Forum Hack Karna Yaaluw

zanharjabir

Well-known member
  • Oct 28, 2007
    3,948
    60
    48
    Today I was working diligently on one of my five websites that I've just setup. I'm still in the works of getting them all on my own server for my own support and making sure the site's are properly monitored. I just happened to want to get some information off of one of my websites, and i saw this really, really odd image in the place of my index page:

    hacked-1.jpg


    So I frantically contacted my assistant administrator and we started working on it right then. Turns out I caught the guy right in the middle of his attack. Another one of my friend came online and I asked him to help as well, he's a security professional who works very well in attacks. Another friend came online (all of this is in MSN btw) who is good with virus attacks and such, as well as website security. So here we are, a team of four Computer technicians working against what seems to be just one hacker to me.

    I contacted my host site immediately, demanding them to turn off the servers, just to stop the guy (he was right in the middle of writing a shell to exploit our our other sites). He swiftly degraded our site's mybb version to an older version so that he would have other exploits to use.

    I had one thing he didn't have, cpanel access. I promptly got into the sql database and started messing with his multiple accounts he was creating until i also denied access in the .htaccess file files to everyone but our ip addresses. The attacks stopped. The message DIDN'T go out.

    This hacker has attacked over 8,000 different websites. There's even a news story on him here:

    http://www.p2pnet.net/story/23929

    and here's a list of all of his posted attacks:

    http://zone-h.org/archive/defacer=NobodyCoder

    There's one thing I forgot to mention. This guy's not too bright. He didn't cover his tracks and left himself wide open. He left his REAL ip addess in my sql database, which is listed in a comment I made in the news article above. His attack was fruitless, compeltely scripted, and to me an utter disgrace to see something like this. Yes, he got into my site, with scripts. He doesn't know how to hack. He just scripts his stuff, so when something happens, he doesn't know how to defend against it. We stopped his attack, took all of our sites on that server offline from public access, recorded all of his information.

    I am more than willing to assist anyone out there who wishes to press charges on this attack or others like them. If you feel that you have been attacked by this hacker or his group, please contact me as soon as you can at the following email address (note that this is an official government email address, anything you send to this account will be scanned and is being monitored, so don't send anything you don't want monitored):

    shawn.wrightatfe.navy.mil (note: edited to stop spambot harvesters, replace the at - Admin) -Thanks :) I appreciate the protection.

    If you have any information at all on this attacker please provide it either in this thread or to the email above. The more we get on this guy the more we have as a case.

    Thank you for your time.

    meka Spam post ekak kiyala namm kiyana epaa
    dain lanka veth web ehma hack karla thiyanwa..
    mang danaa katiyageth web ehma hack karla thiyanwa..

    meka thmi hacker gey mail id eka [email protected]
    api ta dain elakiri ekath nathi karganda baha..
    katiya mokada kiyaney.. elakiri ekath spam post mrng ehma balana kota pririlaa..​
     

    zanharjabir

    Well-known member
  • Oct 28, 2007
    3,948
    60
    48
    Nobody Coder hack fix

    Thank you to everyone that has posted and the wonderful assistance that I have found on these forums, I have never needed to ask a question, and simply came right by searching for what i needed.

    In return I would like to offer this fix, from what I did yesterday on both my forums after I was hacked.

    --------------------------------------------------------------------
    THE FIX.....
    --------------------------------------------------------------------

    There was an exploit on MYBB ver 1.4.6 that allowed hackers to insert a piece of code into your themes directory.
    This is used to change the landing page of your default theme. The quickest way to get rid of this problem is firstly to ftp to your server and delete the file /cache/themes/themes.php, it is not a valid mybb file and is the code used for the exploit.

    Then go to MYBB admin console--> Themes and templates--> Templates--> expand default template--> click on options for index and select revert to defaults.

    Forum will now return to normal operation. It is very important though, that 1.4.6 be upgraded to 1.4.8.
     

    Ethical_World

    Member
    Mar 15, 2009
    2,036
    90
    0
    #! /bin/sh
    this is a vbull software .. its perfectlly ok ..
    2nd is about the server .. most hackers hack forum with there server security holes

    lets think

    www.mybigforum.com and www.shit.com is on 1 server

    if I got a shell up on www.shit.com .. I can root the server and mass deface the all sites in the server

    thats how most turkish / Iran / Muslim Hackers do ..

    They root a server and deface all the sites on it ....
    so dont worry .. Elakiri have there own server and its not possibile to hack elakiri
     

    Hashan dis

    Well-known member
  • Sep 10, 2008
    15,010
    657
    113
    vBulletin hack karanna lasi naa and elakiri wala security
    gana baya wanna epa elakiri tiyanna elakiri ekama private
    Dedicated server wala. spam post daana eka security prashnayak namai
     

    GTRZ

    Administrator
    Staff member
  • Apr 27, 2006
    19,480
    10,860
    113
    spamming and hacking are two different things.
    You can't stop spammers if its a public forum. You can reduce them.
    spamming has nothing to do with exploits or security. Don't get mixed up.
     

    GTRZ

    Administrator
    Staff member
  • Apr 27, 2006
    19,480
    10,860
    113
    this is a vbull software .. its perfectlly ok ..
    2nd is about the server .. most hackers hack forum with there server security holes

    ....................

    They root a server and deface all the sites on it ....
    so dont worry .. Elakiri have there own server and its not possibile to hack elakiri

    vbulletin not hackerble is not true. If then why they release patches and security maintenance releases. You know they release patches after bug trackers or community report them. So if you get caught before that then it'll be game over.
    And there may be tons of unexplored exploits still exist.

    having own server not makes you unreachable too. Its just you don't have to worry about other people's security issues which will effect you.

    I am trying my best to keep elakiri secure. And i am happy that no one hacked it yet. :) But like everyone of you, i am not an expert in this field.
    So my advice is to keep backups and list what you changed in a notebook if you doing modifications. :yes:
     

    Ethical_World

    Member
    Mar 15, 2009
    2,036
    90
    0
    #! /bin/sh
    vbulletin not hackerble is not true. If then why they release patches and security maintenance releases. You know they release patches after bug trackers or community report them. So if you get caught before that then it'll be game over.
    And there may be tons of unexplored exploits still exist.

    having own server not makes you unreachable too. Its just you don't have to worry about other people's security issues which will effect you.

    I am trying my best to keep elakiri secure. And i am happy that no one hacked it yet. :) But like everyone of you, i am not an expert in this field.
    So my advice is to keep backups and list what you changed in a notebook if you doing modifications. :yes:

    lol .. Even Im not expert .. But I know pritty much stuff !

    well Vbull is the most secured Forum software ..neda ? and without any plugins / modules its unhackable .. ( new versions) ..

    Anyways I will be looking Elakiri Security always ... if u dont mind .. ( No More Public suff ..dirct to you GTRz Aiiya :lol::lol:)
     

    GTRZ

    Administrator
    Staff member
  • Apr 27, 2006
    19,480
    10,860
    113
    lol .. Even Im not expert .. But I know pritty much stuff !

    well Vbull is the most secured Forum software ..neda ? and without any plugins / modules its unhackable .. ( new versions) ..

    Anyways I will be looking Elakiri Security always ... if u dont mind .. ( No More Public suff ..dirct to you GTRz Aiiya :lol::lol:)

    nope malli then they don't need to release patches and security releases right. So bro every thing is patched and improved day by day.

    And from the story in first post you can see that hacker got in using shell and downgraded mybb script to do more damage. So you can see even mybb script doing its job. Sure vbulletin has good record for security but nothing says its perfect.

    Anyway bro thanks for your offer for support but learn more than talking which will make your path to success. Good luck! :D
     

    Ethical_World

    Member
    Mar 15, 2009
    2,036
    90
    0
    #! /bin/sh
    nope malli then they don't need to release patches and security releases right. So bro every thing is patched day by day.

    And from the story in first post you can see that hacker got in using shell and downgraded mybb script to do more damage. So you can see even mybb script doing its job. Sure vbulletin has good record for security but nothing says its perfect.

    Anyway bro thanks for your offer for support but learn more than talking which will make your path to success. Good luck! :)

    Correct :yes::yes::yes::yes:

    Kit :lol::lol::lol: