Houston, we have a problem.

Discussion in 'Shelter Releases' started by The Exception, Sep 4, 2013.

Thread Status:
Not open for further replies.
  1. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    While checking to see why some of the scheduled cleanup functions hadn't been occurring, I found that one of the admincp files had been replaced, like so.


    Meaning someone found a backdoor.
    • Agree Agree x 1
  2. Clyde

    Clyde Orange

    Joined:
    Mar 30, 2004
    Messages:
    25,971
    Ratings:
    +8,368
    First off, thank you. You've always been aces in the tech department! :techman:

    Secondly, is it possible to identify who has been using this backdoor?
  3. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    Negative, it appears to have been there for a while, and I'm not even sure it has been used, so it's likely the logs have been purged since then.
  4. Tamar Garish

    Tamar Garish Wanna Snuggle? Deceased Member

    Joined:
    Mar 27, 2004
    Messages:
    35,389
    Location:
    TARDIS
    Ratings:
    +22,764
    :facepalm:

    Unbelievable!
  5. $corp

    $corp Dirty Old Chinaman

    Joined:
    Mar 29, 2004
    Messages:
    15,867
    Location:
    Calgary, Alberta
    Ratings:
    +7,101
    How do these things get there?
  6. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    I'm not quite sure on how it got there, but I would suggest to Lanzman and Order2Chaos that we need to change the server passwords, and if possible start using different passwords for different board functions (ie, a different password for mysql, root access, cpanel, etc.).

    On another note, I've changed the default address that e-mails get sent to when there's a database error, previously it was set to send to Kyle, now it will be sent to exceptions.wordforge@gmail.com.
    • Agree Agree x 2
  7. Tamar Garish

    Tamar Garish Wanna Snuggle? Deceased Member

    Joined:
    Mar 27, 2004
    Messages:
    35,389
    Location:
    TARDIS
    Ratings:
    +22,764
    Will you be staying on staff again? :pwease:
  8. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    Yes, so long as my duties to this board do not encroach majorly on my work life, I will do so.
    • Agree Agree x 3
  9. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,169
    Location:
    Someplace high and cold
    Ratings:
    +36,651
    Nick, thanks for shouldering all this. Especially since it had the bad grace to happen while I had to be in New York.

    That said, where do we stand? What do you need from me aside from changing root passwords?
    • Agree Agree x 1
  10. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    I need the vBulletin 3.8.1 files. I need to reupload one of them which had been replaced by a hacked file..
  11. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    So after some digging, none of the files had been replaced, instead it looks like code that the IRC /me command plugin executes had been hijacked. So far this is the only incidence I've found of it on the server, but I'm going to do a little more digging.

    http://pastebin.com/JaP583uw
  12. Tamar Garish

    Tamar Garish Wanna Snuggle? Deceased Member

    Joined:
    Mar 27, 2004
    Messages:
    35,389
    Location:
    TARDIS
    Ratings:
    +22,764
    What does it mean? What was the hacking supposed to accomplish?
  13. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    Mostly to fuck with people's stuff. Mass deface, etc.
  14. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    There do not appear to be any other infected files. Good news.
  15. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,169
    Location:
    Someplace high and cold
    Ratings:
    +36,651
    Excellent work, Nick. Thank you.
  16. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    [action=The Exception]test[/action]
  17. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
    Excellent, the function works after removing the offending code, WOO!
  18. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,169
    Location:
    Someplace high and cold
    Ratings:
    +36,651
    [action=Lanzman]approves.[/action]
  19. The Exception

    The Exception The One Who Will Be Administrator Super Moderator

    Joined:
    Apr 10, 2004
    Messages:
    21,942
    Ratings:
    +6,317
  20. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,169
    Location:
    Someplace high and cold
    Ratings:
    +36,651
    Yeah, but under the hood the board is based on PHP, so . . .
Thread Status:
Not open for further replies.