Administrator
  • Joined: Dec 27, 2002
  • Posts: 5538
First of all, a big thanks to the man who watches over us while we're asleep. Thanks, rami!
  • Avatar of bonermobile
  • B-U-N-C-H-I-E-S! BUNCHIES!
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Dec 21, 2002
  • Posts: 1309
Nice work, rami!

Checking the wrong log file is just, wow.
  • Avatar of bonzi_buddy
  • Kaiser
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Apr 15, 2005
  • Posts: 1998
I also like how he probably tried to check if his IP and actions were logged in a log file because he checked a log file from the logs directory. The funny thing is that instead of checking today's log, he forgot it's the 16th day, not the 6th.
hahaha
But glad to hear nothing really bad happened. i guess we should AGAIN pool some money for rami's goodjob-icecream...
Last Edit: March 16, 2008, 11:01:04 pm by bonzi_buddy
  • Avatar of Kaworu
  • kaworu*Sigh*Isnt he the cutest person ever
  • PipPipPipPipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Oct 12, 2002
  • Posts: 5755
Yah seriously thanks rami, I think we should bake you a cake.
  • Avatar of bonzi_buddy
  • Kaiser
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Apr 15, 2005
  • Posts: 1998
Yah seriously thanks rami, I think we should bake you a cake.
Kaworu can you do it
can you take a picture of yourself baking a cake, with a "to rami <3" message or w/e and upload it to this topic
because i think he deserves it

c'mon surely everybody agrees with me on this right??
Last Edit: March 16, 2008, 10:39:04 pm by bonzi_buddy
  • Avatar of Sarah
  • Blackman the Game: 0% complete
  • PipPipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Feb 7, 2004
  • Posts: 2401
Good thing you didn't really step down...
  • Avatar of pburn
  • What, me worry?
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Jan 1, 2004
  • Posts: 1752
I've been blamed for this attack, but it's not me. I was at a HORROR CONVENTION and when I got back I thought everyone was lying to me. :(
  • Avatar of Kaworu
  • kaworu*Sigh*Isnt he the cutest person ever
  • PipPipPipPipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Oct 12, 2002
  • Posts: 5755
Dude I just loved how everybody on there seemed to be singing up with racist names except you (was it really you?) so their members list was like
CHINK nigger psyburn SPIC
  • Avatar of Lord Kamina
  • MAZIIIIIN GO!! PILEDER ON!!!
  • PipPipPipPipPip
  • Group: Premium Member
  • Joined: Jan 31, 2003
  • Posts: 775
Yah seriously thanks rami, I think we should bake you a cake.

Make sure it's got plenty of rhubarb...

if you're a vegan you support baby killers
  • Mysterious Member
  • PipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Apr 9, 2006
  • Posts: 803
I've been blamed for this attack, but it's not me. I was at a HORROR CONVENTION and when I got back I thought everyone was lying to me. :(

Registered Users: bortlet, Chink, cookie, hackerboy, j00 s4l33, Maulin Yo, Meanz, nigger, psyburn, r 3 d h o t, southpark180, SPIC, THE GREAT VAGEYENA

 :hmm:
Ock ock, Ack ack!
Beware of the cursed monkey spit!
  • Avatar of bonzi_buddy
  • Kaiser
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Apr 15, 2005
  • Posts: 1998
You can do it Kaworu!!!

well ok don't do it if you don't want to but man that would have been excelent... i can see you in an apron...
Last Edit: March 16, 2008, 10:48:09 pm by bonzi_buddy
  • None of them knew they were robots.
  • PipPipPipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Nov 5, 2006
  • Posts: 3242
It's a good thing it wasn't so terrible now this event will be forever remembered
Play Raimond Ex (if you haven't already)


I'll not TAKE ANYTHING you write like this seriously because it looks dumb
  • Avatar of Xeno|Soft
  • Chicken Hunter
  • PipPipPipPip
  • Group: Premium Member
  • Joined: Jun 18, 2002
  • Posts: 564
Oh wow, good job Rami.
  • Avatar of pburn
  • What, me worry?
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Jan 1, 2004
  • Posts: 1752
Dude I just loved how everybody on there seemed to be singing up with racist names except you (was it really you?) so their members list was like
CHINK nigger psyburn SPIC
I wish I was here when this happened.

Someone framed me man. This is like that one time when someone hacked my account and everyone(including Wishmoo) went ape shit on me. I am INCREDIBLY devoted to GW guys. I don't want to go Jason Bourne.
  • Avatar of local_dunce
  • PipPipPipPipPipPipPipPip
  • Group: Member
  • Joined: Jan 11, 2013
  • Posts: 2454
Man, the work is never over for you.

Thanks.
now is the winter of our discontent
  • Avatar of ase
  • It's A Short Eternity... live with it
  • PipPipPipPipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: May 23, 2003
  • Posts: 4526
great job, ramirez

quick question: did we get our old zoo login and passwords or brand new ones (too lazy to check and compare)
  • Avatar of bonermobile
  • B-U-N-C-H-I-E-S! BUNCHIES!
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Dec 21, 2002
  • Posts: 1309
Registered Users: bortlet, Chink, cookie, hackerboy, j00 s4l33, Maulin Yo, Meanz, nigger, psyburn, r 3 d h o t, southpark180, SPIC, THE GREAT VAGEYENA

 :hmm:
[01:29:59 ][/01:29:59] <%Sarevok> [20:28:05] <+Sarah> i like how PSYBURN joined <--it was me :(
  • Avatar of Finality
  • Still a Roleplay Reformer...
  • Group: Premium Member
  • Joined: Feb 4, 2002
  • Posts: 79
So, if he checked the wrong log, you have his IP and know who it is, right?
  • Avatar of Madolah
  • ;Wyrm
  • PipPipPipPipPip
  • Group: Global Moderator
  • Joined: Oct 4, 2005
  • Posts: 749
thanks rami.

Did you track this guy and his IP after though?
Wyrm  | Madolah | ær