Welcome, Guest. Please Login or Register.
July 03, 2025, 09:13:17 AM
Home Help Search Log in Register
News: SMF is the next generation in forum software, almost completely re-written from the ground up, make sure you don't fall for cheap imitations that suffer from feature bloat!

YaBB SE Community  |  English User Help  |  English Help  |  Hacked Ii « previous next »
Pages: [1] Reply Ignore Print
Author Topic: Hacked Ii  (Read 1667 times)
I, Brian
Full Member
***
Posts: 238


It is coming...

WWW
Hacked Ii
« on: June 15, 2003, 07:27:53 AM »
Reply with quote

Hi -

Last night my site was hacked - all that appears to have happened is that the YaBB SE index file was replaced.

I didn't think to download raw logs at the time - just the forum db. But this morning, 9 hours later, I have downloaded a raw .gz log file of 303kb.

I don't know whether the log file will cover the period in question - the attack was around 22:40 GMT on the 14th June, and the log file was downloaded at 08:10 GMT.

But I have it if anyone wants to check to make sure it wasn't a vulnerability in YaBB SE. So...who wants the log file?

E-mail me and I'll send you it.

Brian



Logged

David
Destroyer Dave
Global Moderator
YaBB God
*****
Posts: 5761


I'm not a llama!

WWW
Re:Hacked Ii
« Reply #1 on: June 15, 2003, 08:03:33 AM »
Reply with quote

As always, [email protected].  Hopefully you can send me just the time around the hack and not the whole log.
Logged

[Unknown]
Global Moderator
YaBB God
*****
Posts: 7830


ICQ - 179721867unknownbrackets@hotmail.com WWW
Re:Hacked Ii
« Reply #2 on: June 15, 2003, 08:13:32 AM »
Reply with quote

Please send a copy ot me as well - [email protected].

-[Unknown]
Logged
Mach8
Sweetie
Beta Tester
YaBB God
*****
Posts: 1218


ICQ - 339855961
Re:Hacked Ii
« Reply #3 on: June 15, 2003, 10:14:57 AM »
Reply with quote

Can you please send me a copy of the log as well - something similar happened on my website and I'd like to cross-reference, see if the same thing happened on both sets of logs.

(when I can read my logs that is, my host has been hacked :-\)
« Last Edit: June 15, 2003, 10:15:13 AM by Mach8 » Logged
Mach8
Sweetie
Beta Tester
YaBB God
*****
Posts: 1218


ICQ - 339855961
Re:Hacked Ii
« Reply #4 on: June 15, 2003, 10:32:46 AM »
Reply with quote

I just found the logs I downloaded from yesterday, and as I guessed - there's no information from what I can see that would point to the attack. I'll still email you the logs though.

I took a look at I, Brian's file and it seems to be the same way as well.
Logged
phark
Sr. Member
****
Posts: 482


Re:Hacked Ii
« Reply #5 on: June 15, 2003, 08:31:04 PM »
Reply with quote

Well, its not just YaBB SE that is being hacked...

http://www.umu.man.ac.uk/muisoc/phpBB2/index.php

EDIT:  fady911x is a busy person
« Last Edit: June 15, 2003, 08:36:04 PM by phark » Logged

I'm not scared of dying, I just don't want to.
David
Destroyer Dave
Global Moderator
YaBB God
*****
Posts: 5761


I'm not a llama!

WWW
Re:Hacked Ii
« Reply #6 on: June 15, 2003, 08:45:14 PM »
Reply with quote

https://www.europe.f-secure.com/v-descs/naco_f.shtml+fady911x&hl=en&ie=UTF-8
http://vx.netlux.org/~melhacker/+fady911x&hl=en&ie=UTF-8
Logged

I, Brian
Full Member
***
Posts: 238


It is coming...

WWW
Re:Hacked Ii
« Reply #7 on: June 16, 2003, 07:21:38 AM »
Reply with quote

Yes, he's easy to track on Google.

However, I'd like to post the reply from VenturesOnline about the incident, because there's a possible suggestion of accessing the site through YaBB SE (I run no other scripts on my account - just normal .html files constructed through php includes):

Quote
Since this is a shared server allowing, anyone to write to a directory is a big mistake and will likely be exploited. If you have world readable configuration files it is also possible this is how this user got in.

If you have a world writeable directory as listed above, it would be wise to remove

I don't actually understand the application of the terms "world readable configuration files" or "world writeable directory".

I wondered if someone could comment:
Logged

andrea
Global Moderator
YaBB God
*****
Posts: 4400


Peace on Earth

WWW
Re:Hacked Ii
« Reply #8 on: June 18, 2003, 01:16:18 AM »
Reply with quote

Quote from: I, Brian on June 16, 2003, 07:21:38 AM
Quote
Since this is a shared server allowing, anyone to write to a directory is a big mistake and will likely be exploited. If you have world readable configuration files it is also possible this is how this user got in.

If you have a world writeable directory as listed above, it would be wise to remove

I don't actually understand the application of the terms "world readable configuration files" or "world writeable directory".

I wondered if someone could comment:

http://www.yabbse.org/community/index.php?board=135;action=display;threadid=15904
Logged

Aeon
Full Member
***
Posts: 235


Chaos Forces

never_mind86@hotmail.com WWW
Re:Hacked Ii
« Reply #9 on: June 18, 2003, 06:42:30 AM »
Reply with quote

from his name "Fady" I can tell he is an Arabic ! also all the sites he hacked are for Arabic ...

well well ... we have some good hackers in our land ;D
Logged

I still don't know what Classes and Object-Orinted do!!?
do you know what they do and why they existed ?!
please tell me and I will appreciate it ..
I, Brian
Full Member
***
Posts: 238


It is coming...

WWW
Re:Hacked Ii
« Reply #10 on: June 18, 2003, 01:22:26 PM »
Reply with quote

Thanks for that Andrea - much appreciated.

As for Fady - yes, he lives in Egypt. Nothing great about being a hacker though.
Logged

Pages: [1] Reply Ignore Print 
YaBB SE Community  |  English User Help  |  English Help  |  Hacked Ii « previous - next »
 


Powered by MySQL Powered by PHP YaBB SE Community | Powered by YaBB SE
© 2001-2003, YaBB SE Dev Team. All Rights Reserved.
SMF 2.1.4 © 2023, Simple Machines
Valid XHTML 1.0! Valid CSS

Page created in 1.849 seconds with 21 queries.