Houston, we have a problem.

Discussion in 'Shelter Releases' started by The Exception, Sep 4, 2013.

Thread Status:
Not open for further replies.
  1. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    While checking to see why some of the scheduled cleanup functions hadn't been occurring, I found that one of the admincp files had been replaced, like so.


    Meaning someone found a backdoor.
     
    • Agree Agree x 1
  2. Clyde

    Clyde Orange

    Joined:
    Mar 30, 2004
    Messages:
    25,971
    Likes Received:
    8,365
    Trophy Points:
    82
    Ratings:
    +8,368
    First off, thank you. You've always been aces in the tech department! :techman:

    Secondly, is it possible to identify who has been using this backdoor?
     
  3. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    Negative, it appears to have been there for a while, and I'm not even sure it has been used, so it's likely the logs have been purged since then.
     
  4. Tamar Garish

    Tamar Garish Wanna Snuggle? Deceased Member

    Joined:
    Mar 27, 2004
    Messages:
    35,389
    Likes Received:
    22,614
    Trophy Points:
    83
    Gender:
    Female
    Occupation:
    Companion
    Location:
    TARDIS
    Ratings:
    +22,764
    :facepalm:

    Unbelievable!
     
  5. $corp

    $corp Dirty Old Chinaman

    Joined:
    Mar 29, 2004
    Messages:
    15,867
    Likes Received:
    7,087
    Trophy Points:
    63
    Location:
    Calgary, Alberta
    Ratings:
    +7,101
    How do these things get there?
     
  6. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    I'm not quite sure on how it got there, but I would suggest to Lanzman and Order2Chaos that we need to change the server passwords, and if possible start using different passwords for different board functions (ie, a different password for mysql, root access, cpanel, etc.).

    On another note, I've changed the default address that e-mails get sent to when there's a database error, previously it was set to send to Kyle, now it will be sent to exceptions.wordforge@gmail.com.
     
    • Agree Agree x 2
  7. Tamar Garish

    Tamar Garish Wanna Snuggle? Deceased Member

    Joined:
    Mar 27, 2004
    Messages:
    35,389
    Likes Received:
    22,614
    Trophy Points:
    83
    Gender:
    Female
    Occupation:
    Companion
    Location:
    TARDIS
    Ratings:
    +22,764
    Will you be staying on staff again? :pwease:
     
  8. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    Yes, so long as my duties to this board do not encroach majorly on my work life, I will do so.
     
    • Agree Agree x 3
  9. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,186
    Likes Received:
    28,709
    Trophy Points:
    83
    Gender:
    Male
    Occupation:
    Web Designer/Graphic Artist
    Location:
    Someplace high and cold
    Ratings:
    +36,695
    Nick, thanks for shouldering all this. Especially since it had the bad grace to happen while I had to be in New York.

    That said, where do we stand? What do you need from me aside from changing root passwords?
     
    • Agree Agree x 1
  10. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    I need the vBulletin 3.8.1 files. I need to reupload one of them which had been replaced by a hacked file..
     
  11. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    So after some digging, none of the files had been replaced, instead it looks like code that the IRC /me command plugin executes had been hijacked. So far this is the only incidence I've found of it on the server, but I'm going to do a little more digging.

    http://pastebin.com/JaP583uw
     
  12. Tamar Garish

    Tamar Garish Wanna Snuggle? Deceased Member

    Joined:
    Mar 27, 2004
    Messages:
    35,389
    Likes Received:
    22,614
    Trophy Points:
    83
    Gender:
    Female
    Occupation:
    Companion
    Location:
    TARDIS
    Ratings:
    +22,764
    What does it mean? What was the hacking supposed to accomplish?
     
  13. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    Mostly to fuck with people's stuff. Mass deface, etc.
     
  14. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    There do not appear to be any other infected files. Good news.
     
  15. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,186
    Likes Received:
    28,709
    Trophy Points:
    83
    Gender:
    Male
    Occupation:
    Web Designer/Graphic Artist
    Location:
    Someplace high and cold
    Ratings:
    +36,695
    Excellent work, Nick. Thank you.
     
  16. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    [action=The Exception]test[/action]
     
  17. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
    Excellent, the function works after removing the offending code, WOO!
     
  18. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,186
    Likes Received:
    28,709
    Trophy Points:
    83
    Gender:
    Male
    Occupation:
    Web Designer/Graphic Artist
    Location:
    Someplace high and cold
    Ratings:
    +36,695
    [action=Lanzman]approves.[/action]
     
  19. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Likes Received:
    6,161
    Trophy Points:
    83
    Ratings:
    +6,317
  20. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,186
    Likes Received:
    28,709
    Trophy Points:
    83
    Gender:
    Male
    Occupation:
    Web Designer/Graphic Artist
    Location:
    Someplace high and cold
    Ratings:
    +36,695
    Yeah, but under the hood the board is based on PHP, so . . .
     
Thread Status:
Not open for further replies.