About 6G Celicas Being Hacked |
About 6G Celicas Being Hacked |
Aug 28, 2006 - 1:13 AM |
|
Administrator Joined Aug 23, '02 From Seattle, WA Currently Offline Reputation: 14 (100%) |
Today, around 3:13PM PST, the 6G Celicas forums were hacked. I got several phone calls (thanks guys) letting me know while I was in the middle of my brake upgrade. I confirmed the site had been hacked, and killed the web services running on the server to prevent any more damage. I then waited for my parents to get home, took their car, came up to my apartment where I have fast and reliable internet access, and fixed the problems.
I don't know who did it, where they did it from, why they did it, or exactly how they did it. I do know that just before the hacker got in, a password recovery request email was sent to me that I did not request. Somehow, a malicious user could get the necessary code to complete the password recovery section, allowing that user to set a new password. In this case, they changed my password, and took the board offline, with a inappropriate message that redirected to a site after a few seconds. With the help of Invision Power Services, the forum software manufacturer, I got the problem fixed, applied my own security updates, and upgraded the board software to the latest version, which includes critical security updates. This was the first time that 6G Celicas was hacked, and should be the last. With administrative access, it appears that the only thing the malicious user did was take the board offline. There's no evidence of the user accessing the administrative control panel, or doing any other malicious work to the board. I know some of you were worried that your password might have been seen by the attacker, but it's impossible for anyone to view any user's password, because they are one-way encrypted using advanced and secure algorithms. The bottom line is that this shouldn't happen again. I'll keep better tabs on applying those security updates, and in the event that something catastrophic were to happen, I do keep frequent database and full filesystem backups. Should you notice anything different, suspicious, any errors, etc., PLEASE let me know immediately. I really appreciated everyone's help and concern today, and I'm sorry to the people I was blunt with on AIM, but we made it through this and shouldn't have to go through it again. Regards, Christian Coomer -------------------- New Toyota project coming soon...
|
Aug 28, 2006 - 9:50 AM |
|
Enthusiast Joined Jun 13, '05 From Poughkeepsie, NY Currently Offline Reputation: 2 (100%) |
QUOTE(Bitter @ Aug 28, 2006 - 10:49 AM) [snapback]473661[/snapback] QUOTE(devilsden97 @ Aug 28, 2006 - 9:18 AM) [snapback]473646[/snapback] Glad to see that nothing else was tampered with except the redirection and nasty message. How did everyone handle, not having 6gc.net in there life for a few hours????? I know Derrick (maskedman), was Iming me, freaking out cuz he was SOOO bored lol. Anyone have any bored stories? i had them taken down for an hour in response huh? -------------------- Kawi Love |
Aug 28, 2006 - 10:01 AM |
|
Enthusiast Joined Mar 11, '06 From Way South Chicago Currently Offline Reputation: 0 (0%) |
QUOTE(devilsden97 @ Aug 28, 2006 - 9:50 AM) [snapback]473662[/snapback] QUOTE(Bitter @ Aug 28, 2006 - 10:49 AM) [snapback]473661[/snapback] QUOTE(devilsden97 @ Aug 28, 2006 - 9:18 AM) [snapback]473646[/snapback] Glad to see that nothing else was tampered with except the redirection and nasty message. How did everyone handle, not having 6gc.net in there life for a few hours????? I know Derrick (maskedman), was Iming me, freaking out cuz he was SOOO bored lol. Anyone have any bored stories? i had them taken down for an hour in response huh? i called the interweb police on them if anyone went to the site and was redirected to a page not found or dns lookup problem last night, that would have been indirectly my doings. -------------------- |
Lo-Fi Version | Time is now: November 29th, 2024 - 3:30 AM |