Author Topic: Forums hacked  (Read 12044 times)

Offline Miquel 'Fire' Burns

  • Administrator
  • *****
  • Posts: 1157
  • Programmer
Forums hacked
« on: July 19, 2006, 02:00:24 PM »
The forums were hacked last night for some reason (Appears to somehow logged into Eric's account, and they suspended my account for some reason.) after the last backup, so I restored it, and updated the version of IPB.
« Last Edit: July 19, 2006, 02:04:23 PM by miquelfire »
"I'm not drunk, just sleep deprived."

Offline Eric H. Jung

  • grimholtz
  • Administrator
  • *****
  • Posts: 3353
Forums hacked
« Reply #1 on: July 19, 2006, 04:14:43 PM »
Both my account and morguns' have periodically been receiving password reset emails. We were confused as to what was going on. Now it makes sense. How many versions of IPB were we behind? Did we lose any messages that hadn't been backed up?

Thanks for handling this. It's amazing to me that someone would attack an open-source project.

edit: does this mean we should change our passwords, or were only the hashes or cookies stolen?
« Last Edit: July 19, 2006, 04:17:54 PM by Eric H. Jung »

Offline Miquel 'Fire' Burns

  • Administrator
  • *****
  • Posts: 1157
  • Programmer
Forums hacked
« Reply #2 on: July 19, 2006, 04:22:18 PM »
We were only one version behind.

As far as I can tell, no messages were missing, but then again, I went offline around 11:30, and didn't notice until around 9-10 this morning. And the backup had message I didn't read yet.

I find it odd they suspended my account however. I wonder if there was a valid reason for this? And they didn't remove my admin status at all.

Edit Changing your passwords would be wise. Time to add something to the modifier field
« Last Edit: July 19, 2006, 04:24:24 PM by miquelfire »
"I'm not drunk, just sleep deprived."

Offline The0n3

  • Normal Members
  • *
  • Posts: 3
Forums hacked
« Reply #3 on: July 19, 2006, 05:35:57 PM »
Hi I am The0n3 from EZWarez.org. I'm the one that hacked/exploited your website last night I see you have it up ipb 2.1.7 has no exploit's.

How I hacked you and why you recived password notice's I targeted you and found out a simple exploit in 2.1.6  I file a lost password on a Admin acount and I can extract the validation number from hash.

So glad to see you up and if you ever need anything feel free to stop by EZWarez.org s0rry we had to meet this way.



Thank's for your time,

The0n3

Offline Eric H. Jung

  • grimholtz
  • Administrator
  • *****
  • Posts: 3353
Forums hacked
« Reply #4 on: July 19, 2006, 07:05:44 PM »
Why would you attack an open-source project? We'd rather spend our limited time on the open-source project than maintaining these forums. Do you just not give a shit? (Yes is an acceptable answer).
« Last Edit: July 19, 2006, 07:06:24 PM by Eric H. Jung »

Offline The0n3

  • Normal Members
  • *
  • Posts: 3
Forums hacked
« Reply #5 on: July 19, 2006, 08:08:58 PM »
No actulley I don't care.  

I woulda hacked any website I found.

Offline Eric H. Jung

  • grimholtz
  • Administrator
  • *****
  • Posts: 3353
Forums hacked
« Reply #6 on: July 20, 2006, 02:02:03 AM »
Well, at least you're honest. I hope for the world's sake that you engender morals of good as you get older.

Offline Miquel 'Fire' Burns

  • Administrator
  • *****
  • Posts: 1157
  • Programmer
Forums hacked
« Reply #7 on: July 20, 2006, 02:21:48 AM »
And yet, you suspended my account out right, without even trying?
"I'm not drunk, just sleep deprived."

Offline The0n3

  • Normal Members
  • *
  • Posts: 3
Forums hacked
« Reply #8 on: July 20, 2006, 03:06:17 AM »
Sorry I'm only 14 if you would don't use such large word's.

I think I might look around this place.  

Feel free to check EZWarez.org out anytime.

LkonKbd

  • Guest
Forums hacked
« Reply #9 on: July 25, 2006, 03:04:02 AM »
Quote from: Eric H. Jung
Well, at least you're honest. I hope for the world's sake that you engender morals of good as you get older.
Eric, Eric, Eric,

This is far from the truth, from what I have just received from http://www.spywareinfo.net/july25,2006.  I have a subscription to this NewsLetter and some ads, but; very interesting info can be found there, now and then.  DoNOT visit that website posted by that 14 year old.  Edited by LkOnKbd > Read the NewsLetter at http://www.spywareinfo.net/july25,2006#testing.

Excuse me, was not supposed to post a quote just supply the link to the online version.  Hope this did not get me into any trouble nor you.

Have not done this before so I hope it works AOK, if not PM me and I will provide, well maybe I have it correctly now after using the 'FullEdit' feature.  The THIRD Time is Charmed. . .
« Last Edit: July 25, 2006, 03:30:09 AM by LkonKbd »

Offline Eric H. Jung

  • grimholtz
  • Administrator
  • *****
  • Posts: 3353
Forums hacked
« Reply #10 on: July 25, 2006, 03:58:14 AM »
Hi 'd',

Thanks for the concern. I read the article you posted. I think we've all been to sites like that at one point or another

I didn't visit his warez site, but I doubt he'd be able to hijack my computer.

-Eric

LkonKbd

  • Guest
Forums hacked
« Reply #11 on: July 26, 2006, 02:59:20 AM »
Quote from: Eric H. Jung
Hi 'd',

Thanks for the concern. I read the article you posted. I think we've all been to sites like that at one point or another

I didn't visit his warez site, but I doubt he'd be able to hijack my computer.

-Eric
Eric,

My main concern was to ALERT you and the other workers as well as those that read over some of our posts to be aware of that threat.  Plus, let someother people know of his newsletter, it has been a HELP to me and a few of my friends.  I did not think you would be in any DANGER, it is primarily for those that are not very smart, LIKE ME.

Another point is I have learnt more about how to use this Forum and have you and the other GREAT HELPers you have there to THANK for these experinces.  Now if I just can remember to use them properly.
« Last Edit: July 31, 2006, 11:10:13 PM by LkonKbd »

Offline tanstaafl

  • God Member
  • ******
  • Posts: 1363
Forums hacked
« Reply #12 on: July 26, 2006, 11:53:43 AM »
Amazing...

Sorry I've been gone so long... been really busy with our office move, and soon will be moving to our new house, but that won't be nearly as traumatic...

I have a lot of catching up to do, so will be reading all of the posts over the last month or so over the next few days...

Offline Eric H. Jung

  • grimholtz
  • Administrator
  • *****
  • Posts: 3353
Forums hacked
« Reply #13 on: July 26, 2006, 05:14:04 PM »
welcome back, charles.

PasswordMaker Forums

Forums hacked
« Reply #13 on: July 26, 2006, 05:14:04 PM »