VJForums  

Go Back   VJForums > Community > General Chat

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 15th April 2002, 12:35 AM
eXhale's Avatar
eXhale eXhale is offline
video magician
 
Join Date: Apr 2002
Posts: 1,380
Angry It was a hacker

I can now pretty much confirm it's a stupid german hacker who deleted the VJForums database because I just noticed that at the same date, he "hacked" the demo of one of the script I sell and replaced the demo text with some german h4X0r text. The other database he deleted was for the demo of another script of mine so I can see the link easily... He probably thought it was fun to also delete the 3000 messages of this message board. Stupid asshole I dedicate my time & money on a non-profit project and some retarded kid thinks he's superior because he manage to fuck up this project.

Anyway, I have no idea how he hacked into my server, but I'm now backing up the database on a daily basis so even if this asshole starts again, this forum will be back in no time.

Reply With Quote
  #2  
Old 15th April 2002, 12:43 AM
eXhale's Avatar
eXhale eXhale is offline
video magician
 
Join Date: Apr 2002
Posts: 1,380
Default

Oh well, just found how he fucked my server. The script I demoed is an upload script and I stupidely let visitors change the upload settings, so he just allowed PHP files (they are not allowed by default), uploaded a h4X0r PHP script, ran it and did whatever he wanted. Like I said, stupid asshole.

At least I'm glad to know how he did this.
Reply With Quote
  #3  
Old 15th April 2002, 12:53 AM
eXhale's Avatar
eXhale eXhale is offline
video magician
 
Join Date: Apr 2002
Posts: 1,380
Default

More specifically, he uploaded a PHP script designed for h4X0rz which lets you browse a server (and see the PHP source code). Because of the Apache settings, he could only navigate through the same site (ScriptsCenter) but this enabled him to view the MySQL server variables of that other script and he was able to delete all tables. Then, because I was using the same MySQL user/pass for both VJForums and ScriptsCenter (I changed this now), he was also able to delete VJForums data.

Nothing amazing really, I could have done it except I do have some ethics.
Reply With Quote
  #4  
Old 15th April 2002, 04:22 AM
LEVLHED's Avatar
LEVLHED LEVLHED is offline
gear whoreder
 
Join Date: Apr 2002
Location: UNITED STATES
Posts: 3,074
Send a message via Yahoo to LEVLHED
Default

remember when "hacking" meant you just when in, left a calling card to prove you'd done it, and left w/ out wrecking shit?
the good old days.

Ahh well, it is probably best you learned of that vulnerability now, instead of a year from now when Morph reaches his million-th post.
Reply With Quote
  #5  
Old 15th April 2002, 10:00 AM
MoRpH's Avatar
MoRpH MoRpH is offline
Moderator
 
Join Date: Apr 2002
Location: AUSTRALIA
Posts: 3,670
Send a message via ICQ to MoRpH Send a message via AIM to MoRpH Send a message via MSN to MoRpH Send a message via Yahoo to MoRpH
Default

Hahaha... yeah well he would be dying for his crimes then. As it is, is there anyway to track down this lame german script kiddie, cause I'm sending around "the boys" fear not vjforums crew this guy will soon be minus his kneecaps
Reply With Quote
  #6  
Old 16th April 2002, 05:12 PM
Amukidi Amukidi is offline
ExHosts
 
Join Date: Apr 2002
Location: UNITED KINGDOM
Posts: 1,644
Default Whilst you are at it.....

Pump 5 pounds of warm shit into his hog's eye - I believe it smarts a bit!
Reply With Quote
  #7  
Old 16th April 2002, 05:29 PM
MoRpH's Avatar
MoRpH MoRpH is offline
Moderator
 
Join Date: Apr 2002
Location: AUSTRALIA
Posts: 3,670
Send a message via ICQ to MoRpH Send a message via AIM to MoRpH Send a message via MSN to MoRpH Send a message via Yahoo to MoRpH
Default

Now thats a good idea
Reply With Quote
  #8  
Old 16th April 2002, 05:30 PM
Amukidi Amukidi is offline
ExHosts
 
Join Date: Apr 2002
Location: UNITED KINGDOM
Posts: 1,644
Default

LMAO literally!!
Reply With Quote
  #9  
Old 16th April 2002, 05:48 PM
MoRpH's Avatar
MoRpH MoRpH is offline
Moderator
 
Join Date: Apr 2002
Location: AUSTRALIA
Posts: 3,670
Send a message via ICQ to MoRpH Send a message via AIM to MoRpH Send a message via MSN to MoRpH Send a message via Yahoo to MoRpH
Default

I have an arsenal of stupid pictures to go at a moments notice
Reply With Quote
  #10  
Old 16th April 2002, 08:59 PM
elbows's Avatar
elbows elbows is offline
SillyPerson
 
Join Date: Apr 2002
Location: UK
Posts: 2,860
Default

lol nice piccy Show us another one

Did you get the hackers IP address? Was there any evidence that he had spoofed his IP address in some way if you do have it?

Ive been very lucky that my site was never hacked, probably becuase its mostly a closed community forum, but as I now host the visualJockey forums I do worry about security sometimes. Still its on a shared server so its really down to my hosts.

Ive just put a linux server in at work and reading the logs is scray how many lame hack attempts there are. I think most of them are caused by lame script kiddy programs that do a range of exploit-searches, I dont think Ive been deliberately attacked by a human hacker directly yet. In this crazy internet though it can only be a matter of time
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:09 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Ad Management plugin by RedTyger