Results 1 to 30 of 32

Thread: Hack Attempt on .Org

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Mr Self Important Senior Member Beskar's Avatar
    Join Date
    Feb 2008
    Location
    Albion
    Posts
    15,930
    Blog Entries
    1

    Default Hack Attempt on .Org

    Hello all,

    It seems that someone got access to our webserver via some legacy software hosted on totalwar.org. This has now been locked down, and many features and functionality from the old sections of the Org are no longer accessible.

    The hacker attempted to hijack and control a admin account (failed), and tried to deface sections of the site. Any alterations have been reversed and secured against.

    Whilst passwords on the Org are encrypted, they may have been exposed during this time, and it is highly recommended that you change your passwords to ensure your accounts are not compromised. Similarly, if you use the same email address/username and password on other websites. Whilst this may just be a precaution as there is no way to tell, I would recommend following this advice.

    We're still investigating the extent of the breach, and some functionality on the site which people may be using is disabled to ensure this cannot occur again

    In the meantime, we recommend that everyone changes their passwords ASAP.

    Best wishes,
    Beskar
    Last edited by Beskar; 10-27-2016 at 17:12.
    Days since the Apocalypse began
    "We are living in space-age times but there's too many of us thinking with stone-age minds" | How to spot a Humanist
    "Men of Quality do not fear Equality." | "Belief doesn't change facts. Facts, if you are reasonable, should change your beliefs."

    Members thankful for this post (4):



  2. #2

    Default Re: Hack Attempt on .Org

    Quote Originally Posted by Beskar View Post
    This has now been locked down, and many features and functionality from the old sections of the Org are no longer accessible.
    What exactly is gone now?
    Vitiate Man.

    History repeats the old conceits
    The glib replies, the same defeats


    Spoiler Alert, click show to read: 


    Member thankful for this post:

    Roma5 


  3. #3
    Mr Self Important Senior Member Beskar's Avatar
    Join Date
    Feb 2008
    Location
    Albion
    Posts
    15,930
    Blog Entries
    1

    Default Re: Hack Attempt on .Org

    Quote Originally Posted by Montmorency View Post
    What exactly is gone now?
    Some old random pieces of dusty equipment that should have been thrown out years ago, but kept around long past its usefulness. Something no one would probably ever use, except for that one random person.But it was the reason for the breach/attempt. In short, I don't know, and @therother is the person to ask.
    Days since the Apocalypse began
    "We are living in space-age times but there's too many of us thinking with stone-age minds" | How to spot a Humanist
    "Men of Quality do not fear Equality." | "Belief doesn't change facts. Facts, if you are reasonable, should change your beliefs."

    Member thankful for this post:

    Roma5 


  4. #4
    Research Fiend Technical Administrator Tetris Champion, Summer Games Champion, Snakeman Champion, Ms Pacman Champion therother's Avatar
    Join Date
    Feb 2004
    Location
    UK
    Posts
    2,631

    Default Re: Hack Attempt on .Org

    Mostly, I've deactivated a whole bunch of file uploaders from back circa 2002-2004. The hack attempt was via these old php scripts.

    I've also deactivated a number of unused sites like our Legend of the Green Dragon install. I could reactivate these if there's interest.

    There was an attempt to break into a dummy forum account but this was unsuccessful.
    Last edited by therother; 10-27-2016 at 19:38.
    Nullius addictus iurare in uerba magistri -- Quintus Horatius Flaccus

    History is a pack of lies about events that never happened told by people who weren't there -- George Santayana

    Members thankful for this post (3):



  5. #5
    Requin Member Vincent Butler's Avatar
    Join Date
    May 2014
    Location
    Laniakea Supercluster
    Posts
    673

    Default Re: Hack Attempt on .Org

    Makes you wonder what somebody could hope to gain by hacking .org, other than just to be malicious.
    Blessed be the LORD my strength, which teacheth my hands to war, and my fingers to fight: Psalm 144:1

    In peace there's nothing so becomes a man
    As modest stillness and humility:
    But when the blast of war blows in our ears,
    Then imitate the action of the tiger;
    -Henry V by William Shakespeare

    Member thankful for this post:

    Roma5 


  6. #6

    Default Re: Hack Attempt on .Org

    Quote Originally Posted by therother View Post
    The hack attempt was via these old php scripts.
    Most likely old, buggy (or just poor) PHP code.

    https://en.wikipedia.org/wiki/File_i...nerability#PHP

    Member thankful for this post:

    Roma5 


  7. #7
    Member Member Stazi's Avatar
    Join Date
    Jun 2008
    Location
    Poland
    Posts
    456

    Default Re: Hack Attempt on .Org

    Quote Originally Posted by Vincent Butler View Post
    Makes you wonder what somebody could hope to gain by hacking .org, other than just to be malicious.
    Your answer is in the first post:

    Quote Originally Posted by Beskar View Post
    Whilst passwords on the Org are encrypted, they may have been exposed during this time, and it is highly recommended that you change your passwords to ensure your accounts are not compromised. Similarly, if you use the same email address/username and password on other websites.
    "Do not fight for glory. Do not fight for love of your lord. Do not fight for hatred, honor or faith. Fight only for victory and you will succeed." - Uji sensei.

    Member thankful for this post:

    Roma5 


  8. #8

    Default Re: Hack Attempt on .Org

    Probably a nutter who thinks anyone with an apolitical interest in war subscribes to fascism or some other extreme ideology. Whenever people find out I'm a Germanophile and have an extensive interest in the Eastern Front of WWII, I get THAT look,

  9. #9
    Banned Kadagar_AV's Avatar
    Join Date
    Jan 2003
    Location
    In average 2000m above sea level.
    Posts
    4,176

    Default Re: Hack Attempt on .Org

    Quote Originally Posted by Beskar View Post

    Wrote stuff

    Best wishes,
    Beskar
    What this means is basically; All your base are belong to us.


    Never have the same PW at 2 places, is the sidenote.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Single Sign On provided by vBSSO