About 6G Celicas Being Hacked |
About 6G Celicas Being Hacked |
Aug 28, 2006 - 1:13 AM |
|
Administrator Joined Aug 23, '02 From Seattle, WA Currently Offline Reputation: 14 (100%) |
Today, around 3:13PM PST, the 6G Celicas forums were hacked. I got several phone calls (thanks guys) letting me know while I was in the middle of my brake upgrade. I confirmed the site had been hacked, and killed the web services running on the server to prevent any more damage. I then waited for my parents to get home, took their car, came up to my apartment where I have fast and reliable internet access, and fixed the problems.
I don't know who did it, where they did it from, why they did it, or exactly how they did it. I do know that just before the hacker got in, a password recovery request email was sent to me that I did not request. Somehow, a malicious user could get the necessary code to complete the password recovery section, allowing that user to set a new password. In this case, they changed my password, and took the board offline, with a inappropriate message that redirected to a site after a few seconds. With the help of Invision Power Services, the forum software manufacturer, I got the problem fixed, applied my own security updates, and upgraded the board software to the latest version, which includes critical security updates. This was the first time that 6G Celicas was hacked, and should be the last. With administrative access, it appears that the only thing the malicious user did was take the board offline. There's no evidence of the user accessing the administrative control panel, or doing any other malicious work to the board. I know some of you were worried that your password might have been seen by the attacker, but it's impossible for anyone to view any user's password, because they are one-way encrypted using advanced and secure algorithms. The bottom line is that this shouldn't happen again. I'll keep better tabs on applying those security updates, and in the event that something catastrophic were to happen, I do keep frequent database and full filesystem backups. Should you notice anything different, suspicious, any errors, etc., PLEASE let me know immediately. I really appreciated everyone's help and concern today, and I'm sorry to the people I was blunt with on AIM, but we made it through this and shouldn't have to go through it again. Regards, Christian Coomer -------------------- New Toyota project coming soon...
|
Aug 28, 2006 - 1:22 AM |
|
Enthusiast Joined Aug 26, '06 From Arlington, WA Currently Offline Reputation: 0 (0%) |
QUOTE(Coomer @ Aug 28, 2006 - 1:13 AM) [snapback]473544[/snapback] Today, around 3:13PM PST, the 6G Celicas forums were hacked. I got several phone calls (thanks guys) letting me know while I was in the middle of my brake upgrade. I confirmed the site had been hacked, and killed the web services running on the server to prevent any more damage. I then waited for my parents to get home, took their car, came up to my apartment where I have fast and reliable internet access, and fixed the problems. I don't know who did it, where they did it from, why they did it, or exactly how they did it. I do know that just before the hacker got in, a password recovery request email was sent to me that I did not request. Somehow, a malicious user could get the necessary code to complete the password recovery section, allowing that user to set a new password. In this case, they changed my password, and took the board offline, with a inappropriate message that redirected to a site after a few seconds. With the help of Invision Power Services, the forum software manufacturer, I got the problem fixed, applied my own security updates, and upgraded the board software to the latest version, which includes critical security updates. This was the first time that 6G Celicas was hacked, and should be the last. With administrative access, it appears that the only thing the malicious user did was take the board offline. There's no evidence of the user accessing the administrative control panel, or doing any other malicious work to the board. I know some of you were worried that your password might have been seen by the attacker, but it's impossible for anyone to view any user's password, because they are one-way encrypted using advanced and secure algorithms. The bottom line is that this shouldn't happen again. I'll keep better tabs on applying those security updates, and in the event that something catastrophic were to happen, I do keep frequent database and full filesystem backups. Should you notice anything different, suspicious, any errors, etc., PLEASE let me know immediately. I really appreciated everyone's help and concern today, and I'm sorry to the people I was blunt with on AIM, but we made it through this and shouldn't have to go through it again. Regards, Christian Coomer Yeah, I was @ work, surfing the forum when it happened. It didn't send a virus out or anything did it? would be bad since all of our company computers run off the same network... lol i was greeted to the word "F**K" and some other words as I tried to reply to a post and my boss was sitting right next to me (she didn't see). I have to commend you and all those who tipped you on the issue for such a speedy recovery of the forums. Thanks Christian. Justin- -------------------- '95 Supra turbo 361whp/350tq~ |
Aug 28, 2006 - 1:23 AM |
|
Enthusiast Joined Mar 4, '03 From Kirkland, Washington Currently Offline Reputation: 0 (0%) |
Thanks coomer for being on top of this! youre welcome for the call ;-) and getting the message out via bulletins on myspace!
keep up the good work on the site! I know we all appreciate the effort you put into it -------------------- Cruisin down the street in my Infiniti...always lookin for my next trip to Sin City
|
Aug 28, 2006 - 1:28 AM |
|
Administrator Joined Aug 23, '02 From Seattle, WA Currently Offline Reputation: 14 (100%) |
QUOTE(gwai1o @ Aug 27, 2006 - 11:22 PM) [snapback]473550[/snapback] Yeah, I was @ work, surfing the forum when it happened. It didn't send a virus out or anything did it? would be bad since all of our company computers run off the same network... lol i was greeted to the word "F**K" and some other words as I tried to reply to a post and my boss was sitting right next to me (she didn't see). I have to commend you and all those who tipped you on the issue for such a speedy recovery of the forums. Thanks Christian. Justin- Nope, it shouldn't have sent out viruses or anything like that. And you're welcome...glad I could get it back online in decent time. -------------------- New Toyota project coming soon...
|
Aug 28, 2006 - 1:34 AM |
|
Enthusiast Joined Jun 25, '06 From Bremerton, Washington Currently Offline Reputation: 1 (100%) |
yea so like that was the reason why i couldn't get on 6gc damn hackers first i thought my computer was f'd up, but anyways thanks coomer
|
Aug 28, 2006 - 1:36 AM |
|
Enthusiast Joined Sep 9, '02 From Scranton, Pa Currently Offline Reputation: 7 (100%) |
coomer, thank you for taking care of 6gc!
|
Aug 28, 2006 - 1:43 AM |
|
Enthusiast Joined Mar 19, '04 From Scottsdale, Az Currently Offline Reputation: 2 (100%) |
Man, i directed to a porn site. I was like damm Coomer. I looked around for a few hours.
|
Aug 28, 2006 - 1:45 AM |
|
Enthusiast Joined Jun 29, '03 From 캘리포니아 Currently Offline Reputation: 23 (100%) |
thanks Coomer for getting the site back up so quickly , i felt like i was lost without it
-------------------- |
Aug 28, 2006 - 2:08 AM |
|
Enthusiast Joined Dec 28, '05 From USA Currently Offline Reputation: 0 (0%) |
0h snpz! ub98r l89t h0x0r FTL!!
|
Aug 28, 2006 - 2:09 AM |
|
Enthusiast Joined Jul 14, '03 From Jacksonville, FL Currently Offline Reputation: 2 (100%) |
QUOTE(madmods @ Aug 28, 2006 - 2:43 AM) [snapback]473563[/snapback] Man, i directed to a porn site. I was like damm Coomer. I looked around for a few hours. LMAO. Yeah, but thanks boo. I was 6GC deprived. -------------------- |
Aug 28, 2006 - 2:10 AM |
|
Enthusiast Joined Jul 3, '04 From Yakima, WA Currently Offline Reputation: 1 (100%) |
i however was redirected to another site right when they did so, just my luck. im racking my brain for the site name because it was an obvious hackers forum where they go about their duties. its not in my history (already checked) time to use some googling
-------------------- the 1/4 doesnt have patience for a ST.... so we make them ST-T's so atleast we'll sound good going slow.
|
Aug 28, 2006 - 2:14 AM |
|
Enthusiast Joined Jul 3, '04 From Yakima, WA Currently Offline Reputation: 1 (100%) |
nvm, it was in another part of another topic.... goons.net ill look into it ^.^ im majoring in computer networking, so i should help out.
+ okay. it was from http://www.g00ns.net and i've found a user named Lad. pretty active member of the forums, and not to mention i've checked all of the sites this specfic forum has defaced and pretty much owned. we're just one in a million. This post has been edited by Blakout16: Aug 28, 2006 - 2:39 AM -------------------- the 1/4 doesnt have patience for a ST.... so we make them ST-T's so atleast we'll sound good going slow.
|
Aug 28, 2006 - 3:10 AM |
|
Enthusiast Joined Dec 9, '05 From Long Beach Currently Offline Reputation: 1 (100%) |
nice save.
must be them civic people LMAO! hehe but yeah. keep up the good work! -------------------- Is this good enuff 4 ya? :D
|
Aug 28, 2006 - 7:51 AM |
|
Enthusiast Joined Oct 10, '03 From Wichita, KS Currently Offline Reputation: 5 (100%) |
It was probably some form of SQL injection that caused your password to be sent to their email adress. You can try and change some of the table names in your DB to nonstandard names to make it more difficult for hackers to figure out. Also make sure that none of your table names are listed in any errors generated.
-------------------- Project ST204.5 99.88946% complete... |
Aug 28, 2006 - 8:08 AM |
|
Enthusiast Joined Jul 20, '06 From St. Thomas, Virgin Islands Currently Offline Reputation: 0 (0%) |
Oh man, this is too funny. When I tried to get onto the forums yesterday, they were down...and I was like "hmm, that's strange." So I went to my second-favorite site (a literature thing...I'm an English major, remember?) and IT was down too! I thought "no way, my internet must be screwing up, did I pay my bill this month?"
Turns out that the literature site was updating was updating some software or something at the same time 6gc went down, lol. Great job Coomer, 6gc prevails!!! Mwahahaha... -------------------- "I bet you drive a standard." "You could make some money off that bet." :D |
Aug 28, 2006 - 9:18 AM |
|
Enthusiast Joined Jun 13, '05 From Poughkeepsie, NY Currently Offline Reputation: 2 (100%) |
Glad to see that nothing else was tampered with except the redirection and nasty message.
How did everyone handle, not having 6gc.net in there life for a few hours????? I know Derrick (maskedman), was Iming me, freaking out cuz he was SOOO bored lol. Anyone have any bored stories? -------------------- Kawi Love |
Aug 28, 2006 - 9:49 AM |
|
Enthusiast Joined Mar 11, '06 From Way South Chicago Currently Offline Reputation: 0 (0%) |
QUOTE(devilsden97 @ Aug 28, 2006 - 9:18 AM) [snapback]473646[/snapback] Glad to see that nothing else was tampered with except the redirection and nasty message. How did everyone handle, not having 6gc.net in there life for a few hours????? I know Derrick (maskedman), was Iming me, freaking out cuz he was SOOO bored lol. Anyone have any bored stories? i had them taken down for an hour in response -------------------- |
Aug 28, 2006 - 9:50 AM |
|
Enthusiast Joined Jun 13, '05 From Poughkeepsie, NY Currently Offline Reputation: 2 (100%) |
QUOTE(Bitter @ Aug 28, 2006 - 10:49 AM) [snapback]473661[/snapback] QUOTE(devilsden97 @ Aug 28, 2006 - 9:18 AM) [snapback]473646[/snapback] Glad to see that nothing else was tampered with except the redirection and nasty message. How did everyone handle, not having 6gc.net in there life for a few hours????? I know Derrick (maskedman), was Iming me, freaking out cuz he was SOOO bored lol. Anyone have any bored stories? i had them taken down for an hour in response huh? -------------------- Kawi Love |
Aug 28, 2006 - 10:01 AM |
|
Enthusiast Joined Mar 11, '06 From Way South Chicago Currently Offline Reputation: 0 (0%) |
QUOTE(devilsden97 @ Aug 28, 2006 - 9:50 AM) [snapback]473662[/snapback] QUOTE(Bitter @ Aug 28, 2006 - 10:49 AM) [snapback]473661[/snapback] QUOTE(devilsden97 @ Aug 28, 2006 - 9:18 AM) [snapback]473646[/snapback] Glad to see that nothing else was tampered with except the redirection and nasty message. How did everyone handle, not having 6gc.net in there life for a few hours????? I know Derrick (maskedman), was Iming me, freaking out cuz he was SOOO bored lol. Anyone have any bored stories? i had them taken down for an hour in response huh? i called the interweb police on them if anyone went to the site and was redirected to a page not found or dns lookup problem last night, that would have been indirectly my doings. -------------------- |
Aug 28, 2006 - 10:12 AM |
|
Enthusiast Joined Mar 25, '05 From Sydney, Australia Currently Offline Reputation: 0 (0%) |
Coomer to the rescue
Keep up the good work mate and yes I did feel lost without it. -------------------- 98 ST204 ZR - Black Beauty - Roaming the streets of Sydney 73 TA22 LT - Tiffany Blue - Mint Classic Weekend Cruiser 75 TA22 LT - Snow White - Mint Classic Weekend Cruiser 77 RA28 LT - Flubber Green - Mint Classic Weekend Cruiser 94 MX-5 NA8 Clubman - Red Racer - Looking for corners WIP Project: 69 RT40 Corona, 2nd WIP Project: 66 RT40 1600s Corona 86 Corona RT142 - Daily Driver 6GC 4 Life Baby!!! |
Lo-Fi Version | Time is now: November 28th, 2024 - 10:30 PM |