Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Snitz Exchange Hacked...
 New Topic  Topic Locked
 Printer Friendly
Next Page
Author Previous Topic Topic Next Topic
Page: of 2

crash
Advanced Member

Netherlands
2064 Posts

Posted - 07 May 2002 :  18:45:33  Show Profile  Visit crash's Homepage
isn't there a way to combine our forces and strike back?

do we really sit back and wait to see all our sites get hacked by this or these losers?

i mean, they don't even really hack, they only add a different background image or empty the DB...

still though, i'm getting quite sick of this so called hacking group!

who's with me?



Crash's Site | Crash is from

Davio
Development Team Member

Jamaica
12217 Posts

Posted - 07 May 2002 :  19:00:01  Show Profile
Can you post the exact error you are getting?

This should be moved to Community forums.

And I advise you not to take things into your hands crash. Users just have to be more careful in the near future when they find security related bugs in the forum. And not publicize it.

«------------------------------------------------------»
Want to know when the next version comes out,
as soon as possible? Join our Mailing Lists !
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 07 May 2002 :  19:05:21  Show Profile  Visit crash's Homepage
look for yourself: http://www.ls3k.com/snitz/default.asp

here's a pic of what i saw (pic has been cut to save space)





Crash's Site | Crash is from
Go to Top of Page

kookis
Starting Member

28 Posts

Posted - 07 May 2002 :  19:16:01  Show Profile
bummer...sorry to see that...I guess they get off on it. Hacking amazes me. Where these people learn these skills is beyond me. I guess it's not hard if you have the right teacher and you know programming. It's gotta take alot of time. Seems like an awful lot of trouble to go to just to mess up the internet which should be here for everyones enjoyment(in a possitive manner). It's a power high i guess... but come on really...power is taking down an ISP or busting through a very secure system with a good firewall.

Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 07 May 2002 :  19:20:03  Show Profile  Visit crash's Homepage
wel... they didn't exactly hack... they just guessed the DB path and downloaded it. they took a quick peek in the DB and logged on as Admin. then they changed some stuff to make it look like the site was hacked. easy does it.

these blokes aren't real hackers! they're just a big fuc*ing pain in the a*s!



Crash's Site | Crash is from
Go to Top of Page

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 07 May 2002 :  19:24:53  Show Profile  Visit Gremlin's Homepage
Doh, Nathan got hit too

www.daoc-halo.com
Go to Top of Page

nutella
Starting Member

19 Posts

Posted - 07 May 2002 :  19:26:40  Show Profile
Hi other hack victims:
the guy who hacked my forum, a mom-type forum for heavans sakes, replaced my admin e-mail with his hacker e-mail. Talk about Bold!
I was tempted to send an e-mail to this little punk, and most of these hackers are pre-adolescent kids (punks in less friendly terms), heck, they are about the same age as my kids!
but, my kids aren't out there hacking to relieve some kind of frustration: they are making fantastic flash films and websites of their own. They are also too busy doing sports like snowboarding and mountain biking to be using a computer as a means of releasing energy.
Should I write a letter to this kid? I know he's a kid, and, I suspect he's messed up big time.
Is it a waste of my time?
nutella

Go to Top of Page

nomad_2k
Junior Member

United Kingdom
173 Posts

Posted - 07 May 2002 :  19:27:35  Show Profile
Where's the exchange gone? All the pages except default.asp and mods.asp have disappeared.


Good things come to those who wait.
http://www.freeasphost.co.uk/evolution/
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 07 May 2002 :  19:33:09  Show Profile  Visit crash's Homepage
there is nothing we can do about it, only the security fixes should not be made available so easily, or at least, not the leaks. the fixes should only be posted. maybe we need to set up a mail system of some kind which tells what leaks have been closed.

on the other hand, if a hacker registered here, he/she would get the same info as we do...



Crash's Site | Crash is from
Go to Top of Page

Aaron S.
Average Member

USA
985 Posts

Posted - 07 May 2002 :  19:39:37  Show Profile  Visit Aaron S.'s Homepage
If he guessed the DB location and downloaded it... then that was Nathan fault (sorry Nathan) not Snitz (and any security problem).

It says clearly to put the DB in a non-accessible place or name it some funky name so it can't be guessed.

--Aaron

DOWNLOAD GREAT NEW MODS HERE
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 07 May 2002 :  19:45:28  Show Profile  Send ruirib a Yahoo! Message
I would say Nathan's situation looks different. That's not a normal Admin takeover hack. They really got into his server, changing the asp files, etc. They couldn't do that with the admin password only...

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 07 May 2002 :  19:50:02  Show Profile  Visit crash's Homepage
they most certainly could! and they weren't on his server. the page only has a different background image. the text still is the same...



Crash's Site | Crash is from
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 07 May 2002 :  19:56:14  Show Profile  Send ruirib a Yahoo! Message
It really didn't look like that to me, although I admit that is possible...

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
Go to Top of Page

kookis
Starting Member

28 Posts

Posted - 07 May 2002 :  20:39:52  Show Profile
I'm betting some hackers visit or or are members of this site. I'm really glad i never decided to put a link to my forum here because the moral of the story is not to have an easy database dir name and i haven't given mine a secure name as of yet and they would have been all through my system. My forum is only for fun and experimental use at the moment and doesn't even have any members. I barely use it. I just wanted to try and get one going. Actually now that i think about it these mods and admin probably have my i.p. through the db here and could easily nibby nose around(not that I'm saying they would). I'm gonna go and do some security fixes on my stuff. Later

Go to Top of Page

Weasel
Starting Member

1 Posts

Posted - 07 May 2002 :  21:23:25  Show Profile  Visit Weasel's Homepage  Send Weasel an ICQ Message
Add me to the list. We had a recent DB backup so it wasn't a big deal to fix, just annoying.
http://www.a-10.org/images/hacked.gif
http://www.a-10.org/images/hacked02.gif

Go to Top of Page

Nathan
Help Moderator

USA
7664 Posts

Posted - 07 May 2002 :  21:51:33  Show Profile  Visit Nathan's Homepage
The snitz exchange was hacked via the members.asp bug.

Really, they did not have to go to all the trouble, HTML was turned on

Nathan Bales
Snitz Exchange | Do's and Dont's
Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Next Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.48 seconds. Powered By: Snitz Forums 2000 Version 3.4.07