Welcome, Guest. Please login or register.

Username: Password:
Pages: [1] 2   Go Down

Author Topic: 25Sep11 Draconity.org "Hack"  (Read 778 times)

0 Members and 1 Guest are viewing this topic.

Selroth

  • 'Lil Imaginary Friend
  • Administrator
  • Legendary Dragon
  • *****
  • Online Online
  • Gender: Male
  • Posts: 3,606
    • Draconity.org
25Sep11 Draconity.org "Hack"
« on: September 25, 2011, 06:30:36 PM »

Today I woke up to see Aure sent me an email that the site was hacked with a screenshot.  What a way to begin the day!

Anyway, many of you probably saw a defaced page.  We were lucky in that the code in it doesn't seem to be malicious, so everyone who saw the page should be safe.  But, because of events like this, it's always good to keep your operation system, browser, and anti-virus up to date!

Draconity.org itself was not attacked, and as far as I can see no personal information was stolen nor any privacy invasion. 

The host I rent the Virtual Private Server from, InMotion Hosting, was attacked, and a ton of their sites were defaced in a similar fashion.  You can read details here:
http://www.inmotionhosting.com/20110925-systems-announcement.html

Anyway, I took the liberty to upgrade all website software.  There may be a few bugs around, but that's normal - just report them here if you find any. 

The host is also applying a fix to all their customers, and the site may go down again for a moment.  They're assuming most of their customers don't know how to fix their site, I already fixed and upgraded my index.php file, but they may restore it off one of their backups, thus breaking the site with a version mismatch between files.  As soon as I see this, I'll have the site back up as I undo their "fix".
Logged
Everything is built from imagination.

I love hearing from the community I maintain!  Feel free to send me a PM or look around my profile.

ImadNemeir

  • the awakened one
  • Private Member
  • Elder Dragon
  • *****
  • Online Online
  • Gender: Male
  • Posts: 1,091
  • here to enjoy myself
Re: 25Sep11 Draconity.org "Hack"
« Reply #1 on: September 25, 2011, 06:52:25 PM »

Good to see everything (almost) is back to normal, and it's also extremely good that no information was stolen (I got really worried about that by the way)

well then we'll get back to business as usual
Logged
looking at things with different perspective is the only way of understanding them.

sillydraco

  • The Silly Dragon
  • Global Moderator
  • Legendary Dragon
  • *****
  • Offline Offline
  • Gender: Male
  • Posts: 2,968
  • the silliest little anklebiter
Re: 25Sep11 Draconity.org "Hack"
« Reply #2 on: September 25, 2011, 07:08:03 PM »

Defaced? what someone graffiti'd the site? what did it look like?
Logged
I love you. I'm sorry. I forgive you. Thank you.

Time for sleepy, dream of new things...new life, new reality, new wings.

LackeDragon

  • French water/air dragon
  • Whelp
  • **
  • Offline Offline
  • Gender: Male
  • Posts: 50
    • My art gallery (drawing specially^^)
Re: 25Sep11 Draconity.org "Hack"
« Reply #3 on: September 25, 2011, 07:10:21 PM »

There was a big HACKED on the page yep
Pretty scaring lol
Logged
Dragon is my past, human is my present, but my future is what I want to become

<a href="http://Ferator.dragonadopters.com/dragon_Dragon_Egg" target="_blank"><img src="http://www.Ferator.dragonadopters.com/dragonimage_82_629_pixelNA" border="0" alt="Dragonadopters" >[/url]

Smotri

  • Critter
  • Wise Dragon
  • ****
  • Online Online
  • Gender: Male
  • Posts: 536
  • Boots on the ground, wings in the sky
Re: 25Sep11 Draconity.org "Hack"
« Reply #4 on: September 25, 2011, 07:10:53 PM »

As soon as the page is entered a script hijacks the browser and shrinks it. Then it spins the window around the screen before maximizing it to display the following;

WARNING: The URL in the screenshot is still affected by the hack. May not be a good idea to visit it.
« Last Edit: September 25, 2011, 07:17:23 PM by Smotri »
Logged
"Your thoughts may be monitored for quality assurance purposes." -Self
WARNING: This product contains ideas known to the State of Nebraska to cause Brain-Weasels.
I am the Asbestos Pillowfighter. I fight without a pillowcase. I fight dirty.

LackeDragon

  • French water/air dragon
  • Whelp
  • **
  • Offline Offline
  • Gender: Male
  • Posts: 50
    • My art gallery (drawing specially^^)
Re: 25Sep11 Draconity.org "Hack"
« Reply #5 on: September 25, 2011, 07:13:26 PM »

Exactly that
Logged
Dragon is my past, human is my present, but my future is what I want to become

<a href="http://Ferator.dragonadopters.com/dragon_Dragon_Egg" target="_blank"><img src="http://www.Ferator.dragonadopters.com/dragonimage_82_629_pixelNA" border="0" alt="Dragonadopters" >[/url]

sillydraco

  • The Silly Dragon
  • Global Moderator
  • Legendary Dragon
  • *****
  • Offline Offline
  • Gender: Male
  • Posts: 2,968
  • the silliest little anklebiter
Re: 25Sep11 Draconity.org "Hack"
« Reply #6 on: September 25, 2011, 07:50:51 PM »

um...why do they tell everyone who did it? they even have a facebook page -.-
Logged
I love you. I'm sorry. I forgive you. Thank you.

Time for sleepy, dream of new things...new life, new reality, new wings.

Dradolan

  • Gothic Dragon
  • Tagger
  • Legendary Dragon
  • *****
  • Offline Offline
  • Gender: Male
  • Posts: 2,637
  • ~Gothic Love~
Re: 25Sep11 Draconity.org "Hack"
« Reply #7 on: September 25, 2011, 07:50:53 PM »

I am glad I was asleep when this happened. Would have freaked me out totally. o.o
Logged
My steamID is ~Grim~RoA EoS~ (or grimroaeos to make it easier)
I have Chronic Fatigue Syndrome (CFS)
"Death is not the greatest loss in life. The greatest loss is what dies inside us while we live." - Norman Cousins


ImadNemeir

  • the awakened one
  • Private Member
  • Elder Dragon
  • *****
  • Online Online
  • Gender: Male
  • Posts: 1,091
  • here to enjoy myself
Re: 25Sep11 Draconity.org "Hack"
« Reply #8 on: September 25, 2011, 07:54:06 PM »

As soon as the page is entered a script hijacks the browser and shrinks it. Then it spins the window around the screen before maximizing it to display the following;

WARNING: The URL in the screenshot is still affected by the hack. May not be a good idea to visit it.

and if you didn't take any action while opening the page an Arab rap song would start to play
Logged
looking at things with different perspective is the only way of understanding them.

Selroth

  • 'Lil Imaginary Friend
  • Administrator
  • Legendary Dragon
  • *****
  • Online Online
  • Gender: Male
  • Posts: 3,606
    • Draconity.org
Re: 25Sep11 Draconity.org "Hack"
« Reply #9 on: September 25, 2011, 11:45:24 PM »

-Missing attachments/avatars uploaded this month fixed
-IRC Webclient fixed
-Member Map fixed

Post any other issues here, cause I may not notice the shoutbox or IRC :)
Logged
Everything is built from imagination.

I love hearing from the community I maintain!  Feel free to send me a PM or look around my profile.

Mawk

  • Queen of Sweet Potatoes 'n Stuff
  • Adult Dragon
  • ****
  • Offline Offline
  • Gender: Female
  • Posts: 328
  • No wings. No scales. Maximum imagination.
Re: 25Sep11 Draconity.org "Hack"
« Reply #10 on: September 26, 2011, 01:41:07 AM »

This didn't happen to me, but I did get a white page this morning with some black writing on it that said something about Selroth.
Logged
Mission impossible. Get started.

Selroth

  • 'Lil Imaginary Friend
  • Administrator
  • Legendary Dragon
  • *****
  • Online Online
  • Gender: Male
  • Posts: 3,606
    • Draconity.org
Re: 25Sep11 Draconity.org "Hack"
« Reply #11 on: September 26, 2011, 01:57:44 AM »

This didn't happen to me, but I did get a white page this morning with some black writing on it that said something about Selroth.

That was me performing surgery on the site while it was still conscious :)

I like that analogy.  It's fitting :)
Logged
Everything is built from imagination.

I love hearing from the community I maintain!  Feel free to send me a PM or look around my profile.

Free

  • Private Member
  • Adult Dragon
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 459
Re: 25Sep11 Draconity.org "Hack"
« Reply #12 on: September 26, 2011, 02:30:42 AM »

Real waste of our time - because they have nothing else better to do than hack random domain hosts. Cool story Bangladesh hackers l2getalife.
Logged
You think I'm a freak? Let me get on your level - Cassiopeia

Graeth-Raltharn

  • Golden Brown and Delicious--with a creamy evil center.
  • Private Member
  • Adult Dragon
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 344
  • Submarine dragon: dives and waits between posts.
    • My Muddlings
Re: 25Sep11 Draconity.org "Hack"
« Reply #13 on: September 26, 2011, 02:36:58 AM »

Yup, thought it was weird.
Noscript held it back just fine.
Logged

sillydraco

  • The Silly Dragon
  • Global Moderator
  • Legendary Dragon
  • *****
  • Offline Offline
  • Gender: Male
  • Posts: 2,968
  • the silliest little anklebiter
Re: 25Sep11 Draconity.org "Hack"
« Reply #14 on: September 26, 2011, 07:25:03 AM »

COUNTERSTRIKE TEAM AWESOME PANDA FIRE SQUAD ALPHA FORCE GO! THIS IS WHAT I TRAINED YOU FOR!
Logged
I love you. I'm sorry. I forgive you. Thank you.

Time for sleepy, dream of new things...new life, new reality, new wings.
Pages: [1] 2   Go Up
Tags: