![]() ![]() |
| LifeMirage |
Dec 06, 2006, 12:57 PM
Post
#1
|
![]() Demi-God ![]() ![]() ![]() ![]() ![]() Group: Global Mod Posts: 974 Joined: Apr 13, 2005 From: Netherlands Member No.: 4349 |
The site was down at 2:45 pm central time with some other webpage was in it's place. I assume the site was hacked?
|
| Shawn |
Dec 06, 2006, 01:03 PM
Post
#2
|
![]() God ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 1498 Joined: Jan 22, 2003 From: CA Member No.: 9 |
yes, it was. A first for BrainMeta. Besides brainmeta.com, there are two other websites hosted on this server, but they were not effected. I'm looking into it.
|
| code buttons |
Dec 06, 2006, 01:22 PM
Post
#3
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 2450 Joined: Oct 05, 2005 Member No.: 4556 |
|
| Shawn |
Dec 06, 2006, 01:37 PM
Post
#4
|
![]() God ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 1498 Joined: Jan 22, 2003 From: CA Member No.: 9 |
I believe I have fixed the issue. It involved, in part, a security hole in PHP.
|
| Enki |
Dec 06, 2006, 01:55 PM
Post
#5
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 2794 Joined: Sep 10, 2004 From: Eridug Member No.: 3458 |
It was something unbelievable.
Hope the hacker can be located by NSA soon. |
| Enki |
Dec 06, 2006, 01:56 PM
Post
#6
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 2794 Joined: Sep 10, 2004 From: Eridug Member No.: 3458 |
Should we change passwords Shawn?
|
| Shawn |
Dec 06, 2006, 02:03 PM
Post
#7
|
![]() God ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 1498 Joined: Jan 22, 2003 From: CA Member No.: 9 |
I think it was someone with an IP address indicating they were from Dubai. You do not have to worry about changing passwords since they are encrypted on the server.
|
| Enki |
Dec 06, 2006, 02:05 PM
Post
#8
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 2794 Joined: Sep 10, 2004 From: Eridug Member No.: 3458 |
Hope some one will be able to teach them a good lesson!
It is a matter of honor to teach them a lesson. Though it looked liked as Jihad hacking but I guess it is another source. Hope 007 can locate them and punish properly. |
| Enki |
Dec 06, 2006, 03:42 PM
Post
#9
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 2794 Joined: Sep 10, 2004 From: Eridug Member No.: 3458 |
I think it was someone with an IP address indicating they were from Dubai. You do not have to worry about changing passwords since they are encrypted on the server. Interesting who from Dubai, at presence of such security measures can dare to hack a server in America. I really do wonder. What a trick. It once again shows how vulnerable the civilization is to the cyber-terrorism. |
| maximus242 |
Dec 06, 2006, 05:13 PM
Post
#10
|
![]() God ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 1751 Joined: Jan 24, 2006 Member No.: 4768 |
Cyber terrorism on brainmeta? what?!? Couldnt it just be come kid hacker from Dubai who has nothing better to do than hack websites?
..WTH did my avatar go Edit: Fixed Avatar |
| Shawn |
Dec 06, 2006, 06:02 PM
Post
#11
|
![]() God ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 1498 Joined: Jan 22, 2003 From: CA Member No.: 9 |
Ok. I have looked into it further and here is what happened. Someone from Cairo with IP 196.218.12.128 (they were not going through a proxy) used the file uploader to upload a file with a .php.gif extension. The file uploader thought it was a .gif file, so it uploaded it, but if you loaded the file in your browser, it would execute the .php script (which is what the file really was, not a .gif). The PHP script was a PHP shell script and directory browser, which enabled the user to delete and modify files. All files were recovered via backups (except for some recently uploaded pics) and the security hole in the file uploader was fixed. The attacker left a big trail, was sloppy, and could have done much worse, which suggests the person was an unsophisticated novice . Nonetheless, incidents like this underscore the fact that brainmeta.com is not invulnerable to attack, though I will do what I can to prevent further incidents.
|
| Flex |
Dec 06, 2006, 06:37 PM
Post
#12
|
|
God ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 1894 Joined: Oct 17, 2006 From: Bay area CA Member No.: 5877 |
Lol I do not get what motive the individual could possibly have... What could be gained from hacking Brain Meta?
|
| maximus242 |
Dec 06, 2006, 07:18 PM
Post
#13
|
![]() God ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 1751 Joined: Jan 24, 2006 Member No.: 4768 |
The biggest thing puzzling me is the Why, I suspect it is someone with just to much time on their hands or... the anti-christ of brain meta, dattaswami II.
|
| Shawn |
Dec 06, 2006, 07:31 PM
Post
#14
|
![]() God ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 1498 Joined: Jan 22, 2003 From: CA Member No.: 9 |
I'm glad they didn't do any real damage, and it was somewhat amusing while it lasted.... and I got to learn about a great PHP shell script and directory browser. Here's a screenshot of the hack for those who missed it.
|
| Flex |
Dec 06, 2006, 08:03 PM
Post
#15
|
|
God ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 1894 Joined: Oct 17, 2006 From: Bay area CA Member No.: 5877 |
Ok I have to admit--that is hardcore (except the layout looks pretty shody). Just curious, but why is Shawn member number 9 instead of 1?
|
| Hey Hey |
Dec 06, 2006, 08:56 PM
Post
#16
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 7763 Joined: Dec 31, 2003 Member No.: 845 |
ameer atom in the universe of Brainmeta.
Well done Shawn for sorting it out so quickly. |
| Enki |
Dec 06, 2006, 11:03 PM
Post
#17
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 2794 Joined: Sep 10, 2004 From: Eridug Member No.: 3458 |
|
| Enki |
Dec 06, 2006, 11:21 PM
Post
#18
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 2794 Joined: Sep 10, 2004 From: Eridug Member No.: 3458 |
ameer atom in the universe of Brainmeta. Well done Shawn for sorting it out so quickly. Hahahahahah. Irrationality in the Universe of Wisdom. Btw, possibly he is one of the users on Brainmeta. Ameer are you here? I can tell you a fantastic story about Archangel Jebrail and about a device Mohammed was using to fly on from Arabia to Jerusalem. Really. It is a fairy tale. So do not do that again with Bainmeta, otherwise the “Gods†from Brainmeta may punish you. |
| Hey Hey |
Dec 07, 2006, 01:51 AM
Post
#19
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 7763 Joined: Dec 31, 2003 Member No.: 845 |
Ok I have to admit--that is hardcore (except the layout looks pretty shody). Just curious, but why is Shawn member number 9 instead of 1? Good question. Why number 1 turned into number 9? Shawn is that you? Also, interestingly, who is number 1? |
| Trip like I do |
Dec 07, 2006, 01:57 PM
Post
#20
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 5143 Joined: Aug 11, 2004 From: Earth^2 Member No.: 3202 |
Hey.... my avatar mysteriously changed again. What's up with that?
|
| code buttons |
Dec 07, 2006, 02:15 PM
Post
#21
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 2450 Joined: Oct 05, 2005 Member No.: 4556 |
Hey.... my avatar mysteriously changed again. What's up with that? I think there was another hack attempt. About 12 or so today BM was not available. I was logged-in at the time and when I hit refresh it dissapeared and I got an error message instead. There was no webpage in place this time, like yesterday, though. Shawn, what if yesterday's "sloppy" hack , as you put it, was some kind of test before a bigger or more organized attepmpt? |
| Rick |
Dec 07, 2006, 02:19 PM
Post
#22
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 5916 Joined: Jul 23, 2004 From: Sunny Southern California Member No.: 3068 |
BrainMeta is a natural target for jihadist attack for the same reason that I come here. Any place of free exchange of ideas and thoughtful free deliberation is a threat to monotheistic certainty.
|
| Shawn |
Dec 07, 2006, 04:24 PM
Post
#23
|
![]() God ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 1498 Joined: Jan 22, 2003 From: CA Member No.: 9 |
unfortunately there was another attack earlier today. I have not been able to confirm that it was the same person, and this time they attempted to delete as much as they could. I have increased the security on the server, with the result that uploading files has been disabled for the time being, at least until a better solution is put into place.
|
| Flex |
Dec 07, 2006, 04:26 PM
Post
#24
|
|
God ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 1894 Joined: Oct 17, 2006 From: Bay area CA Member No.: 5877 |
Well I guess that explains why I could not upload a screen shot from the attack...
|
| Trip like I do |
Dec 07, 2006, 05:08 PM
Post
#25
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 5143 Joined: Aug 11, 2004 From: Earth^2 Member No.: 3202 |
.... and explains why I now have no avatar.
|
| Flex |
Dec 07, 2006, 05:25 PM
Post
#26
|
|
God ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 1894 Joined: Oct 17, 2006 From: Bay area CA Member No.: 5877 |
|
| Rick |
Dec 07, 2006, 05:33 PM
Post
#27
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 5916 Joined: Jul 23, 2004 From: Sunny Southern California Member No.: 3068 |
Minimalism? I see no avatar now (at this exact momen) when a while ago I was his very nice abstract artwork in a horizontal position with Trip standing by it.
|
| maximus242 |
Dec 07, 2006, 08:29 PM
Post
#28
|
![]() God ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 1751 Joined: Jan 24, 2006 Member No.: 4768 |
Seems we also have a spammer who keeps on posting nonsense, this could be the same person. I just deleted one of his spamming topics and moderators will have already seen the reports from HeyHey. It cant be coincidence that there is a spammer and a hacker at the same time, can it?
Any ideas, thoughts on the connection and how to combat our new found internet assailants? |
| Hey Hey |
Dec 07, 2006, 09:02 PM
Post
#29
|
![]() Supreme God ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Basic Member Posts: 7763 Joined: Dec 31, 2003 Member No.: 845 |
Seems we also have a spammer who keeps on posting nonsense, this could be the same person. I just deleted one of his spamming topics and moderators will have already seen the reports from HeyHey. It cant be coincidence that there is a spammer and a hacker at the same time, can it? Any ideas, thoughts on the connection and how to combat our new found internet assailants? Seems we also have a spammer who keeps on posting nonsense, this could be the same person. I just deleted one of his spamming topics and moderators will have already seen the reports from HeyHey. It cant be coincidence that there is a spammer and a hacker at the same time, can it? Any ideas, thoughts on the connection and how to combat our new found internet assailants? I have been deleting lots of rubbish (not not yours We could have a ?? dollar registration fee to all new members, refunded after a ??. Or more registration information required. I know this could be false but the time it would take might put them off. Do they presently need to have a verifiable email address that would mean their ISP could take action. Oh I don't know, let's form a hit squad and take them out! Perhaps we could post replies with recommendations of medication for their condition ... could include suicide pills. |
| LifeMirage |
Dec 07, 2006, 09:13 PM
Post
#30
|
![]() Demi-God ![]() ![]() ![]() ![]() ![]() Group: Global Mod Posts: 974 Joined: Apr 13, 2005 From: Netherlands Member No.: 4349 |
E-mail confirmation and enabling moderators to view and block the IP from spammers should help greatly.
Not sure about offering donation/registration fees again based on what happened last time. |
![]() ![]() |
| Lo-Fi Version | Time is now: 22nd May 2013 - 07:50 AM |