Announcement
Collapse
No announcement yet.
quaddicted.com hacked?
Collapse
X
-
Its real, around 9am -5GMT he made a comment about it in #qc
At the time it was just a text message (the one he put in the word bubble for the geek) and lots of errors. He has since customized his disdain for the hacker.
-
Yes, it's real. A turkish script kiddie. I will investigate further when I have access to today's logfiles (on the next day).
I made a backup 2 days ago since I smelled it happen.
Comment
-
Originally posted by Aquasharkis the file archive damaged?
No need to worry! :d
Comment
-
So if you need to pull from the backup then the server files were deleted? Mind sharing that ip?
Comment
-
Originally posted by Net-TymeSo if you need to pull from the backup then the server files were deleted? Mind sharing that ip?
I'll definitely share the ip and all other information I find.
Comment
-
That's a shame.
Mambo gives me the impression of being very unsecure.
Solecord, Yellow and I looked at Mambo for QuakeOne.com back around August of last year. Some of the features were nice, the file download section came to mind, but the rest of it seemed very awkward to me and a lot of it did not give the impression of a "mature CMS".
Most CMS systems have something annoying about them. Fortunately, Solecord changes what he does not like :d :dQuakeone.com - Being exactly one-half good and one-half evil has advantages. When a portal opens to the antimatter universe, my opposite is just me with a goatee.
So while you guys all have to fight your anti-matter counterparts, me and my evil twin will be drinking a beer laughing at you guys ...
Comment
-
Originally posted by BakerThat's a shame.
Mambo gives me the impression of being very unsecure.
Solecord, Yellow and I looked at Mambo for QuakeOne.com back around August of last year. Some of the features were nice, the file download section came to mind, but the rest of it seemed very awkward to me and a lot of it did not give the impression of a "mature CMS".
Most CMS systems have something annoying about them. Fortunately, Solecord changes what he does not like :d :d
Comment
-
I installed the latest update for Joomla (new Mambo) 1 or 2 days before that. I think he used an exploit for one of the used components though.
Comment
-
Ok, here's all the info I could get.
The attackers IP was 85.102.110.226
That helps nothing though since according to http://whois.domaintools.com/85.102.110.226 it was just a dynamic IP.
Previously he visited the site with the IP 85.98.140.87
The faulty component was my forum (the image upload part of it).
This is the code that was inserted: http://www.coder Do not give them a referrer from quakeone.com, ie do not click this link but copy&paste it! -ukala.org/C99.txt
It was pretty much my fault not to update the forum component to the latest version...
This probably was the used exploit: http://milw0rm.com/ no referrer exploits/1994
I don't think investigating to the Turk Telekom would help anything. And thus I'll just continue to make fun of the idiot as long as I haven't the site back upLast edited by Solecord; 07-12-2006, 06:33 AM. Reason: stopped links from linking to prevent referrs
Comment
-
We should send him an email with a porno attatchment that's a virus. lole|------------------------0---------------
B|---------------0^1----------------1----
G|---------------2------2------0^2-------
D|---------------2-------2--2-------------
A|---------------0------------------------
E|----------------------------------------
Comment
Comment