Author Topic: Website hacking attempt?  (Read 8083 times)

0 Members and 2 Guests are viewing this topic.

Offline DJ Omnimaga

  • Clacualters are teh gr33t
  • CoT Emeritus
  • LV15 Omnimagician (Next: --)
  • *
  • Posts: 55943
  • Rating: +3154/-232
  • CodeWalrus founder & retired Omnimaga founder
    • View Profile
    • Dream of Omnimaga Music
Website hacking attempt?
« on: June 24, 2011, 01:11:33 am »
There was an attempt at hacking or vandalizing the Omnimaga website around midnight, which caused all forum attachments to go down. This was done via a script used to clean orphaned files that was ran recently on the server and on TIMGUL's a week or two ago. However, the admin who ran the script forgot to remove it afterward, then tonight, somebody who most likely have read the IRC logs and read about that script probably have tried to launch the script in malicious ways to delete content.

Thankfully, all but 118 attachments were put back online about 30 minutes later, thanks to Juju, then we managed to retrieve the 118 missing files afterward to move them in their original location.

Safety measures were quickly employed afterward, so everything should be back to normal now, with all 6509 attached files available again. Sorry for the inconveniences the files downtime might have caused.

Edit by Juju: After further investigation, we found out no hacking or vandalizing was attempted. Said admin accidentally ran the script a second time, causing the attachments folder to be renamed and the attachments system to malfunction. I was able to easily undo the effects under 30 minutes, thankfully. However it was a good thing this was immediately spotted, so we could remove the script now, in case.
« Last Edit: June 24, 2011, 07:55:00 pm by DJ_O »

Offline XVicarious

  • LV6 Super Member (Next: 500)
  • ******
  • Posts: 485
  • Rating: +45/-28
  • I F**king Love Twisty Puzzles
    • View Profile
    • XVicarious
Re: Website hacking attempt
« Reply #1 on: June 24, 2011, 01:13:07 am »
Sigh... People these days... It annoys me. We didn't do anything wrong. That we know of... If you think we did, confront us before you attack us...

Offline Netham45

  • LV11 Super Veteran (Next: 3000)
  • ***********
  • Posts: 2103
  • Rating: +213/-4
  • *explodes*
    • View Profile
Re: Website hacking attempt
« Reply #2 on: June 24, 2011, 01:14:17 am »
My bad on leaving the script on there, I should have known better.
Omnimaga Admin

Offline DJ Omnimaga

  • Clacualters are teh gr33t
  • CoT Emeritus
  • LV15 Omnimagician (Next: --)
  • *
  • Posts: 55943
  • Rating: +3154/-232
  • CodeWalrus founder & retired Omnimaga founder
    • View Profile
    • Dream of Omnimaga Music
Re: Website hacking attempt
« Reply #3 on: June 24, 2011, 01:15:26 am »
It's ok. Normally SMF scripts shows a warning on the forums telling admins to remove them (like upgrade.php, install.php, convert.php, repair_settings.php), but for some reasons that one didn't O.O

Offline Juju

  • Incredibly sexy mare
  • Coder Of Tomorrow
  • LV13 Extreme Addict (Next: 9001)
  • *************
  • Posts: 5730
  • Rating: +500/-19
  • Weird programmer
    • View Profile
    • juju2143's shed
Re: Website hacking attempt
« Reply #4 on: June 24, 2011, 01:16:45 am »
Indeed, the script only renamed the attachments folder away. I renamed it back to where it originally was, then noticed I forgot 118 files (that I thought were incorrectly named) and put them back in the right folder.

No data were lost, fortunately. And, of course, the script was deleted.
« Last Edit: June 24, 2011, 01:18:05 am by juju2143 »

Remember the day the walrus started to fly...

I finally cleared my sig after 4 years you're happy now?
THEGAME
This signature is ridiculously large you've been warned.

The cute mare that used to be in my avatar is Yuki Kagayaki, you can follow her on Facebook and Tumblr.

Offline Jim Bauwens

  • Lua! Nspire! Linux!
  • Editor
  • LV10 31337 u53r (Next: 2000)
  • **********
  • Posts: 1881
  • Rating: +206/-7
  • Linux!
    • View Profile
    • nothing...
Re: Website hacking attempt
« Reply #5 on: June 24, 2011, 02:47:48 am »
I'm glad that nothing bad happened.

Could it be that the script was accessed by accident? Or does someone really have to search for it to find it?

Offline Juju

  • Incredibly sexy mare
  • Coder Of Tomorrow
  • LV13 Extreme Addict (Next: 9001)
  • *************
  • Posts: 5730
  • Rating: +500/-19
  • Weird programmer
    • View Profile
    • juju2143's shed
Re: Website hacking attempt
« Reply #6 on: June 24, 2011, 02:52:08 am »
Either someone got the name of the script on IRC, or Netham45 executed the script a second time by rebooting his browser. In fact it's the latter.

Remember the day the walrus started to fly...

I finally cleared my sig after 4 years you're happy now?
THEGAME
This signature is ridiculously large you've been warned.

The cute mare that used to be in my avatar is Yuki Kagayaki, you can follow her on Facebook and Tumblr.

Offline Netham45

  • LV11 Super Veteran (Next: 3000)
  • ***********
  • Posts: 2103
  • Rating: +213/-4
  • *explodes*
    • View Profile
Re: Website hacking attempt
« Reply #7 on: June 24, 2011, 02:54:38 am »
Once again, mah bad. :P
Omnimaga Admin

Offline aeTIos

  • Nonbinary computing specialist
  • LV12 Extreme Poster (Next: 5000)
  • ************
  • Posts: 3915
  • Rating: +184/-32
    • View Profile
    • wank.party
Re: Website hacking attempt
« Reply #8 on: June 24, 2011, 02:59:32 am »
Great job putting it back up! hope this won't happen too much in the future...
I'm not a nerd but I pretend:

Offline DJ Omnimaga

  • Clacualters are teh gr33t
  • CoT Emeritus
  • LV15 Omnimagician (Next: --)
  • *
  • Posts: 55943
  • Rating: +3154/-232
  • CodeWalrus founder & retired Omnimaga founder
    • View Profile
    • Dream of Omnimaga Music
Re: Website hacking attempt
« Reply #9 on: June 24, 2011, 03:16:14 am »
I see juju, well at least this is solved though.

Offline Munchor

  • LV13 Extreme Addict (Next: 9001)
  • *************
  • Posts: 6199
  • Rating: +295/-121
  • Code Recycler
    • View Profile
Re: Website hacking attempt?
« Reply #10 on: June 24, 2011, 04:04:17 am »
Well, the only thing I notice in this topic, besides a mistake by one of the manager is Juju's good job.

Seriously, Juju saved the attachments and I think he deserves some recognition =D Nice job and thanks!

Offline NeoCrisis

  • LV5 Advanced (Next: 300)
  • *****
  • Posts: 217
  • Rating: +14/-2
  • tihacker59
    • View Profile
Re: Website hacking attempt?
« Reply #11 on: June 24, 2011, 04:54:30 am »
thanks Juju!
some bad people still want to attack and destroy the main TI communities (as TI-Bank and Omnimaga), but we'll fight until death!! >:D



TI-Planet moderator

Offline Munchor

  • LV13 Extreme Addict (Next: 9001)
  • *************
  • Posts: 6199
  • Rating: +295/-121
  • Code Recycler
    • View Profile
Re: Website hacking attempt?
« Reply #12 on: June 24, 2011, 07:30:31 am »
thanks Juju!
some bad people still want to attack and destroy the main TI communities (as TI-Bank and Omnimaga), but we'll fight until death!! >:D

:w00t: Fight until dead, that sounds epic :D

Offline ztrumpet

  • The Rarely Active One
  • CoT Emeritus
  • LV13 Extreme Addict (Next: 9001)
  • *
  • Posts: 5712
  • Rating: +364/-4
  • If you see this, send me a PM. Just for fun.
    • View Profile
Re: Website hacking attempt?
« Reply #13 on: June 24, 2011, 11:10:20 am »
* ZTrumpet eats teh Netham and thanks juju and DJ

Thanks. :D (to you too, Netham.)

Edit: Please note that my edit to the first post was just to add bold. :)
« Last Edit: June 24, 2011, 02:01:15 pm by ztrumpet »

Offline jnesselr

  • King Graphmastur
  • LV11 Super Veteran (Next: 3000)
  • ***********
  • Posts: 2270
  • Rating: +81/-20
  • TAO == epic
    • View Profile
Re: Website hacking attempt?
« Reply #14 on: June 27, 2011, 09:08:50 pm »
Well, glad to see it was resolved at least.  On the off chance that someone did ever hack us, we could use our combined calculator power to DDOS them!

Glad to see that everything is okay now.