Author Topic: Unauthorized Update  (Read 12149 times)

0 Members and 1 Guest are viewing this topic.

Offline Trivial Psychic

  • 212
  • Snoop Junkie
Ah, don't look now, but it appears as though there is an unauthorized update to your website... from yesterday.
The Trivial Psychic Strikes Again!

 

Offline Veers

  • 29
Quote
nullbyt3 was here.
>12/03/2011  |  IceFire

nullbyt3 was here. You website is vulnerable to multiple exploits. Please address these problems.

[email protected]

Quote
Development Team

    Bobboau - Chief model designer, MOD manager
    Kellan - Mission designer and story creator (absent)
    ShadowWolf - Mission designer
    Alikchi - Mission designer
    nullbyt3 - New Team leader

Quote
http://www.safe-mail.net/

Safe-mail is the most secure, easy to use communication system. It includes encrypted mail system with collaboration features and document storage functions. Always accessible at any time from anywhere!
3 Mb space is free. More space and functionality is supplied under Premium Packages. There are no advertisements, downloads or cookies. Safe-mail supports most hardware platforms and any operating system. Includes file storage, spam filters and anti virus protection. Full compatibility with most browsers, email clients and all relevant protocols including POP, SMTP, IMAP, S/MIME and PKI.


??? I sure hope nothing else was done.
Current Activities/Projects: Ideas and some storyline completed.

ArmA 2&3 Mission Designer and player.


WoD - I like Crystal. <3

 

Offline Nyctaeus

  • The Slavic Engineer
  • 212
  • 800k tris ships achieved!
    • Exile
My avast found a virus in your gallery section! o__O
Exile | Shadow Genesis | Inferno | Series Resurrecta  | DA Profile | P3D Profile

Proud owner of NyctiShipyards. Remember - Nyx will fix it!

All of my assets including models, textures, skyboxes, effects may be used under standard CC BY-NC 4.0 license.

 

Offline Dragon

  • Citation needed
  • 212
  • The sky is the limit.
Pehaps he's a guy from that safe-mail trying to convince you to improve your security (by using their E-mail system and paying for premium packgages, of course).
Or maybe somebody who wanted a challenge and once he was done, just wanted to be helpfull.
Anyway, updates on BWO site are always welcome, though unfortunately, there's no info on progress in there.  :)

  

Offline Nyctaeus

  • The Slavic Engineer
  • 212
  • 800k tris ships achieved!
    • Exile
Yeah, I know you have amazing assets but you showed only old outdated screenshots and low poly models :(. We want more :D!
Exile | Shadow Genesis | Inferno | Series Resurrecta  | DA Profile | P3D Profile

Proud owner of NyctiShipyards. Remember - Nyx will fix it!

All of my assets including models, textures, skyboxes, effects may be used under standard CC BY-NC 4.0 license.

 

Offline Fury

  • The Curmudgeon
  • 213
Hacked again? Seriously. :no: Whoever is doing your websites should probably learn something about security.

 
nullbyt3 here.


Just letting you know that, no I didn't add any malicious content to your site, nor did I modify content in a malicious manner.. Thats not my thing.  I was simply showing you how easy it is to get Administrator access on\f your site and if I can do it a skid won't be far behind trying to upload his index.

I left the email in the event you wanted advice on how to secure your site. Obviously whoever is doing it is doing a bad job.  As far as how I got in? I don't remember exactly? I break a lot of sites security to leave messages like that to help Web Administrators like yourselves, but in the past few days I have used SQL injection(Full Blind, Double Query, and basic), Symlink attacks, XSS, and one unpublished php code injection(via Perl) attack. 

I don't deface or ruin sites because I'm not a script kiddie. I left the email for you to contact me in the event you actually "want" to find out the problem and need a fix that will work. Safe-mail is just an email provider that encrypts emails between safe-mail users.

 If you email me the site link I will give you more input on how I got in and how to stop the next guy from getting in. Oh, and as far as Avast detecting a virus, Avast has probably flagged some php code in an image or a php shell as a virus. There was NO malicious content that could infect users visiting your site. 


« Last Edit: March 16, 2011, 11:03:40 am by nullbyt3 »

 

Offline Luis Dias

  • 211
So.... what are you selling, and for how much?

 

Offline Snail

  • SC 5
  • 214
  • Posts: ☂
Hey, cool! An internet vigilante! Can I have your autograph, sir? :cool:

 

Offline TopAce

  • Stalwart contributor
  • 212
  • FREDder, FSWiki editor, and tester
nullbyt3 here.


Just letting you know that, no I didn't add any malicious content to your site, nor did I modify content in a malicious manner.. Thats not my thing.  I was simply showing you how easy it is to get Administrator access on\f your site and if I can do it a skid won't be far behind trying to upload his index.

I left the email in the event you wanted advice on how to secure your site. Obviously whoever is doing it is doing a bad job.  As far as how I got in? I don't remember exactly? I break a lot of sites security to leave messages like that to help Web Administrators like yourselves, but in the past few days I have used SQL injection(Full Blind, Double Query, and basic), Symlink attacks, XSS, and one unpublished php code injection(via Perl) attack. 

I don't deface or ruin sites because I'm not a script kiddie. I left the email for you to contact me in the event you actually "want" to find out the problem and need a fix that will work. Safe-mail is just an email provider that encrypts emails between safe-mail users.

 If you email me the site link I will give you more input on how I got in and how to stop the next guy from getting in. Oh, and as far as Avast detecting a virus, Avast has probably flagged some php code in an image or a php shell as a virus. There was NO malicious content that could infect users visiting your site.

But then why hack the site instead of posting about it here?
My community contributions - Get my campaigns from here.

I already announced my retirement twice, yet here I am. If I bring up that topic again, don't believe a word.

 

Offline MatthTheGeek

  • Captain Obvious
  • 212
  • Frenchie McFrenchface
Cause it would have made his point so much less viable !
People are stupid, therefore anything popular is at best suspicious.

Mod management tools     -     Wiki stuff!     -     Help us help you

666maslo666: Releasing a finished product is not a good thing! It is a modern fad.

SpardaSon21: it seems like you exist in a permanent state of half-joking misanthropy

Axem: when you put it like that, i sound like an insane person

bigchunk1: it's not retarded it's american!
bigchunk1: ...

batwota: steele's maneuvering for the coup de gras
MatthTheGeek: you mispelled grâce
Awaesaar: grace
batwota: oh right :P
Darius: ah!
Darius: yes, i like that
MatthTheGeek: the way you just spelled it it means fat
Awaesaar: +accent I forgot how to keyboard
MatthTheGeek: or grease
Darius: the killing fat!
Axem: jabba does the coup de gras
MatthTheGeek: XD
Axem: bring me solo and a cookie

 
Cause it would have made his point so much less viable !

^^Exactly!

 That , and its more the fact that I didn't know that this community existed until I read the above posts yesterday. I didn't deface it or delete anything so the site itself is fine, but I hope the owner takes the time to secure it before some kids come along and ruin it just for fun. Again, if you need any help securing your DB/Website you have my safe-mail addy. 

And no, I'm not trying to sell anything. I have ethics. Peace and Good luck.

 

Offline Mobius

  • Back where he started
  • 213
  • Porto l'azzurro Dolce Stil Novo nella fantascienza
    • Skype
    • Twitter
    • The Lightblue Ribbon | Cultural Project
Does this mean that the other projects' websites are equally vulnerable?
The Lightblue Ribbon

Inferno: Nostos - Alliance
Series Resurrecta: {{FS Wiki Portal}} -  Gehenna's Gate - The Spirit of Ptah - Serendipity (WIP) - <REDACTED> (WIP)
FreeSpace Campaign Restoration Project
A tribute to FreeSpace in my book: Riflessioni dall'Infinito

 

Offline Droid803

  • Trusted poster of legit stuff
  • 213
  • /人 ◕ ‿‿ ◕ 人\ Do you want to be a Magical Girl?
    • Skype
    • Steam
Mmmm yeah.
I think we should do something about our security.
I mean, its not the first time its been hacked either :P
(´・ω・`)
=============================================================

 

Offline Raven2001

  • Machina Terra Reborn
  • 211
  • Im not the droid your looking for, move along
A hacker with morals!

Unusual, but quite welcome :)
Yeah, I know you were waiting for a very nice sig, in which I was quoting some very famous scientist or philosopher... guess what?!? I wont indulge you...

Why, you ask? What, do I look like a Shivan to you?!?


Raven is a god.

 

Offline Mobius

  • Back where he started
  • 213
  • Porto l'azzurro Dolce Stil Novo nella fantascienza
    • Skype
    • Twitter
    • The Lightblue Ribbon | Cultural Project
Mmmm yeah.
I think we should do something about our security.
I mean, its not the first time its been hacked either :P

What can we do about it?
The Lightblue Ribbon

Inferno: Nostos - Alliance
Series Resurrecta: {{FS Wiki Portal}} -  Gehenna's Gate - The Spirit of Ptah - Serendipity (WIP) - <REDACTED> (WIP)
FreeSpace Campaign Restoration Project
A tribute to FreeSpace in my book: Riflessioni dall'Infinito

 

Offline Goober5000

  • HLP Loremaster
  • 214
    • Goober5000 Productions
You, nothing.  The admins are looking into it.

 

Offline Fury

  • The Curmudgeon
  • 213
That is incorrect. Admins cannot do anything about hosted project sites that have security issues. Unless of course, you want to examine and fix hosted project sites security yourself. Unlikely to happen, isn't it?

The more complex a site is, the more likely is it that you may have security problem or few. The BWO/CE website uses php and mysql, making it far more vulnerable to exploits than standard basic html. But it is possible to have exploits even in basic html, though these are rare.

What admins have control over is server-wide security, namely that of apache, php and mysql. Security updates to any and all packages are handled automatically. While I can never be 100% sure, I'm quite confident settings of apache, php and mysql are secure enough without compromising php compatibility. Improvements can be done via 3rd party tools, such as mod_security. Last time mod_security was installed it caused problems with SMF though.

Case in point, if the server had exploitable security holes, I'm pretty sure the mainpage, forums or wiki would have been victimized many times already instead of some random hosted project site that's obscure even among hosted projects. Still, it doesn't hurt to contact this guy and confirm what security exploit was used, if nothing else at least that gives yet another lesson of security to whoever is coding BWO website.

 

Offline Goober5000

  • HLP Loremaster
  • 214
    • Goober5000 Productions
Well, I meant "you" as in Mobius specifically, but reading his question again that wasn't quite fair to him because he did ask the question using "we".

Anyway, we are in contact with nullbyt3 and he has given us some useful information about how the site is vulnerable.  We will shortly be in contact with the BWO staff.

(Incidentally, who is in charge of website design on the BWO site, and why hasn't he posted on this thread yet?)

 

Offline Snail

  • SC 5
  • 214
  • Posts: ☂
(Incidentally, who is in charge of website design on the BWO site, and why hasn't he posted on this thread yet?)
Given the age of the CE website maybe they've left. :P