About 6G Celicas Being Hacked |
About 6G Celicas Being Hacked |
Aug 28, 2006 - 1:13 AM |
|
Administrator Joined Aug 23, '02 From Seattle, WA Currently Offline Reputation: 14 (100%) |
Today, around 3:13PM PST, the 6G Celicas forums were hacked. I got several phone calls (thanks guys) letting me know while I was in the middle of my brake upgrade. I confirmed the site had been hacked, and killed the web services running on the server to prevent any more damage. I then waited for my parents to get home, took their car, came up to my apartment where I have fast and reliable internet access, and fixed the problems.
I don't know who did it, where they did it from, why they did it, or exactly how they did it. I do know that just before the hacker got in, a password recovery request email was sent to me that I did not request. Somehow, a malicious user could get the necessary code to complete the password recovery section, allowing that user to set a new password. In this case, they changed my password, and took the board offline, with a inappropriate message that redirected to a site after a few seconds. With the help of Invision Power Services, the forum software manufacturer, I got the problem fixed, applied my own security updates, and upgraded the board software to the latest version, which includes critical security updates. This was the first time that 6G Celicas was hacked, and should be the last. With administrative access, it appears that the only thing the malicious user did was take the board offline. There's no evidence of the user accessing the administrative control panel, or doing any other malicious work to the board. I know some of you were worried that your password might have been seen by the attacker, but it's impossible for anyone to view any user's password, because they are one-way encrypted using advanced and secure algorithms. The bottom line is that this shouldn't happen again. I'll keep better tabs on applying those security updates, and in the event that something catastrophic were to happen, I do keep frequent database and full filesystem backups. Should you notice anything different, suspicious, any errors, etc., PLEASE let me know immediately. I really appreciated everyone's help and concern today, and I'm sorry to the people I was blunt with on AIM, but we made it through this and shouldn't have to go through it again. Regards, Christian Coomer -------------------- New Toyota project coming soon...
|
Aug 28, 2006 - 8:08 AM |
|
Enthusiast Joined Jul 20, '06 From St. Thomas, Virgin Islands Currently Offline Reputation: 0 (0%) |
Oh man, this is too funny. When I tried to get onto the forums yesterday, they were down...and I was like "hmm, that's strange." So I went to my second-favorite site (a literature thing...I'm an English major, remember?) and IT was down too! I thought "no way, my internet must be screwing up, did I pay my bill this month?"
Turns out that the literature site was updating was updating some software or something at the same time 6gc went down, lol. Great job Coomer, 6gc prevails!!! Mwahahaha... -------------------- "I bet you drive a standard." "You could make some money off that bet." :D |
Lo-Fi Version | Time is now: November 29th, 2024 - 3:43 AM |