6G Celicas Forums

Welcome Guest ( Log In | Register )

> About 6G Celicas Being Hacked
post Aug 28, 2006 - 1:13 AM
+Quote Post
Coomer



Administrator
*****
Joined Aug 23, '02
From Seattle, WA
Currently Offline

Reputation: 14 (100%)




Today, around 3:13PM PST, the 6G Celicas forums were hacked. I got several phone calls (thanks guys) letting me know while I was in the middle of my brake upgrade. I confirmed the site had been hacked, and killed the web services running on the server to prevent any more damage. I then waited for my parents to get home, took their car, came up to my apartment where I have fast and reliable internet access, and fixed the problems.

I don't know who did it, where they did it from, why they did it, or exactly how they did it.

I do know that just before the hacker got in, a password recovery request email was sent to me that I did not request. Somehow, a malicious user could get the necessary code to complete the password recovery section, allowing that user to set a new password. In this case, they changed my password, and took the board offline, with a inappropriate message that redirected to a site after a few seconds.

With the help of Invision Power Services, the forum software manufacturer, I got the problem fixed, applied my own security updates, and upgraded the board software to the latest version, which includes critical security updates. This was the first time that 6G Celicas was hacked, and should be the last.

With administrative access, it appears that the only thing the malicious user did was take the board offline. There's no evidence of the user accessing the administrative control panel, or doing any other malicious work to the board.

I know some of you were worried that your password might have been seen by the attacker, but it's impossible for anyone to view any user's password, because they are one-way encrypted using advanced and secure algorithms.

The bottom line is that this shouldn't happen again. I'll keep better tabs on applying those security updates, and in the event that something catastrophic were to happen, I do keep frequent database and full filesystem backups.

Should you notice anything different, suspicious, any errors, etc., PLEASE let me know immediately. I really appreciated everyone's help and concern today, and I'm sorry to the people I was blunt with on AIM, but we made it through this and shouldn't have to go through it again. smile.gif

Regards,
Christian Coomer


--------------------
New Toyota project coming soon...
 
Start new topic
Replies
post Aug 28, 2006 - 1:08 PM
+Quote Post
lagos



Enthusiast
*****
Joined Aug 31, '02
From Philadelphia, PA
Currently Offline

Reputation: 8 (100%)




QUOTE(JoKeRkId613 @ Aug 28, 2006 - 11:57 AM) [snapback]473697[/snapback]

yeah, the message said something along the lines of "g00ns.net F*cking owns you!" and under it, they had their mIRC server info.

server: irc.g00ns.net
channel: #g00ns

I went into their chat after I saw the message and saw the user LaD in there talking smack about our forums. I knew it was just some noob password request "hack". Those guys had to be hacker-wannabes. The guy was like "yea, give me 5 dollars and I'll bring the forum back up". I just mentioned that all of the users go on a secondary board as well just so that he stopped feeling so special.

Thanks for bringing the forum back up... I hate myspace!



go back to that irc chat. look up the ip for this LaD kid, and give it to coomer. then coomer can give it to his isp, and they can block it or contract the cops on this kid.


--------------------
15PSI - 30MPG - Megasquirt Tuned

Posts in this topic
- Coomer   About 6G Celicas Being Hacked   Aug 28, 2006 - 1:13 AM
- - gwai1o   QUOTE(Coomer @ Aug 28, 2006 - 1:13 A...   Aug 28, 2006 - 1:22 AM
|- - Coomer   QUOTE(gwai1o @ Aug 27, 2006 - 11:22 ...   Aug 28, 2006 - 1:28 AM
- - BlackCelicaGT94   Thanks coomer for being on top of this! youre ...   Aug 28, 2006 - 1:23 AM
- - rayneezy23   yea so like that was the reason why i couldn't...   Aug 28, 2006 - 1:34 AM
- - zipstrips   coomer, thank you for taking care of 6gc!   Aug 28, 2006 - 1:36 AM
- - madmods   Man, i directed to a porn site. I was like damm Co...   Aug 28, 2006 - 1:43 AM
|- - Jen   QUOTE(madmods @ Aug 28, 2006 - 2:43 ...   Aug 28, 2006 - 2:09 AM
- - MaskedMan   thanks Coomer for getting the site back up so quic...   Aug 28, 2006 - 1:45 AM
- - pure_dx   0h snpz! ub98r l89t h0x0r FTL!!   Aug 28, 2006 - 2:08 AM
- - Blakout16   i however was redirected to another site right whe...   Aug 28, 2006 - 2:10 AM
- - Blakout16   nvm, it was in another part of another topic.... g...   Aug 28, 2006 - 2:14 AM
- - XS4lv1Truch0x   nice save. must be them civic people LMAO! h...   Aug 28, 2006 - 3:10 AM
- - WannabeGT4   It was probably some form of SQL injection that ca...   Aug 28, 2006 - 7:51 AM
- - mzztoyota   Oh man, this is too funny. When I tried to get ont...   Aug 28, 2006 - 8:08 AM
- - devilsden97   Glad to see that nothing else was tampered with ex...   Aug 28, 2006 - 9:18 AM
|- - Bitter   QUOTE(devilsden97 @ Aug 28, 2006 - 9...   Aug 28, 2006 - 9:49 AM
- - devilsden97   QUOTE(Bitter @ Aug 28, 2006 - 10:49 ...   Aug 28, 2006 - 9:50 AM
|- - Bitter   QUOTE(devilsden97 @ Aug 28, 2006 - 9...   Aug 28, 2006 - 10:01 AM
- - CelicaZR   Coomer to the rescue Keep up the good work mate...   Aug 28, 2006 - 10:12 AM
- - m0dd3d1   Good lookin' out! Don't know what i...   Aug 28, 2006 - 10:23 AM
- - hitcachi   I glad that i was at work while this whole thing w...   Aug 28, 2006 - 10:23 AM
- - LewFX   i bugged dan and dustin, then went surfing online.   Aug 28, 2006 - 10:26 AM
- - mzztoyota   I was so bored that I wound up subjecting myself t...   Aug 28, 2006 - 10:26 AM
- - DomGT   I guess I should feel lucky that I'm obsessed ...   Aug 28, 2006 - 10:55 AM
|- - DomGT   QUOTE(DomGT @ Aug 28, 2006 - 11:55 A...   Sep 1, 2006 - 11:47 PM
- - JoKeRkId613   yeah, the message said something along the lines o...   Aug 28, 2006 - 10:57 AM
- - Jaws4God   Great work Coomer! I was so scared that we...   Aug 28, 2006 - 11:23 AM
- - tomazws   Wow... it's very nice for you to get this back...   Aug 28, 2006 - 11:56 AM
- - coldbluesteel   I went into shock when it happed. I was online whe...   Aug 28, 2006 - 12:51 PM
- - lagos   QUOTE(JoKeRkId613 @ Aug 28, 2006 - 11...   Aug 28, 2006 - 1:08 PM
|- - laff09   QUOTE(lagos @ Aug 28, 2006 - 1:08 PM...   Aug 28, 2006 - 9:57 PM
- - BBoYRuGGeD   wow...all that happened while i was at work..? and...   Aug 28, 2006 - 1:20 PM
- - bloodrain   QUOTE(rayneezy23 @ Aug 28, 2006 - 2...   Aug 28, 2006 - 1:23 PM
- - easternpiro1   i wonder if it was that guy that i got into a figh...   Aug 28, 2006 - 2:54 PM
- - XS4lv1Truch0x   lmao! thats noobish lol, hacking thru exploit...   Aug 28, 2006 - 3:54 PM
- - slvr_celica_GT_816   yea i dont see why people waste there time doing s...   Aug 28, 2006 - 10:31 PM
- - CheesyLobster   i bet it was those gosh darn honda hooligans!   Sep 1, 2006 - 5:00 PM


Reply to this topicStart new topic
5 User(s) are reading this topic (5 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: November 29th, 2024 - 3:30 AM