6G Celicas Forums

Welcome Guest ( Log In | Register )

> About 6G Celicas Being Hacked
post Aug 28, 2006 - 1:13 AM
+Quote Post
Coomer



Administrator
*****
Joined Aug 23, '02
From Seattle, WA
Currently Offline

Reputation: 14 (100%)




Today, around 3:13PM PST, the 6G Celicas forums were hacked. I got several phone calls (thanks guys) letting me know while I was in the middle of my brake upgrade. I confirmed the site had been hacked, and killed the web services running on the server to prevent any more damage. I then waited for my parents to get home, took their car, came up to my apartment where I have fast and reliable internet access, and fixed the problems.

I don't know who did it, where they did it from, why they did it, or exactly how they did it.

I do know that just before the hacker got in, a password recovery request email was sent to me that I did not request. Somehow, a malicious user could get the necessary code to complete the password recovery section, allowing that user to set a new password. In this case, they changed my password, and took the board offline, with a inappropriate message that redirected to a site after a few seconds.

With the help of Invision Power Services, the forum software manufacturer, I got the problem fixed, applied my own security updates, and upgraded the board software to the latest version, which includes critical security updates. This was the first time that 6G Celicas was hacked, and should be the last.

With administrative access, it appears that the only thing the malicious user did was take the board offline. There's no evidence of the user accessing the administrative control panel, or doing any other malicious work to the board.

I know some of you were worried that your password might have been seen by the attacker, but it's impossible for anyone to view any user's password, because they are one-way encrypted using advanced and secure algorithms.

The bottom line is that this shouldn't happen again. I'll keep better tabs on applying those security updates, and in the event that something catastrophic were to happen, I do keep frequent database and full filesystem backups.

Should you notice anything different, suspicious, any errors, etc., PLEASE let me know immediately. I really appreciated everyone's help and concern today, and I'm sorry to the people I was blunt with on AIM, but we made it through this and shouldn't have to go through it again. smile.gif

Regards,
Christian Coomer


--------------------
New Toyota project coming soon...
 
Start new topic
Replies
post Aug 28, 2006 - 9:50 AM
+Quote Post
devilsden97



Enthusiast
*****
Joined Jun 13, '05
From Poughkeepsie, NY
Currently Offline

Reputation: 2 (100%)




QUOTE(Bitter @ Aug 28, 2006 - 10:49 AM) [snapback]473661[/snapback]

QUOTE(devilsden97 @ Aug 28, 2006 - 9:18 AM) [snapback]473646[/snapback]

Glad to see that nothing else was tampered with except the redirection and nasty message.

How did everyone handle, not having 6gc.net in there life for a few hours????? I know Derrick (maskedman), was Iming me, freaking out cuz he was SOOO bored lol.

Anyone have any bored stories?

i had them taken down for an hour in response mad.gif


huh?


--------------------

Kawi Love
post Aug 28, 2006 - 10:01 AM
+Quote Post
Bitter

Enthusiast
*****
Joined Mar 11, '06
From Way South Chicago
Currently Offline

Reputation: 0 (0%)




QUOTE(devilsden97 @ Aug 28, 2006 - 9:50 AM) [snapback]473662[/snapback]

QUOTE(Bitter @ Aug 28, 2006 - 10:49 AM) [snapback]473661[/snapback]

QUOTE(devilsden97 @ Aug 28, 2006 - 9:18 AM) [snapback]473646[/snapback]

Glad to see that nothing else was tampered with except the redirection and nasty message.

How did everyone handle, not having 6gc.net in there life for a few hours????? I know Derrick (maskedman), was Iming me, freaking out cuz he was SOOO bored lol.

Anyone have any bored stories?

i had them taken down for an hour in response mad.gif


huh?

i called the interweb police on them wink.gif

if anyone went to the site and was redirected to a page not found or dns lookup problem last night, that would have been indirectly my doings.


--------------------

Posts in this topic
- Coomer   About 6G Celicas Being Hacked   Aug 28, 2006 - 1:13 AM
- - gwai1o   QUOTE(Coomer @ Aug 28, 2006 - 1:13 A...   Aug 28, 2006 - 1:22 AM
|- - Coomer   QUOTE(gwai1o @ Aug 27, 2006 - 11:22 ...   Aug 28, 2006 - 1:28 AM
- - BlackCelicaGT94   Thanks coomer for being on top of this! youre ...   Aug 28, 2006 - 1:23 AM
- - rayneezy23   yea so like that was the reason why i couldn't...   Aug 28, 2006 - 1:34 AM
- - zipstrips   coomer, thank you for taking care of 6gc!   Aug 28, 2006 - 1:36 AM
- - madmods   Man, i directed to a porn site. I was like damm Co...   Aug 28, 2006 - 1:43 AM
|- - Jen   QUOTE(madmods @ Aug 28, 2006 - 2:43 ...   Aug 28, 2006 - 2:09 AM
- - MaskedMan   thanks Coomer for getting the site back up so quic...   Aug 28, 2006 - 1:45 AM
- - pure_dx   0h snpz! ub98r l89t h0x0r FTL!!   Aug 28, 2006 - 2:08 AM
- - Blakout16   i however was redirected to another site right whe...   Aug 28, 2006 - 2:10 AM
- - Blakout16   nvm, it was in another part of another topic.... g...   Aug 28, 2006 - 2:14 AM
- - XS4lv1Truch0x   nice save. must be them civic people LMAO! h...   Aug 28, 2006 - 3:10 AM
- - WannabeGT4   It was probably some form of SQL injection that ca...   Aug 28, 2006 - 7:51 AM
- - mzztoyota   Oh man, this is too funny. When I tried to get ont...   Aug 28, 2006 - 8:08 AM
- - devilsden97   Glad to see that nothing else was tampered with ex...   Aug 28, 2006 - 9:18 AM
|- - Bitter   QUOTE(devilsden97 @ Aug 28, 2006 - 9...   Aug 28, 2006 - 9:49 AM
- - devilsden97   QUOTE(Bitter @ Aug 28, 2006 - 10:49 ...   Aug 28, 2006 - 9:50 AM
|- - Bitter   QUOTE(devilsden97 @ Aug 28, 2006 - 9...   Aug 28, 2006 - 10:01 AM
- - CelicaZR   Coomer to the rescue Keep up the good work mate...   Aug 28, 2006 - 10:12 AM
- - m0dd3d1   Good lookin' out! Don't know what i...   Aug 28, 2006 - 10:23 AM
- - hitcachi   I glad that i was at work while this whole thing w...   Aug 28, 2006 - 10:23 AM
- - LewFX   i bugged dan and dustin, then went surfing online.   Aug 28, 2006 - 10:26 AM
- - mzztoyota   I was so bored that I wound up subjecting myself t...   Aug 28, 2006 - 10:26 AM
- - DomGT   I guess I should feel lucky that I'm obsessed ...   Aug 28, 2006 - 10:55 AM
|- - DomGT   QUOTE(DomGT @ Aug 28, 2006 - 11:55 A...   Sep 1, 2006 - 11:47 PM
- - JoKeRkId613   yeah, the message said something along the lines o...   Aug 28, 2006 - 10:57 AM
- - Jaws4God   Great work Coomer! I was so scared that we...   Aug 28, 2006 - 11:23 AM
- - tomazws   Wow... it's very nice for you to get this back...   Aug 28, 2006 - 11:56 AM
- - coldbluesteel   I went into shock when it happed. I was online whe...   Aug 28, 2006 - 12:51 PM
- - lagos   QUOTE(JoKeRkId613 @ Aug 28, 2006 - 11...   Aug 28, 2006 - 1:08 PM
|- - laff09   QUOTE(lagos @ Aug 28, 2006 - 1:08 PM...   Aug 28, 2006 - 9:57 PM
- - BBoYRuGGeD   wow...all that happened while i was at work..? and...   Aug 28, 2006 - 1:20 PM
- - bloodrain   QUOTE(rayneezy23 @ Aug 28, 2006 - 2...   Aug 28, 2006 - 1:23 PM
- - easternpiro1   i wonder if it was that guy that i got into a figh...   Aug 28, 2006 - 2:54 PM
- - XS4lv1Truch0x   lmao! thats noobish lol, hacking thru exploit...   Aug 28, 2006 - 3:54 PM
- - slvr_celica_GT_816   yea i dont see why people waste there time doing s...   Aug 28, 2006 - 10:31 PM
- - CheesyLobster   i bet it was those gosh darn honda hooligans!   Sep 1, 2006 - 5:00 PM


Reply to this topicStart new topic
6 User(s) are reading this topic (6 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: November 29th, 2024 - 3:30 AM