Home Marketplace Articles FAQ Gallery Arcade
Join FireBlades.org! Unanswered Posts New Posts Today's Posts Search Mark Forums Read
Go Back   Honda Motorcycles - FireBlades.org Forums > General Motorcycling > General Discussion

General Discussion: General Motorcycle Discussion. If it's related to motorcycles in any way, and doesn't fit into a more specific forum, it goes here.
Forgot your User Name or Password?
Not a member? Join today!





Some dickheads hacked VFRdiscussion.com

Reply
 
Thread Tools
Old 10-20-2005, 12:11 AM
  #1
 
Join Date: 05-09-2003
Location: Ann Arbor, Michigan
Bike(s): '92 VFR750F, SV650 track tool. 954 no more!
Posts: 4,806
Rep: CBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud of (1495)
Rep Power: 24
Some dickheads hacked VFRdiscussion.com

That's a non-controversial, inoffensive site. Makes me mad. I trust Conq has this site protected.

Anyway, if some tech guru here can offer help, please email ULEWZ. He's a member here and a mod over there.

http://www.fireblades.org/forums/members/ulewz.html

CBRVFR is offline  
View CBRVFR's Profile View CBRVFR's Gallery Find More Posts by CBRVFR
Reply With Quote Go To Top
Old 10-20-2005, 12:17 AM
  #2
Resigned to pursue other interests.
 
ConqSoft's Avatar
 
Join Date: 05-01-2001
Location: Raleigh, NC
Bike(s): 2007 Honda ST1300
Age: 36
Posts: 12,313
Rep: ConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to behold (833)
Rep Power: 28
Re: Some dickheads hacked VFRdiscussion.com

Wow. That sucks. I was just over there the other day too. When did it happen?
ConqSoft is offline  
View ConqSoft's Profile View ConqSoft's Gallery Visit ConqSoft's homepage! Find More Posts by ConqSoft My Map Location
Reply With Quote Go To Top
Old 10-20-2005, 12:29 AM
  #3
Resigned to pursue other interests.
 
ConqSoft's Avatar
 
Join Date: 05-01-2001
Location: Raleigh, NC
Bike(s): 2007 Honda ST1300
Age: 36
Posts: 12,313
Rep: ConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to behold (833)
Rep Power: 28
Re: Some dickheads hacked VFRdiscussion.com

Hopefully they had a pretty recent backup?

Are they on a shared server or dedicated? That's one bad thing about shared servers, if some other site is running a piece of software that has security flaws, the whole server can be affected.

If dedicated, they should go through everything running on the server with a fine-tooth comb and see if there are any known issues. I'm pretty sure they were running the latest version of Invision Powerboard, and I haven't see any security alerts for it.

There's always the chance someone guessed or obtained an FTP or SSH password too...

Just throwing out scenarios.... Do you know any details?
ConqSoft is offline  
View ConqSoft's Profile View ConqSoft's Gallery Visit ConqSoft's homepage! Find More Posts by ConqSoft My Map Location
Reply With Quote Go To Top
Old 10-20-2005, 12:32 AM
  #4
Going into turn one
 
sheepofblue's Avatar
 
Join Date: 07-13-2004
Location: Huntsville AL
Bike(s): '04 CBR1000RR, '84 Ascot, '02 RC51
Posts: 13,846
Rep: sheepofblue has much to be proud ofsheepofblue has much to be proud ofsheepofblue has much to be proud ofsheepofblue has much to be proud ofsheepofblue has much to be proud ofsheepofblue has much to be proud ofsheepofblue has much to be proud ofsheepofblue has much to be proud ofsheepofblue has much to be proud ofsheepofblue has much to be proud of (1363)
Rep Power: 31
Send a message via AIM to sheepofblue
Re: Some dickheads hacked VFRdiscussion.com

Quote:
Originally Posted by CBRVFR
That's a non-controversial, inoffensive site. Makes me mad. I trust Conq has this site protected.

Anyway, if some tech guru here can offer help, please email ULEWZ. He's a member here and a mod over there.

http://www.fireblades.org/forums/members/ulewz.html
Umm I am far from a guru but has he checked the logs? It should have what IP and how entry was made. The IP might not help but the other might help prevent more attacks. Since it is such a inoffensive sight it is likely script kiddies that are not good enough to cover thier tracks.

EDIT: Also on an educated guess they were running windoz for the attack if that helps determine the vector (they spec'ed fonts that are windoz like names in the HTML
__________________
Send maple
sheepofblue is offline  
View sheepofblue's Profile View sheepofblue's Gallery Visit sheepofblue's homepage! Find More Posts by sheepofblue My Map Location
Reply With Quote Go To Top
Old 10-20-2005, 12:33 AM
  #5
Resigned to pursue other interests.
 
ConqSoft's Avatar
 
Join Date: 05-01-2001
Location: Raleigh, NC
Bike(s): 2007 Honda ST1300
Age: 36
Posts: 12,313
Rep: ConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to behold (833)
Rep Power: 28
Re: Some dickheads hacked VFRdiscussion.com

Hmm. Any idea which version they were running? They released a security patch in September. Nothing major though.
http://forums.invisionpower.com/inde...owtopic=186748
ConqSoft is offline  
View ConqSoft's Profile View ConqSoft's Gallery Visit ConqSoft's homepage! Find More Posts by ConqSoft My Map Location
Reply With Quote Go To Top
Old 10-20-2005, 12:58 AM
  #6
Resigned to pursue other interests.
 
ConqSoft's Avatar
 
Join Date: 05-01-2001
Location: Raleigh, NC
Bike(s): 2007 Honda ST1300
Age: 36
Posts: 12,313
Rep: ConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to behold (833)
Rep Power: 28
Re: Some dickheads hacked VFRdiscussion.com

It's back...
ConqSoft is offline  
View ConqSoft's Profile View ConqSoft's Gallery Visit ConqSoft's homepage! Find More Posts by ConqSoft My Map Location
Reply With Quote Go To Top
Old 10-20-2005, 1:51 AM
  #7
 
Bacchus's Avatar
 
Join Date: 08-15-2002
Location: South Australia
Bike(s): Bikeless - for now
Age: 61
Posts: 10,812
Rep: Bacchus has a spectacular aura aboutBacchus has a spectacular aura about (188)
Rep Power: 18
Re: Some dickheads hacked VFRdiscussion.com

What exactly did this hack consist of - i.e., what repercussions did it have on their site. Whatever, it stinks!
Bacchus is offline  
View Bacchus's Profile View Bacchus's Gallery Find More Posts by Bacchus
Reply With Quote Go To Top
Old 10-20-2005, 1:53 AM
  #8
Resigned to pursue other interests.
 
ConqSoft's Avatar
 
Join Date: 05-01-2001
Location: Raleigh, NC
Bike(s): 2007 Honda ST1300
Age: 36
Posts: 12,313
Rep: ConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to beholdConqSoft is a splendid one to behold (833)
Rep Power: 28
Re: Some dickheads hacked VFRdiscussion.com

The site was replaced with a screen saying that the site had been hacked by so-and-so, etc.
ConqSoft is offline  
View ConqSoft's Profile View ConqSoft's Gallery Visit ConqSoft's homepage! Find More Posts by ConqSoft My Map Location
Reply With Quote Go To Top
Old 10-20-2005, 1:54 AM
  #9
 
Bacchus's Avatar
 
Join Date: 08-15-2002
Location: South Australia
Bike(s): Bikeless - for now
Age: 61
Posts: 10,812
Rep: Bacchus has a spectacular aura aboutBacchus has a spectacular aura about (188)
Rep Power: 18
Re: Some dickheads hacked VFRdiscussion.com

Such childish **** - hope they pay for their actions...

edit: so they will have lost everything back to their last backup? :-(
Bacchus is offline  
View Bacchus's Profile View Bacchus's Gallery Find More Posts by Bacchus
Reply With Quote Go To Top
Old 10-20-2005, 10:43 AM
  #10
 
Join Date: 05-09-2003
Location: Ann Arbor, Michigan
Bike(s): '92 VFR750F, SV650 track tool. 954 no more!
Posts: 4,806
Rep: CBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud ofCBRVFR has much to be proud of (1495)
Rep Power: 24
Re: Some dickheads hacked VFRdiscussion.com

Sorry, guys, I don't have any background in this stuff, so I don't know what version Miguel is using or if the server is shared or dedicated.. I guess it was down for a few hours last night, and was back up this morning, as Conq noted.


Here's the thread:

http://www.vfrdiscussion.com/forum/i...topic=16019&hl=

and an excerpt-

Quote:
The "hackers" probably exploited a known vulnerability in the version of Ikonboard that Miguel is running. Either that, or the server it's hosted on had some other problem which they exploited.

I work in IT security and I see this type of stuff all the time. The folks who do it are usually male, and aged anywhere between 12 and 30 most commonly. Many of them these days are from Eastern Europe. Nothing you say or do will affect their current state of mind regarding how they feel about what they do. However many of these guys do grow out of it and can end up as normal functioning members of society.

Exploiting a known vulnerability like this is basically targetting the "low hanging fruit". These guys are after the notoriety of defacing a site - especially since any defacements get copied and posted on a central Index. The more defacements your "crew" makes, the higher your perceived standing in the hacker pecking order. I wouldn't call the attack personally that skillful, but what it does demonstrate is the need to be constantly vigilant. If you run a piece of software that has a vulnerability, patch it!

When it comes to "skilled" attacks, I've seen consultants in the team I work in absolutely tear banks to shreds (we're talking complete access to all customer data) within six hours . Now *that's* skill.

In short, don't worry about these guys - they're smalltime. Worry about the organised folks (often males aged over 30) actually trying to commit real organised crime and steal your identity, money, or both. You'll never see them deface anyone's site, or boast of their "1337 m@d sk1llz"; in fact you may never know they ever did anything. It's up to folks like me to stop those boys, and they can be *super* talented. They have the benefit of unlimited time and budget. The defending team is limited in time, people, and money and relies on automated tools to detect and stop attacks.

Currently, we're losing. http://www.vfrdiscussion.com/forum/s...ons/unsure.gif

Maybe Conq could contact Miguel (Hispanicslammer) for more details..


Edit - The difference in the response of the members over there compared to what I would expect here is striking..

I guess that I-4 really does lead to the dark side..
CBRVFR is offline  
View CBRVFR's Profile View CBRVFR's Gallery Find More Posts by CBRVFR
Reply With Quote Go To Top

 
About Blog Links Contact Staff Rules Link To Us Legal Privacy Sitemap
Top

Copyright © 2006 FireBlades.org. All Rights Reserved. FireBlades.org is not affiliated with, nor endorsed by, any motorcycle manufacturers.
Best viewed at a resolution of 1024x768 or higher. SEO by vBSEO ©2007, Crawlability, Inc. All times are GMT -4. The time now is 7:12 PM.

FireBlades.org RSS2 Feed   Add to Google   Add to My Yahoo!   Add to My MSN


Powered by vBulletin. Copyright ©2000 - 2007, Jelsoft Enterprises Ltd.