Back to Main Site
 Welcome Guest ( Log In | Register )

Help | Search | Members | Calendar

 
Board Hacked
« Next Oldest | Next Newest » Track this topic | Email this topic | Print this topic
ceng
  Posted: Jun 7 2005, 08:11 AM


Administrator


Group: Admin
Posts: 1155
Member No.: 1
Joined: 23-August 01



Somebody hacked the board last night and deleted all the posts. I restored from backup but all posts since June 6th at 6:00 AM (EDT) have been lost.

We weren't targeted by some evil Connick hater, we were simply a target of opportunity. There was a security hole reported in Invision Power Board (the software running this forum) a couple weeks ago and somebody just did a Google search for "Powered by Invision" and happened to find this board. What a loser! The type of person who did this is someone we in the security industry refer to as a "script kiddie", meaning they have no technical expertise whatsoever, they just download exploit code off the Internet and run it.

For the technically curious: I've identified the vulnerability (http://www.gulftech.org/?node=research&art...=00073-05052005), found a copy of the exploit code that was most likely used (http://seclists.org/lists/bugtraq/2005/May/0296.html), and patched the hole so that the board is no longer vulnerable to this particular attack.

Working on recovering uploaded images now.

--------------------
I hate signature blocks.
 
      Top
ceng
Posted: Jun 7 2005, 08:18 AM


Administrator


Group: Admin
Posts: 1155
Member No.: 1
Joined: 23-August 01



Uploaded images through May 31st are now recovered. I don't back those up as often as the posts since they take up a lot of space.

--------------------
I hate signature blocks.
 
      Top
0 User(s) are reading this topic (0 Guests and 0 Anonymous Users)
0 Members:
1 replies since Jun 7 2005, 08:11 AM Track this topic | Email this topic | Print this topic

<< Back to Announcements