Outpost Universe Forums

Community => News => Topic started by: xfir on January 10, 2004, 07:17:36 PM

Title: Recent Event
Post by: xfir on January 10, 2004, 07:17:36 PM
We were hacked.

Now, don't let this alarm you. No damage was done.

The problem has been resolved.

As a note though, the shoutbox will stay offline until I can get it more secure (and make sure it isn't on EVERY page)
Title: Recent Event
Post by: Zircon on January 10, 2004, 07:25:59 PM
Thread is gone... And so is my finely crafted message... *sob*

Well, No matter  :) We're secure again  ^_^  :P
Title: Recent Event
Post by: BlackBox on January 10, 2004, 07:31:59 PM
Who/what was responsible for it?

And how did they do it? (I'd be willing to help "patch" the shoutbox.... I'm guessing they injected SQL thru it..?)

edit: You should use a regular expression to remove stuff that starts with ibf_ from the shoutbox, preventing the database from being touched.
Title: Recent Event
Post by: xfir on January 10, 2004, 07:33:27 PM
No... Zircon explained it, but at length.

Basically, this version is now a "pure" Invision 1.3 Final..  
Title: Recent Event
Post by: plymoth45 on January 10, 2004, 10:34:45 PM
YAY, now y was my skin different from wht i had it at? I just barely had to change it back. Could it of had something to do with this hack?
Title: Recent Event
Post by: xfir on January 10, 2004, 11:51:33 PM
Actually, I deleted all the old skins and reuploaded everything.

That is the reason for the switch back to the default skin.
Title: Recent Event
Post by: BlackBox on January 11, 2004, 10:40:45 AM
Xfir: The skin sets are still stored in the database.. Should I go in and delete them out?

Also, make sure you re-CHMOD'ed the uploads/ and html/emoticons/ folders to 777.
Title: Recent Event
Post by: xfir on January 11, 2004, 01:20:18 PM
Quote
Xfir: The skin sets are still stored in the database.. Should I go in and delete them out?

Also, make sure you re-CHMOD'ed the uploads/ and html/emoticons/ folders to 777.
That's all done already. I took care of everything.
Title: Recent Event
Post by: SilentoBoborachi on January 11, 2004, 04:17:29 PM
I liked the shout box, it's the first time i've seen one on a forum
Title: Recent Event
Post by: CK9 on January 11, 2004, 07:03:43 PM
I hate it when people do stupid things like that.  Hacking is okay the way it is being used in our case, because we just want to try to keep this game alive.  When you hack a forum or a site, that's just wrong.
Title: Recent Event
Post by: Luweeg64 on January 12, 2004, 07:08:37 AM
NOooooo THE SHOUTBOX!!!!! sob.... :'(  :'( ......
Title: Recent Event
Post by: Leviathan on January 12, 2004, 08:38:07 AM
well now theres no shoutbox people should come on irc and chat there.
Title: Recent Event
Post by: plymoth45 on January 12, 2004, 09:42:31 AM
With out the shoutbox, luweeg is powerless lol.
Title: Recent Event
Post by: Oprime on January 12, 2004, 06:45:40 PM
:'(  I feel sad cause nobody was in IRC when I needed my OP2 fix*....Not even Leviathan.  Don't cry Luqeeg we all loved the shoutbox :'( .  Will it ever come back......
Title: Recent Event
Post by: xfir on January 12, 2004, 06:47:00 PM
Quote
:'(  I feel sad cause nobody was in IRC when I needed my OP2 fix*....Not even Leviathan.  Don't cry Luqeeg we all loved the shoutbox :'( .  Will it ever come back......
Yes it will come back.. but I want to redo some portions of it.
Title: Recent Event
Post by: BlackBox on January 12, 2004, 08:07:14 PM
Yeah, all you gotta do is stop SQL injection.....

(What you could do, is use eregi() or something to remove words like UPDATE, DELETE, INSERT, DROP, CREATE, etc.

Btw I consider OP2 "hacking" more "cracking" and "reversing" than hacking... Those words define it better.
Title: Recent Event
Post by: plymoth45 on January 12, 2004, 09:42:17 PM
so change ur name to racking lol.
Title: Recent Event
Post by: Luweeg64 on January 13, 2004, 07:22:29 AM
i'm beginning to think lev makes money off us visiting the shoutbox :lol:
 
Title: Recent Event
Post by: plymoth45 on January 13, 2004, 09:23:07 AM
you mean IRC? or the shoutbox?
Title: Recent Event
Post by: BlackBox on January 13, 2004, 04:59:14 PM
Quote
the shoutbox
Um, yeah the shoutbox.

And this topic is going (OT).
Title: Recent Event
Post by: Oprime on January 13, 2004, 06:20:04 PM
Xfir how long to you think it would take to bring the shoutbox back?
Title: Recent Event
Post by: xfir on January 13, 2004, 06:36:46 PM
Quote
Xfir how long to you think it would take to bring the shoutbox back?
I may take the board offline tonight to make the modifications.
Title: Recent Event
Post by: plymoth45 on January 13, 2004, 07:02:49 PM
k, as long as it is back up and running tommorrow.
Title: Recent Event
Post by: xfir on January 13, 2004, 08:08:16 PM
As you can see, the shoutbox is back.. there currently isn't a fader though.. I don't plan on adding one..

Also, I plan to take the forum down again on Sunday for another modification.
Title: Recent Event
Post by: Luweeg64 on January 15, 2004, 10:10:07 AM
yay shoutbox is back
Title: Recent Event
Post by: Oprime on January 17, 2004, 08:01:30 PM
I like using the smilies in the shoutbox. Xfir are you gonna be adding that back in?
Title: Recent Event
Post by: BlackBox on January 17, 2004, 08:02:48 PM
smilies work in the shoutbox.
Title: Recent Event
Post by: Oprime on January 17, 2004, 08:15:42 PM
How do get the smilies in the shoutbox. Do you have to enter something like 8) <--- this to get it to work?
Title: Recent Event
Post by: xfir on January 18, 2004, 09:20:45 AM
Quote
How do get the smilies in the shoutbox. Do you have to enter something like 8) <--- this to get it to work?
Well.. you could try clicking the link above the box where you enter your shout. :whistle:
Title: Recent Event
Post by: CK9 on January 18, 2004, 05:32:18 PM
x, are you 100% sure that the new shoutbox is hack resistant?  (no such thing as 100% hack proof)
Title: Recent Event
Post by: plymoth45 on January 18, 2004, 07:45:40 PM
um, hack resistant? i don't think there is a 100% hack resistant. There is a class at my school that quit trying to put that sort of security on the comps cause hackers get around it.
Title: Recent Event
Post by: xfir on January 19, 2004, 10:42:10 AM
Technically, there is no way to execute PHP or MySQL commands through the shoutbox or through the forum (at least to my knowledge, but I know there isn't through the shoutbox)
Title: Recent Event
Post by: plymoth45 on January 19, 2004, 02:28:00 PM
well, only way i can c the forum really being hacked, is if someone knows xfir's codes.
Title: Recent Event
Post by: [op]5uk on January 19, 2004, 05:36:58 PM
Who is responsible for this outrageous event?!
Title: Recent Event
Post by: BlackBox on January 19, 2004, 06:00:50 PM
www.icehack.com, I think.

And yes I'm sure there are ways in the forum that hacking could be done.
Title: Recent Event
Post by: Betaray on January 19, 2004, 06:02:36 PM
why would somone want to hack the forum anyway?
Title: Recent Event
Post by: plymoth45 on January 19, 2004, 06:36:39 PM
watch, beta is going to answer that question on the next page
Title: Recent Event
Post by: xfir on January 19, 2004, 07:10:45 PM
Why do they want to hack a forum?

Interesting question.. most of the time they do it to prove that they can do it.
Title: Recent Event
Post by: plymoth45 on January 19, 2004, 07:40:53 PM
dang, beta was supposed to say that lol, but i agree
Title: Recent Event
Post by: Betaray on January 19, 2004, 07:54:34 PM
so they hack a forum

whoop de do, not somthing you can brag to your friends about

now if you hacked into the control center for icbm's and launched one at china, then people would be impressed, right before you get shot for starting WW3
Title: Recent Event
Post by: xfir on January 19, 2004, 09:29:53 PM
Well, technically, hacking forum software is a lot harder than it sounds.. and it proves that nothing is invunerable.
Title: Recent Event
Post by: [op]5uk on January 22, 2004, 07:44:54 AM
Quote
why would somone want to hack the forum anyway?
I believe it's revenge.
Title: Recent Event
Post by: CK9 on January 22, 2004, 08:41:57 AM
I don't think so, the only people who would want revenge on use are Kiler and Xkr, both of whom I do notthink have the experience let alone the meterials needed to do it.  I think it was someone trying out their new hacking abilities.
Title: Recent Event
Post by: Zircon on January 22, 2004, 10:02:33 AM
All he did was leave a little message (in x-firs name), someone evilminded knowing of that exploit could have easily screwed up the entire forum...
(im just comparing the different outcomes, one message compared to a wiped user database for example)

He "informed" us of our lacking security which i think was pretty good actually so that we could prevent any possible evil minded persons ^ ...

And it's not like he "hacked" the forum, He used an already known exploit...
A real hack is when you figure out an exploit no one else knows about...
(atleast that's my opinion)
Title: Recent Event
Post by: plymoth45 on January 22, 2004, 12:44:12 PM
i wouldn't know, i don't know how to hack, so, my opinion, anything that gets around security that isn't a virus, worm, or ect, is a hack.
Title: Recent Event
Post by: CK9 on January 22, 2004, 02:40:27 PM
All I know how to do is a backround search using only email and ip.
Title: Recent Event
Post by: xfir on January 22, 2004, 06:38:08 PM
Quote
i wouldn't know, i don't know how to hack, so, my opinion, anything that gets around security that isn't a virus, worm, or ect, is a hack.
So is breaking a cipher considered a hack?

Quote
All he did was leave a little message (in x-firs name), someone evilminded knowing of that exploit could have easily screwed up the entire forum...
(im just comparing the different outcomes, one message compared to a wiped user database for example)

He "informed" us of our lacking security which i think was pretty good actually so that we could prevent any possible evil minded persons ^ ...

And it's not like he "hacked" the forum, He used an already known exploit...
A real hack is when you figure out an exploit no one else knows about...
(atleast that's my opinion)
Yes, this is good that he didn't do any major damage.
Title: Recent Event
Post by: plymoth45 on January 22, 2004, 08:33:51 PM
well, i meant web based stuff, enlighten me if ciphers are web based.
Title: Recent Event
Post by: xfir on January 22, 2004, 08:36:28 PM
Technically, http://www.xfir.net/xfir/itsasecret.php (http://www.xfir.net/xfir/itsasecret.php) is a web-based cipher.

So, in effect, ciphers can be web-based. But I can understand your idea.. I think you instead intended Internet Security.
Title: Recent Event
Post by: Betaray on January 22, 2004, 08:40:48 PM
just wondering, I remember when op2hacker decrypted our cyphers that we were having fun with, I was just wondering how he did that lol

it probly has abunch of computer junk that only he and fellow hackers know how to read lol