FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 



Tweaknews hacked!
Goto page 1, 2, 3, 4  Next
 
Post new topic   Reply to topic    [TweakNews.net Forum] Forum Index -> Tweaknews Website Talk Only
View previous topic :: View next topic  
Author Message
[TN] Nathan
ALMIGHTY PWNER!


Joined: 14 Feb 2002
Posts: 7406

PostPosted: Sun Nov 21, 2004 5:52 pm    Post subject: Tweaknews hacked! Reply with quote

As you probably very well know now, we had someone gain access to an old admin account and have a little fun on Tweaknews.

This was due to a vital flaw in PHPBB that was unnoticed to today.

Forum has again been upgraded and all holes have been patched up and hopefully this moron can leave us alone so we can help people.
_________________
Owner & Administrator
www.Tweaknews.net
www.Pocketbookpinch.com


Last edited by [TN] Nathan on Thu Sep 29, 2005 11:15 pm; edited 1 time in total
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
Google
Sponsor





PostPosted: Sun Nov 21, 2004 5:52 pm    Post subject: Advertisement

Back to top
JayDubya
TWEAKGURU


Joined: 01 Oct 2003
Posts: 5496
Location: ames, ia

PostPosted: Sun Nov 21, 2004 5:58 pm    Post subject: Reply with quote

Wow, he must be some awesome hacker to find a flaw in script. Its good to hear that all is fixed now. Back to helping others
_________________
JayDubya aka JW Jay JD ^> ﺵ
Back to top
View user's profile Send private message Send e-mail AIM Address Yahoo Messenger MSN Messenger
[TN] Nathan
ALMIGHTY PWNER!


Joined: 14 Feb 2002
Posts: 7406

PostPosted: Sun Nov 21, 2004 6:02 pm    Post subject: Reply with quote

There are two situtations.

1.) He hacked into the computer of a formaer admin and gained access through that.
2.) Took advantage of a small flaw in the recent upgrade we did to Tweaknews.

Either way, they are both gone.
_________________
Owner & Administrator
www.Tweaknews.net
www.Pocketbookpinch.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
Silicon Skum
UberTweaker


Joined: 26 Jul 2004
Posts: 1156
Location: UK, Geordie land

PostPosted: Sun Nov 21, 2004 6:02 pm    Post subject: Reply with quote

My guess is that he used an OLD pearl script to hack the BB, Something similar existed (exists ?) in UBB.

Prize LAMER if ever I saw one!.

Nate, you got his IP?

§
_________________
my sig disappeared from the image host (?)
But at least I have a Josh Award!
Back to top
View user's profile Send private message
[TN] Nathan
ALMIGHTY PWNER!


Joined: 14 Feb 2002
Posts: 7406

PostPosted: Sun Nov 21, 2004 6:04 pm    Post subject: Reply with quote

Yip, if it is even his IP
_________________
Owner & Administrator
www.Tweaknews.net
www.Pocketbookpinch.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
Silicon Skum
UberTweaker


Joined: 26 Jul 2004
Posts: 1156
Location: UK, Geordie land

PostPosted: Sun Nov 21, 2004 6:22 pm    Post subject: Reply with quote

[TN] Nathan wrote:
Yip, if it is even his IP


It's more than likely it IS the IP he was using, but it could be an internet cafe, school, or he might have some intelegence and used a proxy or two. It's tracable but hard if he went through a number of systems.
Best guess, it's a throw-away dialup account. Could be worth checking, he might just be stupid enough to do this from home.

§
_________________
my sig disappeared from the image host (?)
But at least I have a Josh Award!
Back to top
View user's profile Send private message
smith.p.sean
UberTweaker


Joined: 16 Jun 2004
Posts: 1595
Location: orlando, UCF

PostPosted: Sun Nov 21, 2004 7:45 pm    Post subject: Reply with quote

i hope the idiot was stupid enough to leave a trail that we can follow. The first thing i see when i get home from school is tn missing tons of posts and nathans name in green and aveno in yellow and i wasnt shure what had happened then i open my mail and get the mail and i started freakin out.... by the way... hey guys how ya been, but more on that in chit chat.
Back to top
View user's profile Send private message Send e-mail AIM Address MSN Messenger
Hoedizzy
Tweakafile


Joined: 24 Oct 2004
Posts: 856
Location: Bellevue

PostPosted: Sun Nov 21, 2004 8:06 pm    Post subject: Reply with quote

I hope he used his home ip. Then we could get that little pile.
Back to top
View user's profile Send private message AIM Address
Yoshida
UberTweaker


Joined: 24 Dec 2003
Posts: 1219

PostPosted: Sun Nov 21, 2004 8:48 pm    Post subject: Reply with quote

glad to see everything is fixed, you really never think about security until you get hacked, my site got a hacked a few months ago, they didnt damage anything just replaced my index page.
Back to top
View user's profile Send private message
[TN] Nathan
ALMIGHTY PWNER!


Joined: 14 Feb 2002
Posts: 7406

PostPosted: Sun Nov 21, 2004 8:52 pm    Post subject: Reply with quote

Turns out this guy wanted to point out a flaw in our site also.

He wanted to contact the guy I had working on the fix.

He also was a lot better than we initially though, and had more access then we believed.
_________________
Owner & Administrator
www.Tweaknews.net
www.Pocketbookpinch.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
BW
TweakNOOB


Joined: 19 Apr 2004
Posts: 100
Location: Seattle/Chicago

PostPosted: Sun Nov 21, 2004 9:14 pm    Post subject: Reply with quote

Thanks for fixing it so promptly Nate.....keep it up!

Stupid kids...
_________________
p4 3.2 @ 3.46, DFI Lanparty Pro875B, CoolerMaster Jet 4 H/S Fan, Thermaltake Silent purepower 480w PSU, 6800gt AGP Vid. card
1024mb pc2700 Kingston 2,2,2.5,6, 200gb seagate ata hdd, Plextor dr700u DL Burner
Sony cd/rw, Win Xp pro, xaser v6000a
Back to top
View user's profile Send private message
null_set
TweakNOOB


Joined: 22 Sep 2004
Posts: 151
Location: Jersey

PostPosted: Sun Nov 21, 2004 9:16 pm    Post subject: Reply with quote

What sort of access? And what do you mean, was trying to point out a flaw? As in honest grey-hat "I'm bored, I found a hole, you guys should fix this?"
Or as in he caused damage, and happened to leave a note showing how he got in?
_________________
[ ]
chown -R us ./your_base

Back to top
View user's profile Send private message AIM Address
[TN] Nathan
ALMIGHTY PWNER!


Joined: 14 Feb 2002
Posts: 7406

PostPosted: Sun Nov 21, 2004 9:51 pm    Post subject: Reply with quote

Kinda a mix of all.

He caused damage and wanted to point out the flaw.
_________________
Owner & Administrator
www.Tweaknews.net
www.Pocketbookpinch.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
Jason
TweakNOOB


Joined: 05 Nov 2003
Posts: 38
Location: NJ

PostPosted: Sun Nov 21, 2004 10:18 pm    Post subject: Reply with quote

Glad you got control back quickly!! Now buy some new locks for the doors!!
Back to top
View user's profile Send private message Visit poster's website
[TN] Nathan
ALMIGHTY PWNER!


Joined: 14 Feb 2002
Posts: 7406

PostPosted: Sun Nov 21, 2004 10:32 pm    Post subject: Reply with quote

I know, this took me for a loop.
_________________
Owner & Administrator
www.Tweaknews.net
www.Pocketbookpinch.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
smith.p.sean
UberTweaker


Joined: 16 Jun 2004
Posts: 1595
Location: orlando, UCF

PostPosted: Sun Nov 21, 2004 10:44 pm    Post subject: Reply with quote

so... did we lose that section or will it be able to be replaced?
Back to top
View user's profile Send private message Send e-mail AIM Address MSN Messenger
[TN] Nathan
ALMIGHTY PWNER!


Joined: 14 Feb 2002
Posts: 7406

PostPosted: Sun Nov 21, 2004 10:52 pm    Post subject: Reply with quote

We lost three sections:

Announcements
Tweaknews Website General Talk
General Technical Discussion
_________________
Owner & Administrator
www.Tweaknews.net
www.Pocketbookpinch.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
Jason
TweakNOOB


Joined: 05 Nov 2003
Posts: 38
Location: NJ

PostPosted: Sun Nov 21, 2004 10:57 pm    Post subject: Reply with quote

No backups of the db?

2.0.11 from 2.0.10 didn't involve any db changes, so it should work fine... if you have a recent backup.
Back to top
View user's profile Send private message Visit poster's website
[TN] Nathan
ALMIGHTY PWNER!


Joined: 14 Feb 2002
Posts: 7406

PostPosted: Sun Nov 21, 2004 11:04 pm    Post subject: Reply with quote

Yea, we do, but it will take some time to extract just the missing sections.

If I reinstate the backup I will lose all the posts created after it .
_________________
Owner & Administrator
www.Tweaknews.net
www.Pocketbookpinch.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
Ham_fisT
Lord of the Tweak


Joined: 20 Jun 2004
Posts: 2244
Location: Gone Fishin'

PostPosted: Sun Nov 21, 2004 11:06 pm    Post subject: Reply with quote

I'm sure we can all be patient while you get this sorted


(as long as it's done by Morning)
_________________
Yeah....... ok
Back to top
View user's profile Send private message Send e-mail MSN Messenger
smith.p.sean
UberTweaker


Joined: 16 Jun 2004
Posts: 1595
Location: orlando, UCF

PostPosted: Sun Nov 21, 2004 11:34 pm    Post subject: Reply with quote

ok thank goodness. Im going to download the entire tweaknews to my computer too just in case so i can have my own backup incase something like this ever happens again knock on wood.
Back to top
View user's profile Send private message Send e-mail AIM Address MSN Messenger
2old2care
Lord of the Tweak


Joined: 09 Jul 2004
Posts: 2817
Location: Pssst....Over Here

PostPosted: Sun Nov 21, 2004 11:39 pm    Post subject: Reply with quote

Wow....I have a day with the g/f...get HL2...and you guys go get hacked while I'm not here. WTF's up with that....
Well looking at the bright side...I guess the emails from the snotwad woke a few ppl up, that haven't been here for a while.
_________________
.
Liquid-Cooled Q9450 and an EeePC
.
Back to top
View user's profile Send private message
Xal
Lord of the Tweak


Joined: 15 Jul 2004
Posts: 2858
Location: Tweaknation =P

PostPosted: Mon Nov 22, 2004 2:50 am    Post subject: Reply with quote

I'm just glad its fixed, If TN went down my life would lose all meaning
Thanks for the prompt repairs Nate
_________________
Phenom II x4 955 @ Stock
Asus M3N78-EM
4gb Corsair XMS2 DDR2 667 @ 800
1gb Powercolor Radeon HD 5850 @ Stock
X-fi Extreme Audio PCI E
Nexus 600W Silent PSU
Nexus Fans
Custom case
Back to top
View user's profile Send private message Send e-mail Visit poster's website
[TN] Nathan
ALMIGHTY PWNER!


Joined: 14 Feb 2002
Posts: 7406

PostPosted: Mon Nov 22, 2004 3:35 am    Post subject: Reply with quote

No problem.
_________________
Owner & Administrator
www.Tweaknews.net
www.Pocketbookpinch.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
Xal
Lord of the Tweak


Joined: 15 Jul 2004
Posts: 2858
Location: Tweaknation =P

PostPosted: Mon Nov 22, 2004 3:41 am    Post subject: Reply with quote

Hey Nate, that email came from "nobody@www.ipkonfig.com" I suspect that our hacker buddy is a member there but you probably already knew that. I would guess that its a toss away account anyways.
_________________
Phenom II x4 955 @ Stock
Asus M3N78-EM
4gb Corsair XMS2 DDR2 667 @ 800
1gb Powercolor Radeon HD 5850 @ Stock
X-fi Extreme Audio PCI E
Nexus 600W Silent PSU
Nexus Fans
Custom case
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    [TweakNews.net Forum] Forum Index -> Tweaknews Website Talk Only All times are GMT - 5 Hours
Goto page 1, 2, 3, 4  Next
Page 1 of 4

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB3 ©