PDA

View Full Version : **Important - forum has been hacked



Speed Racer
04-17-2005, 04:42 PM
I will be taking the board down. You probably just received a bogus email from an "admin" at CS.com forum. That did not come from Me or Malloy.

hi,
please help us with some downloads & clicks
visit teendump.dk.tc


Download it and have fun!

best regards
admin
I'm taking care of it now. Btw...the forum was not taken down by us this morning in "not-available" mode.

Please be patient - I'm on it.

rabidchimp.com
04-17-2005, 04:46 PM
Hackers should DIE!
-Aaron

cellulargod721
04-17-2005, 04:47 PM
Thank you for clearing that up. I just got that email and I am like hmm.........luckily this is a work computer so I didnt use any of their downloads.

82phoenix
04-17-2005, 04:49 PM
Thanx.. the email looked suspicious.
I figured something was up.

Speed Racer
04-17-2005, 04:53 PM
I'm upgrading us to version 2.0.14 right now - we may lose some of the mods I've done, unless I use the patch files only. I'm reading about the update now.

What concerns me is that there is an account floating around out there "supposedly" with admin rights.

This is going to be interesting - instead of spending my day doing other stuff like washing the cars, and enjoying my Sunday, some POS fucking hacker asshole is making me do this.

Grrrrrrrrrrrrrrrrrrrrrrrrrrrrrr. :evil:

cellulargod721
04-17-2005, 04:55 PM
If we find that little bastard we should cut his fucking balls off and feed them to his mother. Then cut each one of his frickin fingers off so he cant fuck up another board ever again. Note to the hacker: FUCK YOU!!

Speed Racer
04-17-2005, 04:57 PM
Chad,

Relax, this is a known hack problem - which is why version 2.0.14 was released on 4/15 - many phpBB forums have been hit.

cellulargod721
04-17-2005, 05:02 PM
Sorry I just hate it when people cant leave things alone. Is it too much to ask that just cause you know how to screw things up that you dont. Like I said sorry for getting heated but it just really gets me that little punks like this have to go thru and screw with everyone. My deepest apologies for getting irate. And thank you for all your hard work Speed Racer!

Speed Racer
04-17-2005, 05:34 PM
Ok...

We are on version 2.0.14 now - all the updates files are in place. We likely have lost all the mods I've done to the forum, because with the changed files, there was no way to preserve them.

We have some plans in place for some serious forum changes (ie; Vbulletin new version) and we'll keep you posted as to what's going on.

I'm sorry I didn't get the patches and updates in place sooner, since they only came out on Friday - but a buddy of mine warned me that this was going to happen - since it happened to his DJ forum a few days ago.

Thanks everyone.

Malloy
04-17-2005, 05:35 PM
Thanks Steve, you are da man! I just bought vBulletin...so expect a changeover soon :)

Ironic, that I started working on a switch to vBulletin Fri night....and we get hacked just 2 days later.

Phil G.
04-17-2005, 05:37 PM
Die hacker scum!! :fawk: :evil: :evil2:

Tanya
04-17-2005, 05:39 PM
Thanks for getting us back up :) Switchover to Vbulletin huh? Damn I liked PhpBB too, SF just got the upgrade over there and I cant say Im too happy with their layout, but Im sure Sidman will do better ;)

CDarthvader
04-17-2005, 05:40 PM
If your lookin for a new Vbullitin thing one of the forums i visit has a nice one that has a preview thing on the forums. Like if you hover over a link it will preview about the first sentence of the actual post.

I think SF uses the same one to*edit*

Speed Racer
04-17-2005, 05:45 PM
I'm going to tweak Vbulletin with a different skin set and try to make it look more like what we have now. I don't care for the layout over at SF.com either, and I'll do my best to make it look nicer.

I do like the functionality of Vbulletin, but we first have to successfully migrate the existing database over to it. I know nothing about how Vbulletin works, so this is going to be interesting. Mike's got the software on his end, so the two of us should be able to figure it out.

He's got a copy of the database on his PC and I do too, so we should be ok. What a flipping pain in the ass though.

The biggest reason for doing this is support and functionality - phpBB is always going to be focused on by hackers because it's "free" and heavily used on the internet. Our forum has been pretty damn stable for the most part, some little minor hiccups here and there but nothing I would call unusual.

I have two more forums I need to upgrade to phpBB 2.0.14 and then I can enjoy the rest of my day.

MWebber
04-17-2005, 06:36 PM
I have two more forums I need to upgrade to phpBB 2.0.14 and then I can enjoy the rest of my day.

:fainting:

on another note....I've noticed a few forums going over to VB...


Mike

Andrew
04-17-2005, 06:59 PM
Good Job Steve, We all really appriciate it.

SupraOfDoom
04-17-2005, 07:09 PM
supramania got hacked a little while ago by some phpbb script... you better switch over to something new :O , they lost nearly everything.

Speed Racer
04-17-2005, 07:20 PM
supramania got hacked a little while ago by some phpbb script... you better switch over to something new :O , they lost nearly everything.

This is why we...

a) backup the database often
b) are going to migrate over to Vbulletin asap

I'm aware of what happened over at Supramania.com - which is why I'm so careful about making sure our database is backed up.

punkara
04-17-2005, 07:24 PM
thank you for the great job you're doing! :dj_smile: we all apriciate it!
I wonder if this little hacker son of ***** owns a damn honda civic or something?
die hack :comp_pow:

Arnout
04-17-2005, 07:40 PM
I didn't get that email. Is the porn any good?

Speed Racer
04-17-2005, 07:47 PM
I didn't get that email. Is the porn any good?

I suggest you don't visit the URL that was in the email. Since these morons are "hackers" who knows what malware/spyware BS is waiting on their server. I'd rather not find out, myself.

TOYMAN321
04-17-2005, 07:58 PM
Admin;
I was on the site when it was taken down, thank you all for clearning things up and fixing things so quickly, great job admin! :worship:

canadian_psyko
04-17-2005, 08:18 PM
Just for fun, It checked it out. (I love knoppix). It's no auto install stuff, just 4 .pif files, which I assume are viruses based on the fact they aren't image format files.

Oh, and for mods, is you have ssh access, you can use the patch file, works ok on the 1 I've done so far, working on another one right now.

Speed Racer
04-17-2005, 08:29 PM
Just for fun, It checked it out. (I love knoppix). It's no auto install stuff, just 4 .pif files, which I assume are viruses based on the fact they aren't image format files.

Oh, and for mods, is you have ssh access, you can use the patch file, works ok on the 1 I've done so far, working on another one right now.

Yup, I looked at them too. Same conclusion.

CelicaSupra.com and the CelicaSupra.com logo - Copyright © 2004 2005 - All Rights Reserved

Powered by phpBB 2.0.14 © 2005 phpBB Group
Upgrade already done. Upgraded forums on 3 diff websites & I'm aware that patch files can be used. I chose the "changed files only" method, which is what I normally do. Seems to be working ok so far.

Jax184
04-17-2005, 08:39 PM
YaBB!!

Anyway, does VB have a Working search system?
I get the feeling some of the noobs might stop asking such dumb questions if the search function we told them to use actually worked decently.

chassisb0t
04-17-2005, 08:55 PM
i could tell it was bogus, but I almost clicked it.
If you really need help with some bad spyware or virus issues, I'm a lightweight virus technician and I might help you out.
:billy_za:

underconstruction
04-17-2005, 09:25 PM
I am wondering the same as punkara
I wonder if this little hacker son of ***** owns a damn honda civic or something?

repinS
04-17-2005, 09:51 PM
YaBB!!

Anyway, does VB have a Working search system?
I get the feeling some of the noobs might stop asking such dumb questions if the search function we told them to use actually worked decently.

phpBB search works... only if you know how to gratuitously use the "and" function. That's what I don't like about it. I've never totally familiarized myself on how to effectively search vB, but it's not the same as phpBB.

supra8215
04-17-2005, 10:34 PM
I wonder if this little hacker son of ***** owns a damn honda civic or something? :fawk: :banme: Jk man.

I didn't think it was Malloy. Just because Mike would actually take the time to spell Thanks, not thx.

Thanks again Steve.

Malloy
04-17-2005, 11:00 PM
vBulletin will rock the house. It will not look anything like sf.com....I already have a few skins that look clean.

btw: I like the way this site looks ;-) http://www.rx8club.com/

Phil G.
04-17-2005, 11:30 PM
btw: I like the way this site looks ;-) http://www.rx8club.com/

Figures :shakehea:

ma615mgte
04-17-2005, 11:57 PM
I'm upgrading us to version 2.0.14 right now - we may lose some of the mods I've done, unless I use the patch files only. I'm reading about the update now.

What concerns me is that there is an account floating around out there "supposedly" with admin rights.

This is going to be interesting - instead of spending my day doing other stuff like washing the cars, and enjoying my Sunday, some POS fucking hacker asshole is making me do this.

Grrrrrrrrrrrrrrrrrrrrrrrrrrrrrr. :evil:

it was a nice day here for it, i enjoyed my drive.. im glad all has gotten fixed too. i just saw the e-mail and i knew right off it didnt look important so i deleted it..

btw i do like the look of the rx8 forum too.

85 rat rod
04-18-2005, 02:22 AM
chad is right tho... to a certian extent, if someone does cut his fingers off, while your at it, you should force feed them to him in wendys chilly!

3000cc MK2
04-18-2005, 12:03 PM
btw: I like the way this site looks ;-) http://www.rx8club.com/

Figures :shakehea:

:imwithst:

supra8215
04-18-2005, 02:03 PM
vBulletin will rock the house. It will not look anything like sf.com....I already have a few skins that look clean.

btw: I like the way this site looks ;-) http://www.rx8club.com/ It looks good.

OFF TOPIC: Is that forum pretty good? My brother is about to buy a RX8, and he wants somewhere where he can learn about the rotary stuff. Is that n00b friendly?

BACK ON TOPIC:

Speed Racer
04-18-2005, 02:17 PM
I installed & used a little php program on the server to "cleanse" the database, and found no other admin accounts, other than the ones that should be there...so apparently we're ok.

Whew ;)

soren dy
04-18-2005, 05:40 PM
So when you do find that little sob just mail us all his name, adress and a picture of his car and licensplate and let nature take it´s course, that´s how we deal with his kind of people where i´m from.

Best regards DY

BillyM
04-18-2005, 05:59 PM
...give me an IP.

I have 15 t1's and a t3 just waiting to burn his ass between 5pm and 6am.

--BillyM

Tommy
04-18-2005, 06:05 PM
Thanks Steve, you are da man! I just bought vBulletin...so expect a changeover soon :)

Ironic, that I started working on a switch to vBulletin Fri night....and we get hacked just 2 days later.

He didn't buy shit, I gave him my spare license... :D

288888888888888!

Malloy
04-18-2005, 08:33 PM
Dont mind this guy...he is a Trailblazer fan :roll: :D



Thanks Steve, you are da man! I just bought vBulletin...so expect a changeover soon :)

Ironic, that I started working on a switch to vBulletin Fri night....and we get hacked just 2 days later.

He didn't buy shit, I gave him my spare license...

288888888888888!

Junkie
04-18-2005, 11:11 PM
I got 2 emails.....both went to BULK in my Yahoo account,so I read about it here 1st.Sometimes yahoo will send a legit email to bulk,and I have kinda just bitched to myself....figured everyone thought I was full of B.S.

Finaly worked to my benefit :lol:

stevrock
04-19-2005, 01:51 AM
I like Vb.

The search function is like any other, it searches for the words that you type in. I'm over at www.yotatech.com for alot of my time and they are with Vb.

Good stuff over there, I like it alot.

I'm not big on this host but the information is too good to turn my back on.

phreaky728
04-19-2005, 11:14 AM
heres what i got in my extended headers feature in gmail, finding out his email is nobody@host.solidwebdomains.com :




X-Gmail-Received: d336ccf352c8b8c68bc1b713e760a159efdfadfa
Delivered-To: me@gmail.com
Received: by 10.38.73.48 with SMTP id v48cs22642rna;
Sun, 17 Apr 2005 12:42:47 -0700 (PDT)
Received: by 10.38.68.14 with SMTP id q14mr4918992rna;
Sun, 17 Apr 2005 12:42:47 -0700 (PDT)
Return-Path: <nobody@host.solidwebdomains.com>
Received: from host.solidwebdomains.com (host.solidwebdomains.com [209.59.142.198])
by mx.gmail.com with ESMTP id 59si19763rnd.2005.04.17.12.40.07;
Sun, 17 Apr 2005 12:42:32 -0700 (PDT)
Received-SPF: pass (gmail.com: best guess record for domain of nobody@host.solidwebdomains.com designates 209.59.142.198 as permitted sender)
Received: from nobody by host.solidwebdomains.com with local (Exim 4.44)
id 1DNF4f-0000xa-4v; Sun, 17 Apr 2005 15:04:53 -0400
To: malloy@celicasupra.com
Subject: Help us thx!
Reply-to: malloy@celicasupra.com
From: malloy@celicasupra.com
Message-ID: <e8e848f7d9cf099e08f3cd0d58d48b11@www.celicasupra. com>
MIME-Version: 1.0
Content-type: text/plain; charset=iso-8859-1
Content-transfer-encoding: 8bit
Date: Sun, 17 Apr 2005 15:04:53 -0400
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: PHP
X-MimeOLE: Produced By phpBB2
X-AntiAbuse: Board servername - www.celicasupra.com
X-AntiAbuse: User_id - 2
X-AntiAbuse: Username - Malloy
X-AntiAbuse: User IP - 211.185.204.66
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - host.solidwebdomains.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12]
X-AntiAbuse: Sender Address Domain - host.solidwebdomains.com
X-Source:
X-Source-Args:
X-Source-Dir:


The following is an email sent to you by an administrator of "CelicaSupra.com". If this message is spam, contains abusive or other comments you find offensive please contact the webmaster of the board at the following address:

malloy@celicasupra.com

Include this full email (particularly the headers).

Message sent to you follows:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~

hi,
please help us with some downloads & clicks
visit http://www.teendump.dk.tc


Download it and have fun!

best regards
admin

MWebber
04-19-2005, 12:01 PM
solidwebdomains.com

that's the company that is hosting the site. The script was used against the server and used the server's php mail() function to send the email. The email did come from this site, but, wasn't authorized by Mike or Steve since they are the only guys that should access to those features of the board.

I hate to say this, but finding the person responsible will be extremely difficult. First the host would have to look at the logs and find out when the mail function is being used, sort through ALL the mail function usage, then find the corrosponding IP addresses, sort through those, then they would need to contact law enforcement and get them in on it to draw up a warrent (ad investigate) to get the guy's account info from the guy's ISP. Then, they would know who to go after....

IIRC, they won't do much unless the 'victim' has lost $10k or more from the attack. :?

-MW

Import_Eve
04-19-2005, 10:53 PM
I kinda knew it was a fake email after reading the url that we are surpost to click on.

cellulargod721
04-20-2005, 12:20 PM
chad is right tho... to a certian extent, if someone does cut his fingers off, while your at it, you should force feed them to him in wendys chilly!

Yuk!! I eat Wendys chili almost daily.

*searches for hackers fingures in his bowl o' chili*

Oh well ty for the props rat rod! 8-)

Tanya
04-20-2005, 01:22 PM
was the forum just hacked again? It was down for like 10-20 minutes for me *shrug*...then I thought we might be switching over to Vb but I didnt know

Malloy
04-20-2005, 01:27 PM
I was backing up the database to get ready for a change to vBulletin.

Malibyte
04-20-2005, 01:36 PM
I have to admit that I'm not as impressed with vBulletin as phpBB (mostly look and feel); also wondering what we'd lose in the conversion. Couldn't we simply get the latest phpBB patches installed? It's your call, but just thought I'd throw in my :twocents:.

Tanya
04-20-2005, 01:47 PM
yeah I like the feel of PhpBB as well, BUT I think Sidman can make Vb look just as well

:bigok:

Malloy
04-20-2005, 02:51 PM
http://www.rx8club.com/

bob: do you like the look/feel of that site?

MWebber
04-20-2005, 02:56 PM
http://www.rx8club.com/

bob: do you like the look/feel of that site?

not that you asked me, but IMHO...

I like it with the exception of the ad, it needs to be moved elsewhere and the forum moved up a bit towards the top.

layout-wise, I like it. (it even has the 'subscribe' features some people were asking for.

then again... you didn't ask me. :mrgreen:

Chrisfrom1986
04-20-2005, 03:03 PM
agreed, the add can go over that gay area where they stretched the road and have the forum moved up to fill the space, then it would be near perfect... if it was the celicasupra site :P

Gage006
04-20-2005, 04:13 PM
vb isn't too bad, i'm just used to php. As far as the actual posts, on rx8 they have it setup so the icons and user info is on top of the post...that's annoying. Is it possible to keep it so it's on the left side of the post? That's my only complaint.

Speed Racer
04-20-2005, 05:39 PM
I have to admit that I'm not as impressed with vBulletin as phpBB (mostly look and feel); also wondering what we'd lose in the conversion. Couldn't we simply get the latest phpBB patches installed? It's your call, but just thought I'd throw in my :twocents:.

Bob,

I've already installed the patches, so we're up to date with the latest security bandaids from phpBB. The reason we want to "try" Vbulletin is because they have a better support system, and they are less of a target for hackers / script kiddies vs. phpBB. Also, phpBB doesn't have a lot of the functionality that Vbulletin does for moving posts, and making changes to the database on the fly too.

The phpBB forum software is good, and it does let you do a lot of things administration wise but it's not too great about housekeeping issues. Sometimes the the forum "prune" command to get rid of old posts in For Sale and Wanted doesn't always work. If someone creates a duplicate post in another section of the forum, I can't just grab that entire thread and combine it with the existing thread, to preserve the posts and keep the conversations in one spot.

What we want to do is "try" Vbulletin and see how it goes. If it sucks, we'll go back to using phpBB. Also, keep in mind, it's going to take a while to get it up and running, get all the sections of the forum established, figure out how it works and then start the "tweaking" process where we customize it to look just the way we want it to.

All we ask is that everyone let us get it running, and get the bugs out BEFORE you start hammering us with "can you do this? can you do that?" because we are behind the learning curve with Vbulletin...and need time to come up to speed first.

Chrisfrom1986
04-20-2005, 06:08 PM
If someone creates a duplicate post in another section of the forum, I can't just grab that entire thread and combine it with the existing thread, to preserve the posts and keep the conversations in one spot.
im sure vbulletin is good with this. :)

trdmkii
04-20-2005, 06:12 PM
I like vbulliten set up (other than the color scheme) on this site....i like the quick reply option...and the overall setup.... http://www.celicatech.com/forums/index.php

toyotaman5mge
04-24-2005, 04:38 PM
I down loaded the link. and now my computer is all fucked up. what can I do about it.. it makes my computer shut down as soon as I log on.. help