justclaws #26 Posted June 23, 2006 Hi Jason, Albert, Ok guys, this is how far the relationship between AA and JSII has come. Al spent this evening fixing my forums. I can't thank Al enough for helping me while my tickets just SAT THERE at my hosting company. That's great to hear, you two being able to talk together to stop these flaming incidents which have been driving people away from the Jaguar "scene", myself included. Cooperative action helps everybody! I hope you both have a big red "hotline" telephone by your desk and/or sofas now. Bravo to Albert for helping Jason out on this, and good luck to you, Jason, on restoring JS-II forums soon. Regards, JustClaws. Quote Share this post Link to post Share on other sites
+doctorclu #27 Posted June 23, 2006 Sorry to hear about this, but glad to hear how it was and is being fixed. Quote Share this post Link to post Share on other sites
jaysmith2000 #28 Posted June 23, 2006 Ok, good news, Al reviewed my access log this morning to do some detective work. And now we know who it WAS! It was SERBLANDER! I'm kidding of course. Actually the person used a google search for IPB v1.3 forums. Mine is tagged at the bottom, so not too hard to find unfortunately. After that, it looks like he used an exploit that hijacks an admin's session, giving him access to the admin panel. He then made some changes there (probably adding the new forum and category), then went back into the forum to post the message that some people noticed, then went back into the admin panel to make more changes. The last thing he did was change the URLs to include that redirect. Which I might add, did not work properly since the forum, since I'm sure the guy's intent was for this redirect to go to his page every time your forum loaded. After that, the hacker left. It doesn't look like he made any changes on any user accounts, which is good. He couldn't really do anything other than a password change which I can fix pretty easily. Good news is there is no way he could bypass the admin password. Phew. Just in case, I've gone out of my way to change every password related to my admin password at every account I have on the net. Overkill I know. Thanks again to Al for all the help! Quote Share this post Link to post Share on other sites
leearco #29 Posted June 23, 2006 And now we know who it WAS! It was SERBLANDER! sounds about right j/k Quote Share this post Link to post Share on other sites
oesii #30 Posted June 23, 2006 And now we know who it WAS! It was SERBLANDER! sounds about right j/k I knew you could never trust those Aussies Glad that everything on JSII should be back up soon. Quote Share this post Link to post Share on other sites
leearco #31 Posted June 23, 2006 And now we know who it WAS! It was SERBLANDER! sounds about right j/k I knew you could never trust those Aussies Glad that everything on JSII should be back up soon. Yer, Aussies are the most untrustworthy people in the world. Quote Share this post Link to post Share on other sites
Serblander #32 Posted June 23, 2006 And now we know who it WAS! It was SERBLANDER! sounds about right j/k @ Jay: I'll try and be more carefull in covering my tracks next time! @ Lee: You and your monkeys! Quote Share this post Link to post Share on other sites
leearco #33 Posted June 23, 2006 And now we know who it WAS! It was SERBLANDER! sounds about right j/k @ Jay: I'll try and be more carefull in covering my tracks next time! @ Lee: You and your monkeys! Monkeys are the best. Quote Share this post Link to post Share on other sites
jaysmith2000 #34 Posted June 23, 2006 Forums are still updating. 9 hours. If you guys wouldn't post so much that would have sped things up! Argh! They haven't given me at ETA for it to be done, but will let everyone know when we're back online. It's going to look very different since Al while he was in the database changed the name to Atari Age TOO with a subline saying "sequels are never as good as the originals". Quote Share this post Link to post Share on other sites
leearco #35 Posted June 23, 2006 Forums are still updating. 9 hours. If you guys wouldn't post so much that would have sped things up! Argh! They haven't given me at ETA for it to be done, but will let everyone know when we're back online. It's going to look very different since Al while he was in the database changed the name to Atari Age TOO with a subline saying "sequels are never as good as the originals". 9 friggin hours. Quote Share this post Link to post Share on other sites
walter_J64bit #36 Posted June 23, 2006 Forums are still updating. 9 hours. If you guys wouldn't post so much that would have sped things up! Argh! They haven't given me at ETA for it to be done, but will let everyone know when we're back online. It's going to look very different since Al while he was in the database changed the name to Atari Age TOO with a subline saying "sequels are never as good as the originals". LOL Atari Age TOO ,but any way I'll be happy when JSII is back up and running. Quote Share this post Link to post Share on other sites
LinkoVitch #37 Posted June 23, 2006 Actually the person used a google search for IPB v1.3 forums. Mine is tagged at the bottom, so not too hard to find unfortunately. After that, it looks like he used an exploit that hijacks an admin's session, giving him access to the admin panel. He then made some changes there (probably adding the new forum and category), then went back into the forum to post the message that some people noticed, then went back into the admin panel to make more changes. The last thing he did was change the URLs to include that redirect. Which I might add, did not work properly since the forum, since I'm sure the guy's intent was for this redirect to go to his page every time your forum loaded. After that, the hacker left. Actually I think his intentions may have been otherwise JagFest.org got knobbled a while back and the attacker left a redirect in, from what I can tell it was collecting the data being posted to the forum and sending it to his server. This may have been what they were planning to do to your site too. evil buggers Quote Share this post Link to post Share on other sites
Dragonforce-Europe #38 Posted June 23, 2006 And now we know who it WAS! It was SERBLANDER! sounds about right j/k @ Jay: I'll try and be more carefull in covering my tracks next time! @ Lee: You and your monkeys! Monkeys are the best. i liked that monkey face picture of yours when that monkey was shitting tough. Quote Share this post Link to post Share on other sites
Dragonforce-Europe #39 Posted June 23, 2006 And now we know who it WAS! It was SERBLANDER! sounds about right j/k @ Jay: I'll try and be more carefull in covering my tracks next time! @ Lee: You and your monkeys! Monkeys are the best. i liked that monkey face picture of yours when that monkey was shitting tough. Quote Share this post Link to post Share on other sites
leearco #40 Posted June 23, 2006 And now we know who it WAS! It was SERBLANDER! sounds about right j/k @ Jay: I'll try and be more carefull in covering my tracks next time! @ Lee: You and your monkeys! Monkeys are the best. i liked that monkey face picture of yours when that monkey was shitting tough. Huh? shititittiing, never had that. had a jif monkey urinating, and an albino ape with a scrunched face. never scatting (lol) Oh i get it now, the albino one, scrunched face = scatting. Quote Share this post Link to post Share on other sites
Serblander #41 Posted June 23, 2006 i liked that monkey face picture of yours when that monkey was shitting tough. Huh? shititittiing, never had that. had a jif monkey urinating,... You sick bastard! Quote Share this post Link to post Share on other sites
Albert #42 Posted June 23, 2006 Actually I think his intentions may have been otherwise JagFest.org got knobbled a while back and the attacker left a redirect in, from what I can tell it was collecting the data being posted to the forum and sending it to his server. This may have been what they were planning to do to your site too. evil buggers It's possible, I've seen a few different types of these hacks. Some try to collect information, others simply redirect your site to another website instead ("You've been hacked! Muhahahah!") and others will try to download a virus onto your computer. And then there are more disastrous hacks, where the entire site and/or database is wiped clean (fortunately that was not the case here). Looks like this was a partially botched hack attempt, since all the links were broken instead of going to the hacker's website. Probably an entry-level scriptkiddy. ..Al Quote Share this post Link to post Share on other sites
Dragonforce-Europe #43 Posted June 23, 2006 Huh?shititittiing, never had that. had a jif monkey urinating, and an albino ape with a scrunched face. never scatting (lol) Oh i get it now, the albino one, scrunched face = scatting. Could you show that one again? (not the one urinating. you can keep that for your own personal entertainment ) Quote Share this post Link to post Share on other sites
leearco #44 Posted June 23, 2006 Huh?shititittiing, never had that. had a jif monkey urinating, and an albino ape with a scrunched face. never scatting (lol) Oh i get it now, the albino one, scrunched face = scatting. Could you show that one again? (not the one urinating. you can keep that for your own personal entertainment ) done Mr. Checkered Flag Quote Share this post Link to post Share on other sites
Dragonforce-Europe #45 Posted June 23, 2006 Huh?shititittiing, never had that. had a jif monkey urinating, and an albino ape with a scrunched face. never scatting (lol) Oh i get it now, the albino one, scrunched face = scatting. Could you show that one again? (not the one urinating. you can keep that for your own personal entertainment ) done Mr. Checkered Flag its a classic! Quote Share this post Link to post Share on other sites
tynstar #46 Posted June 23, 2006 Well that really sucks. I was looking at the Funny threads forum when the site went down. Hackers like this should be dragged out of their parents basements and beat. For a while seemed like DP was being hacked a lot. Quote Share this post Link to post Share on other sites
jaysmith2000 #47 Posted June 23, 2006 Well that really sucks. I was looking at the Funny threads forum when the site went down. Hackers like this should be dragged out of their parents basements and beat. For a while seemed like DP was being hacked a lot. Yeah, I noticed you're loving that thread Tynstar! I had you pegged for the Bikini thread, but who knows? LOL.... This is really, in the end, my fault. I should have upgraded the forums a long time ago. There was just no reason to stay on the old software other than the fact I didn't want to add a ton of work to my plate. Quote Share this post Link to post Share on other sites
jaysmith2000 #48 Posted June 23, 2006 Ok, potentially bad news here. Just got an update and the standard time for an upgrade is 1-2 BUSINESS days. If they get it finished today we're golden, but if not, no JSII for the weekend. Wow, I might actually have free time! Woohoo! Quote Share this post Link to post Share on other sites
Phineasfool #49 Posted June 23, 2006 Ok, potentially bad news here. Just got an update and the standard time for an upgrade is 1-2 BUSINESS days. If they get it finished today we're golden, but if not, no JSII for the weekend. Wow, I might actually have free time! Woohoo! What? Are you saying I might have to actually do something constructive this weekend? Quote Share this post Link to post Share on other sites
tynstar #50 Posted June 23, 2006 Ok, potentially bad news here. Just got an update and the standard time for an upgrade is 1-2 BUSINESS days. If they get it finished today we're golden, but if not, no JSII for the weekend. Wow, I might actually have free time! Woohoo! NOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO!!!!!!!!!!! I don't think it is your fault. You didn't upgrade but you didn't hack the site. I took a screenshot of the forums page when it was first hacked incase you didn't see it. I don't know how bad the site got before you saw it. Quote Share this post Link to post Share on other sites