PDA

View Full Version : WTF happened



pack3tg0st
11-21-2009, 09:25 PM
Ok... I'll try to explain in non-geek talk about the going's on of today...

Sometime this afternoon, Skunk noticed that there were some posts labeled as 'guest' and threads started by 'guest'

Obviously this was incorrect.... as we remembered who started the threads...

I chocked the whole situation up to another import error.. (there were a shitload of em)

anyway, in the middle of me tinkering with the database (user tables) to see if I could resolve the issue, we noticed that the only people who's posts were affected, and showing up as 'guest' were Me, Skunk and Mojo... and it was only showing us as 'guest' for posts made before about 4 am this morning...

SInce the error only applied to Administrators, it's entirely possible that our SQL database was hacked... There's also an outside possibility that there was a hardware error or something while a table was being written to...

As it stands now, I've downloaded the corrupted database files/tables to sift through as time permits... I've also downloaded the apache logs...

The Arcade is temporarily Disabled... as an SQL injection vulnerability has been discovered with that particular software...

Admins: Please change your password and check in at the admin forums...

If anyone has any questions... I'd be happy to answer them... Just don't ask me to draw up a doofy comic style cartoon to explain it... sigh...

anyway, we're back... restored to a backup I took last night...

hp
11-21-2009, 09:29 PM
Pack. please do the SELECT I mentioned earlier.

pack3tg0st
11-21-2009, 09:32 PM
done and done HP.

ALso talking with the admins about removing some of the inactive users with admin permissions...

hp
11-21-2009, 09:33 PM
Did you see anything out of place?

pack3tg0st
11-21-2009, 09:35 PM
nope... everything looked ok...

we do have a shitload of inactives though

hp
11-21-2009, 09:38 PM
OK. I put the word out.

Guess people will slowly return tonite.

skunk
11-21-2009, 09:39 PM
Wouldn't be a bad idea to reset your password if you haven't already.

pack3tg0st
11-21-2009, 09:40 PM
Me? or HP?

pack3tg0st
11-21-2009, 09:41 PM
OK. I put the word out.

Guess people will slowly return tonite.

I emailed everyone who emailed me while the board was down...

skunk
11-21-2009, 09:41 PM
That was towards everyone :fsm:

hp
11-21-2009, 09:42 PM
I'm new, just in case.

boycotteverything
11-21-2009, 09:44 PM
mail kiwi and lala new passwords. they're... well.. them.

http://photos-c.ak.fbcdn.net/hphotos-ak-snc1/hs122.snc1/5250_1108560678180_1351737755_30306435_3730902_n.j pg

skunk
11-21-2009, 09:45 PM
If you talk to anyone who has problems logging into amkon tell them to click the contact us button at the bottom of the page.

I thought it was pretty easy, but I guess not.

boycotteverything
11-21-2009, 09:49 PM
hell- most people never scrolled down the far

hp
11-21-2009, 09:49 PM
The ability to follow clear instructions is required.

Cogburn
11-21-2009, 09:50 PM
http://forum.intern0t.net/exploits-vulnerabilities-pocs/1502-vbulletin-3-8-4-cross-site-script-redirection.html

boycotteverything
11-21-2009, 09:50 PM
we're talkin kiwi and lala here. jeeziz

Cogburn
11-21-2009, 09:53 PM
I think I'll wait just 3 more weeks or so before attempting to start any more threads.

pack3tg0st
11-21-2009, 09:55 PM
anyone who was able to log in as before 1 am last night... can still log in using the same passwords...

captainkiwi
11-21-2009, 09:56 PM
you hum it Sam and ill play it

boycotteverything
11-21-2009, 09:57 PM
I think I'll wait just 3 more weeks or so before attempting to start any more threads. i hear ya. shit- i lost at least 20 excellent posts in the pizza thread. fuck.

boycotteverything
11-21-2009, 09:59 PM
...not mention an exquisite little exchange with Obasi on Kierkegaard. double fuck.

pack3tg0st
11-21-2009, 10:01 PM
I lost my sanity...

Jackinthebox
11-21-2009, 10:03 PM
I had trouble logging in, and now this profile is mixed up with my sock too. Gonna try to straighten that out. BTW, I did find the contact button and used it, lol. Thanks guys.

boycotteverything
11-21-2009, 10:04 PM
i think we were hacked by warren and sancho- maybe exploiting that hole (cog's link.) hell that was a how-to manual.

skunk
11-21-2009, 10:05 PM
i think we hacked by warren and sancho- maybe exploiting that hole (cog's link.) hell that was a how-to manual.

We're using the most up to date version of vb and that exploit is for an older version.

hp
11-21-2009, 10:10 PM
I don't think they did it.

pack3tg0st
11-21-2009, 10:11 PM
SHTF?

nah... there's no way...

hp
11-21-2009, 10:12 PM
BE, they can't even get your pizza to ya on time.

boycotteverything
11-21-2009, 10:13 PM
...until Starfire showed.

mojo
11-21-2009, 10:13 PM
hah!
take more than that to get rid of amkon, otherwise they'd obviously know about all the other back up forums we have hidden around the net in case of major failure.

skunk
11-21-2009, 10:14 PM
Wouldn't be a bad idea to start an email list.

mojo
11-21-2009, 10:15 PM
can probably dump all registered members email to notepad and save on hard drive.

mojo
11-21-2009, 10:16 PM
can probably dump all members email to notepad and save on disk.

boycotteverything
11-21-2009, 10:18 PM
damn! that was good enough to post twice!

mojo
11-21-2009, 10:19 PM
lagged....and double posted. hmmph.

Cogburn
11-21-2009, 10:20 PM
Just format the board and start fresh... no import errors, no nothing.

Setup the old board as read only for archival purposes and let's all just move on.

skunk
11-21-2009, 10:21 PM
Should be fine now.

Cogburn
11-21-2009, 10:21 PM
Until the next time.

mojo
11-21-2009, 10:22 PM
Should be fine now.

:lol:

general custer said something similar i reckon.

boycotteverything
11-21-2009, 10:22 PM
fuck. i still think we should become the web's first uni-thread forum.

Cogburn
11-21-2009, 10:22 PM
Aren't we there now?

pack3tg0st
11-21-2009, 10:23 PM
Cog: DB is fine lol

in fact.. importing it to Vb got rid of all the phpbb garbage in it...

and isn't a unithread forum called a chat room?

boycotteverything
11-21-2009, 10:23 PM
chat room. yeah. that's what we are at heart.

skunk
11-21-2009, 10:24 PM
Live topic is a perfect fit.

hp
11-21-2009, 10:24 PM
We can call the NSA and get BE's lost posts.

Cogburn
11-21-2009, 10:25 PM
Cog: DB is fine lol
You just have a suspicion you were hacked.

The cat is still both alive and dead.

mojo
11-21-2009, 10:27 PM
You just have a suspicion you were hacked.

The cat is still both alive and dead.

and skinned.

Trauma Teased
11-21-2009, 10:27 PM
Wow, I made a post in the Color test thread earlier today, and the same second I hit "submit post" this place went down...

Honestly, I thought I had broke the whole damn forum... Such is the life of a techno idiot.
:cry:

hp
11-21-2009, 10:27 PM
The cat is stuffed - ask BE.

mojo
11-21-2009, 10:27 PM
... Such is the life of a techno idiot.
:cry:

welcome to my world. :D

hp
11-21-2009, 10:28 PM
I was reading the post before it. Cog's thread did it.

Cogburn
11-21-2009, 10:28 PM
I hacked AmKon.

skunk
11-21-2009, 10:28 PM
Must have pissed off pablo.

boycotteverything
11-21-2009, 10:29 PM
well from now on i'm only gonna post right here in this thread. i remember one time i got really pissed about all the icons on my desk top and so i created a folder name "stuff" and scooped everything up and dumped in that folder. the ultimate simplicity. unfortunately i ended up with a blue screen. kindly rename this thread "Unithread."

mojo
11-21-2009, 10:29 PM
well from now on i'm only gonna post right here in this thread.

Saved for future reference.

pack3tg0st
11-21-2009, 10:30 PM
You just have a suspicion you were hacked.

The cat is still both alive and dead.

that is true.

a fairly strong suspicion... and I'll only know for sure when I start diving into the downloaded logs/tables...

and even then... its never a certainty...

especially if its anyone that's any good.

pack3tg0st
11-21-2009, 10:30 PM
Saved for future reference.

:lol:

Vb has all sorts of cool features...

We could block him out of all the other ones lol

Cogburn
11-21-2009, 10:31 PM
So really all you might have just done is restore what ever exploit allowed entry in the first place?

Format the board and put phpBB3 online as an archive.

boycotteverything
11-21-2009, 10:32 PM
Saved for future reference.given our history, you better commit it to paper.

Cogburn
11-21-2009, 10:32 PM
Can we get daily printouts?

hp
11-21-2009, 10:32 PM
Not if it was done today.

mojo
11-21-2009, 10:32 PM
given our history, you better commit it to paper.

hahaha...ive printed it out.

:lol:

gonna get it framed too.

pack3tg0st
11-21-2009, 10:32 PM
I thought about that cog...

I think I'll know more when I start looking at the stuff...

but anyway... check your PM's :)

boycotteverything
11-21-2009, 10:35 PM
hey! this guy just dribbled outa my floppy drive..

http://shtf411.com/download/file.php?avatar=55_1257834258.gif

Cogburn
11-21-2009, 10:35 PM
Might want to have that drive replaced.

mojo
11-21-2009, 10:44 PM
Might want to have that drive replaced.

or lubricated. :)

rasobasi420
11-21-2009, 10:45 PM
I assume we have no more chat? Not that I'd want to just 'chat' with any of you fuckers. But sometimes, posting random, useless shit that gets documented for eternity (usually) is kinda intimidating. Look at me! I'm intimidated!

Eyeforalie
11-21-2009, 10:45 PM
I agree with Cog. Take the last coupe active thread titles and reopen a tread of the same name here and archive the rest. Keep it available, but fuck...Its a new board, and we have already lost shit at 3 different occasions. Might as well start over.

Its actually a bit funny now. It sucks dick...But, Hakuna matata.

boycotteverything
11-21-2009, 10:49 PM
archive- my ass. hell, we don't even wash the sheets in this flop house.

http://www.coasttocoastam.com/cimages/var/ezwebin_site/storage/images/coast-to-coast/repository/photos/shroud-of-turin-twist/445178-2-eng-US/Shroud-of-Turin-Twist_featured.jpg

Eyeforalie
11-21-2009, 10:50 PM
Thats where I let my cum-rag...Thanks

rasobasi420
11-21-2009, 10:50 PM
That jizz stain looks like Jesus! Lets hang it up at the Vatican!

boycotteverything
11-21-2009, 10:51 PM
that's mojo's sleeping bag

rasobasi420
11-21-2009, 10:55 PM
In that case, I'm sure the Pope will enjoy it in his bedroom. Although, he might have enjoyed it better when Mojo was younger... much younger.

Eyeforalie
11-21-2009, 10:56 PM
Told ya I was hacked.

Lexion
11-21-2009, 11:17 PM
I'm in tears, laughing.

http://i196.photobucket.com/albums/aa20/Lexion07/AmKonEdit.jpg

hp
11-21-2009, 11:20 PM
Damnit Lex, don't type anything while you are here.

hp
11-21-2009, 11:21 PM
The board can since you like to disassemble things.

Lexion
11-21-2009, 11:22 PM
damnit lex, don't type anything while you are here.

--- -.- -..-. .... .--. -..-. .. .----. .-.. .-.. -..-. .-. . ..-. .-. .- .. -.

hp
11-21-2009, 11:23 PM
Oh crap, extra work

pack3tg0st
11-21-2009, 11:24 PM
lex... the DB error you were getting wasn't really a DB error... I had the board shut down... and was tying up the SQL server...

all the going's on of the database and website going down was me... I intentionall brought it down to do some work on resolving some problems...

one of the problems I was resolving may have been caused by an sql injection that occured early morning today...

once discovering that, my work grinded to a hault, I restored.. and now I'm trying to figure out what the hell happened this morning while I was sleeping...

hp
11-21-2009, 11:25 PM
... .... .- -.- . / - .... . / ..-. --- .-. ..- -- / -.. --- .-- -. / .. - / .. ... / -.-- --- ..- .-. / --. .. ..-. -

skunk
11-21-2009, 11:25 PM
mengapa tidak anda bercakap malay lexion ia lebih mudah untuk terjemah

hp
11-21-2009, 11:26 PM
Why do I have to press 1 for english?

Lexion
11-21-2009, 11:27 PM
Press 3 for board crash.

hp
11-21-2009, 11:29 PM
Removing 3 keys now...

Lexion
11-21-2009, 11:33 PM
... .... .- -.- .. -. --.