Development site has been hacked!!

Development site has been hacked!!

Discuss the source code and development of Spring Engine in general from a technical point of view. Patches go here too.

Moderator: Moderators

User avatar
Gabba
Posts: 319
Joined: 08 Sep 2004, 22:59

Development site has been hacked!!

Post by Gabba »

Hello people,

I don't have much time to hang around the forums anymore, but I went to check out the "new" development forum at http://taspring-linux.berlios.de/, and as of now :shock: it redirects to a hacker site: http: // naryech.by.ru / index / index.htm (hit CTRL-A to see the hidden text).
(edit: I voluntarily messed up the URL 'cause I don't want to link to it... google ranking etc. If you want to see the hacker's signature you can always copy the url and remove the spaces to make it work.)

My personal guess is that the CMS that was being used hasn't been kept up to date - the typical cause for hacker attacks.

AF, you better check this out!!
Last edited by Gabba on 20 Sep 2006, 06:52, edited 1 time in total.
User avatar
BvDorp
Posts: 439
Joined: 14 Oct 2005, 12:09

Post by BvDorp »

E: being stupid here..
Tobi
Spring Developer
Posts: 4598
Joined: 01 Jun 2005, 11:36

Post by Tobi »

took the thing offline
User avatar
AF
AI Developer
Posts: 20687
Joined: 14 Sep 2004, 11:32

Post by AF »

I put it up as maintenance, but forgot the direct path to the login page

edit:
Oh crap I thought you were referring to the maintenance, I hadnt read the post properly....
Tobi
Spring Developer
Posts: 4598
Joined: 01 Jun 2005, 11:36

Post by Tobi »

AF, do you still have a copy of configuration.php locally?
User avatar
AF
AI Developer
Posts: 20687
Joined: 14 Sep 2004, 11:32

Post by AF »

It shouldnt be that hard to setup a new config.php. Did they replace the existing config.php with the defaced webpage?
Tobi
Spring Developer
Posts: 4598
Joined: 01 Jun 2005, 11:36

Post by Tobi »

They/he replaced the files' contents with a <script>location=blah;</script> tag.
Maybe I have a backup myself tho, will look tomorrow.
User avatar
AF
AI Developer
Posts: 20687
Joined: 14 Sep 2004, 11:32

Post by AF »

I have the stuff to fix it but its saying permission denied, I cant upload anything or change any of the files around
User avatar
Caydr
Omnidouche
Posts: 7179
Joined: 16 Oct 2004, 19:40

Post by Caydr »

Moron. That'll really be something to write home about. "Today I hacked a defenseless open-source game project's web site! I am L33T!!!!111"
User avatar
LOrDo
Posts: 1154
Joined: 27 Feb 2006, 00:21

Post by LOrDo »

Just...why? :|
User avatar
Das Bruce
Posts: 3544
Joined: 23 Nov 2005, 06:16

Post by Das Bruce »

Felony 9, first warning I would say. -- SinbadEV
HawkMan
Posts: 53
Joined: 20 Jul 2006, 22:28

Post by HawkMan »

insecure CMS systems... this happens all the time to sites runnign e107 since they can just google for sites runngin it, and then run their automated scripts.

Guess whatever CMS that site where runnign has the same security problems.
User avatar
Neddie
Community Lead
Posts: 9406
Joined: 10 Apr 2006, 05:05

Post by Neddie »

Well - that was unexpected.
User avatar
Snipawolf
Posts: 4357
Joined: 12 Dec 2005, 01:49

Post by Snipawolf »

That's pathetic, go hack a bank site, nub..
Last edited by Snipawolf on 24 Sep 2006, 01:03, edited 1 time in total.
Dwarden
Posts: 278
Joined: 25 Feb 2005, 03:21

Post by Dwarden »

any important data loses or just frontend and pain in ass (timesink) ?
User avatar
AF
AI Developer
Posts: 20687
Joined: 14 Sep 2004, 11:32

Post by AF »

I need to uplaod a new configuration.php, and I have the original copy that was used after it was all installed. However I cannot do anything to the dev sites files, I get permission denied. The database is all intact though.
User avatar
Guessmyname
Posts: 3301
Joined: 28 Apr 2005, 21:07

Post by Guessmyname »

...

why?

Why hack someone's site. If you're just pointing out a flaw in their system (which is the only real / sensible reason I can think of, but then, this is the internet - hardly renowned for reason and sensibility) would it not be best to simply notify the web host / owner / html script monkey?
User avatar
Snipawolf
Posts: 4357
Joined: 12 Dec 2005, 01:49

Post by Snipawolf »

Cuz they are soooo 1337 that they think it would be awesome too...

/Sarcasm/

They can't go and hack a bank to get rich or something, they waste their time playing with an open-source game site..
Dwarden
Posts: 278
Joined: 25 Feb 2005, 03:21

Post by Dwarden »

it shows it were lame crackers w/o honor...

they not contacted admin / owner with informations about security hole (usually in exchange for credits mentioned somewhere on site after being fixed) ...

and if they erased / damaged data , twice lame ...

in such case , it's just crime, nothing less nothing more ... same like someone take baseball bat and demolish Your car ...

if You got logs , share with some local authorities ...
Acreo Aeneas
Posts: 23
Joined: 17 Sep 2006, 19:29

Post by Acreo Aeneas »

Hmm. This is interesting.

First time I've heard a Open-Source site, much less a gaming site, come under attack by kiddie-hackers or the likewise. I truly wonder if there was some unseen motivation for this very stupid attack?
Post Reply

Return to “Engine”