Lacrima Castle
HelpSearchMembersCalendar

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> Guiz, we've been hacked
Raijinili
post Mar 9 2012, 06:57 PM
Post #1


Lieutenant
*************

Group: Gods
Posts: 2538
Joined: 25-December 05
Member No.: 16



GET OFF THE SITE IT'S NOT SAFE

go to irc.psigenix.net channel #lcn for now. mibbit link: http://chat.mibbit.com/#lcn@irc.psigenix.net

Edit: I think I fixed it. More details in topic.

This post has been edited by Raijinili: Mar 9 2012, 09:18 PM


~~~
IPB Image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Raijinili
post Mar 9 2012, 09:58 PM
Post #2


Lieutenant
*************

Group: Gods
Posts: 2538
Joined: 25-December 05
Member No.: 16



What happened?
- Random links to Russian sites have been popping up in certain browsers. This was traced to a mass March 6th edit of all PHP files.

What else happened?
- I dunno. Sysadmin was not part of my job description.
- Seriously, though. I don't know. Passwords may have been compromised. The security of that is dependent on our forum software, which is years out of date.
- I'm still trying to see if they added any backdoors so that this can happen again.
- Security may have been compromised long ago, and March 6 was just the date they decided to do something about it. We weren't the only Dreamhost customer that was hit on that date: http://danhilltech.tumblr.com/post/1808586...press-dreamhost

What we do?
- I've cleaned up the code that was doing it. There may have been more code added to specific files. I have no basis of comparison and would have to manually search through .php files for that.
- I'm emailing Dreamhost for more information.
- I'm going to have to change the passwords for the forum database.
- I must emphasize again that I'm basically just the cleverest chimp on a keyboard around here. I don't actually have any expertise about this.

What you do?
- You should change your password (http://strongpasswordgenerator.com/). You should NOT change your password to something you use elsewhere: we don't know how the breach happened or if it can happen again, or if it's still open.
- You should also change any password of anything you use with the same password.
- You should scan for viruses and other malware, especially if you were ever redirected to any other site while trying to go to LCN.
- Um, don't post private information on this site. And think about what private information you may have had here (e.g. private messages containing passwords or something). They may have downloaded anything and everything.

This was the code added to the top of every PHP file:
http://pastebin.com/gXfHRTbn

That was base64 encoded PHP script, probably to prevent server searches from turning up the links. Here is the base64 decoded:
http://pastebin.com/vXfaqbS4


~~~
IPB Image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Raijinili
post Mar 9 2012, 10:57 PM
Post #3


Lieutenant
*************

Group: Gods
Posts: 2538
Joined: 25-December 05
Member No.: 16



Just removed the ability for IPB to drop tables. Tell me if something goes wrong.


~~~
IPB Image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Raijinili
post Mar 10 2012, 12:28 AM
Post #4


Lieutenant
*************

Group: Gods
Posts: 2538
Joined: 25-December 05
Member No.: 16



Having to manually change the DB password in several places. Tell me if you find broken pages.


~~~
IPB Image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
DustyHaru
post Mar 10 2012, 03:25 PM
Post #5


Check Length
*********

Group: Knights
Posts: 916
Joined: 7-August 07
From: Check Length
Member No.: 1632



When I check my profile page I see:
QUOTE
IPB WARNING [2] mysql_connect() [function.mysql-connect]: Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2) (Line: 802 of /sources/action_public/profile.php)" at the top.


Using Revolution if that means anything.

This post has been edited by DustyHaru: Mar 10 2012, 03:26 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Raijinili
post Mar 10 2012, 09:15 PM
Post #6


Lieutenant
*************

Group: Gods
Posts: 2538
Joined: 25-December 05
Member No.: 16



fixed in a bad way

Edit: Just changed the way some variables work. Tell me if that broke anything.

This post has been edited by Raijinili: Mar 10 2012, 10:33 PM


~~~
IPB Image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Raijinili
post Mar 11 2012, 09:16 AM
Post #7


Lieutenant
*************

Group: Gods
Posts: 2538
Joined: 25-December 05
Member No.: 16



Oh yeah. I should email all members.

Edit: Oh yeah. Forgot to remember to sign the email.


~~~
IPB Image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
DavidSchinkel
post Mar 11 2012, 06:16 PM
Post #8


Shy
*

Group: Arcs
Posts: 42
Joined: 10-June 10
From: Gig Harbor, Washington
Member No.: 2071



Hey, are you going update PSP faces with the Special Edition ones?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
loool
post Mar 12 2012, 03:49 AM
Post #9


Shy
*

Group: Arcs
Posts: 34
Joined: 14-October 08
Member No.: 1798



I just receive an email saying we got hacked. !!! D:
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SyphonVectorman
post Mar 12 2012, 05:28 AM
Post #10


Talkative
***

Group: Arcs
Posts: 106
Joined: 17-March 07
Member No.: 829



Well this sucks; checking my old e-mail and I see this. Thanks for the heads-up though.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Raijinili
post Mar 13 2012, 01:43 AM
Post #11


Lieutenant
*************

Group: Gods
Posts: 2538
Joined: 25-December 05
Member No.: 16



Removed some powers/adminship from some inactive members (or until they change their password):
- Marionette
- Malice
- Ledah


~~~
IPB Image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Reply to this topicStart new topic
4 User(s) are reading this topic (4 Guests and 0 Anonymous Users)
0 Members:

 

Lo-Fi Version Time is now: 19th April 2024 - 05:51 PM