Jump to content
Paolo

PANIC! JS2 owned!

Recommended Posts

Hi Jason, Albert,

Ok guys, this is how far the relationship between AA and JSII has come. Al spent this evening fixing my forums. I can't thank Al enough for helping me while my tickets just SAT THERE at my hosting company.
That's great to hear, you two being able to talk together to stop these flaming incidents which have been driving people away from the Jaguar "scene", myself included. Cooperative action helps everybody! I hope you both have a big red "hotline" telephone by your desk and/or sofas now. :D

Bravo to Albert for helping Jason out on this, and good luck to you, Jason, on restoring JS-II forums soon.

Regards,

JustClaws.

Share this post


Link to post
Share on other sites

Sorry to hear about this, but glad to hear how it was and is being fixed.

Share this post


Link to post
Share on other sites

Ok, good news, Al reviewed my access log this morning to do some detective work. And now we know who it WAS! It was SERBLANDER! :D I'm kidding of course.

 

Actually the person used a google search for IPB v1.3 forums. Mine is tagged at the bottom, so not too hard to find unfortunately. After that, it looks like he used an exploit that hijacks an admin's session, giving him access to the admin panel. He then made some changes there (probably adding the new forum and category), then went back into the forum to post the message that some people noticed, then went back into the admin panel to make more changes. The last thing he did was change the URLs to include that redirect. Which I might add, did not work properly since the forum, since I'm sure the guy's intent was for this redirect to go to his page every time your forum loaded. After that, the hacker left.

 

It doesn't look like he made any changes on any user accounts, which is good. :) He couldn't really do anything other than a password change which I can fix pretty easily. Good news is there is no way he could bypass the admin password. Phew. Just in case, I've gone out of my way to change every password related to my admin password at every account I have on the net. Overkill I know.

 

Thanks again to Al for all the help!

Share this post


Link to post
Share on other sites
And now we know who it WAS! It was SERBLANDER!

 

sounds about right :D

 

j/k

 

 

I knew you could never trust those Aussies ;)

 

Glad that everything on JSII should be back up soon.

Share this post


Link to post
Share on other sites
And now we know who it WAS! It was SERBLANDER!

 

sounds about right :D

 

j/k

 

 

I knew you could never trust those Aussies ;)

 

Glad that everything on JSII should be back up soon.

 

Yer, Aussies are the most untrustworthy people in the world. ;)

Share this post


Link to post
Share on other sites
And now we know who it WAS! It was SERBLANDER!

 

sounds about right :D

 

j/k

@ Jay: I'll try and be more carefull in covering my tracks next time! :D

 

@ Lee: You and your monkeys! :lolblue:

Share this post


Link to post
Share on other sites
And now we know who it WAS! It was SERBLANDER!

 

sounds about right :D

 

j/k

@ Jay: I'll try and be more carefull in covering my tracks next time! :D

 

@ Lee: You and your monkeys! :lolblue:

 

Monkeys are the best.

Share this post


Link to post
Share on other sites

Forums are still updating. 9 hours. If you guys wouldn't post so much that would have sped things up! Argh! They haven't given me at ETA for it to be done, but will let everyone know when we're back online. It's going to look very different since Al while he was in the database changed the name to Atari Age TOO with a subline saying "sequels are never as good as the originals". :D

Share this post


Link to post
Share on other sites

Forums are still updating. 9 hours. If you guys wouldn't post so much that would have sped things up! Argh! They haven't given me at ETA for it to be done, but will let everyone know when we're back online. It's going to look very different since Al while he was in the database changed the name to Atari Age TOO with a subline saying "sequels are never as good as the originals". :D

9 friggin hours. :P

Share this post


Link to post
Share on other sites

Forums are still updating. 9 hours. If you guys wouldn't post so much that would have sped things up! Argh! They haven't given me at ETA for it to be done, but will let everyone know when we're back online. It's going to look very different since Al while he was in the database changed the name to Atari Age TOO with a subline saying "sequels are never as good as the originals". :D

LOL Atari Age TOO ,but any way I'll be happy when JSII is back up and running. :D

Share this post


Link to post
Share on other sites

Actually the person used a google search for IPB v1.3 forums. Mine is tagged at the bottom, so not too hard to find unfortunately. After that, it looks like he used an exploit that hijacks an admin's session, giving him access to the admin panel. He then made some changes there (probably adding the new forum and category), then went back into the forum to post the message that some people noticed, then went back into the admin panel to make more changes. The last thing he did was change the URLs to include that redirect. Which I might add, did not work properly since the forum, since I'm sure the guy's intent was for this redirect to go to his page every time your forum loaded. After that, the hacker left.

 

Actually I think his intentions may have been otherwise JagFest.org got knobbled a while back and the attacker left a redirect in, from what I can tell it was collecting the data being posted to the forum and sending it to his server. This may have been what they were planning to do to your site too.

 

evil buggers

Share this post


Link to post
Share on other sites
And now we know who it WAS! It was SERBLANDER!

 

sounds about right :D

 

j/k

@ Jay: I'll try and be more carefull in covering my tracks next time! :D

 

@ Lee: You and your monkeys! :lolblue:

 

Monkeys are the best.

 

 

i liked that monkey face picture of yours when that monkey was shitting tough. :D

Share this post


Link to post
Share on other sites
And now we know who it WAS! It was SERBLANDER!

 

sounds about right :D

 

j/k

@ Jay: I'll try and be more carefull in covering my tracks next time! :D

 

@ Lee: You and your monkeys! :lolblue:

 

Monkeys are the best.

 

 

i liked that monkey face picture of yours when that monkey was shitting tough. :D

Share this post


Link to post
Share on other sites
And now we know who it WAS! It was SERBLANDER!

 

sounds about right :D

 

j/k

@ Jay: I'll try and be more carefull in covering my tracks next time! :D

 

@ Lee: You and your monkeys! :lolblue:

 

Monkeys are the best.

 

 

i liked that monkey face picture of yours when that monkey was shitting tough. :D

Huh?

shititittiing, never had that. had a jif monkey urinating, and an albino ape with a scrunched face. never scatting (lol)

Oh i get it now, the albino one, scrunched face = scatting. :D

Share this post


Link to post
Share on other sites

i liked that monkey face picture of yours when that monkey was shitting tough. :D

Huh?

shititittiing, never had that. had a jif monkey urinating,...

You sick bastard! :lolblue:

Share this post


Link to post
Share on other sites
Actually I think his intentions may have been otherwise JagFest.org got knobbled a while back and the attacker left a redirect in, from what I can tell it was collecting the data being posted to the forum and sending it to his server. This may have been what they were planning to do to your site too.

 

evil buggers

It's possible, I've seen a few different types of these hacks. Some try to collect information, others simply redirect your site to another website instead ("You've been hacked! Muhahahah!") and others will try to download a virus onto your computer. And then there are more disastrous hacks, where the entire site and/or database is wiped clean (fortunately that was not the case here). Looks like this was a partially botched hack attempt, since all the links were broken instead of going to the hacker's website. Probably an entry-level scriptkiddy.

 

..Al

Share this post


Link to post
Share on other sites
Huh?

shititittiing, never had that. had a jif monkey urinating, and an albino ape with a scrunched face. never scatting (lol)

Oh i get it now, the albino one, scrunched face = scatting. :D

 

 

Could you show that one again? (not the one urinating. you can keep that for your own personal entertainment :P )

Share this post


Link to post
Share on other sites
Huh?

shititittiing, never had that. had a jif monkey urinating, and an albino ape with a scrunched face. never scatting (lol)

Oh i get it now, the albino one, scrunched face = scatting. :D

 

 

Could you show that one again? (not the one urinating. you can keep that for your own personal entertainment :P )

done Mr. Checkered Flag

Share this post


Link to post
Share on other sites
Huh?

shititittiing, never had that. had a jif monkey urinating, and an albino ape with a scrunched face. never scatting (lol)

Oh i get it now, the albino one, scrunched face = scatting. :D

 

 

Could you show that one again? (not the one urinating. you can keep that for your own personal entertainment :P )

done Mr. Checkered Flag

 

 

its a classic! :D

Share this post


Link to post
Share on other sites

Well that really sucks. I was looking at the Funny threads forum when the site went down.

 

Hackers like this should be dragged out of their parents basements and beat.

 

For a while seemed like DP was being hacked a lot.

Share this post


Link to post
Share on other sites

Well that really sucks. I was looking at the Funny threads forum when the site went down.

 

Hackers like this should be dragged out of their parents basements and beat.

 

For a while seemed like DP was being hacked a lot.

 

Yeah, I noticed you're loving that thread Tynstar! I had you pegged for the Bikini thread, but who knows? LOL....

 

This is really, in the end, my fault. I should have upgraded the forums a long time ago. There was just no reason to stay on the old software other than the fact I didn't want to add a ton of work to my plate.

Share this post


Link to post
Share on other sites

Ok, potentially bad news here. Just got an update and the standard time for an upgrade is 1-2 BUSINESS days. If they get it finished today we're golden, but if not, no JSII for the weekend. Wow, I might actually have free time! Woohoo! :D

Share this post


Link to post
Share on other sites

Ok, potentially bad news here. Just got an update and the standard time for an upgrade is 1-2 BUSINESS days. If they get it finished today we're golden, but if not, no JSII for the weekend. Wow, I might actually have free time! Woohoo! :D

 

What? Are you saying I might have to actually do something constructive this weekend?

Share this post


Link to post
Share on other sites

Ok, potentially bad news here. Just got an update and the standard time for an upgrade is 1-2 BUSINESS days. If they get it finished today we're golden, but if not, no JSII for the weekend. Wow, I might actually have free time! Woohoo! :D

 

NOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO!!!!!!!!!!!

 

 

I don't think it is your fault. You didn't upgrade but you didn't hack the site.

 

I took a screenshot of the forums page when it was first hacked incase you didn't see it. I don't know how bad the site got before you saw it.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...