Jump to content


Photo

New Forum Code, Oh My!


23 replies to this topic

#1 cxwq

cxwq

    Member

  • Founders
  • 3,634 posts

Posted 17 April 2006 - 12:08 PM

At least one NH member recently received an email purporting to be from NH admins and requesting that a link be followed. If you received the same, do not click on the link!

I'm looking into things now but early information suggests an SQL injection attack. I will keep everyone updated as I learn more.
  • 0
<meta name="cxwq" content="mostly water">

#2 Hunter

Hunter

    Member

  • Members
  • 312 posts

Posted 17 April 2006 - 12:22 PM

Thanks for getting on that so quick, Cxwq. Let me know if forwarding the email to you would help.
  • 0
Hunter
Organizer Vancouver Area Nerf Series

#3 cxwq

cxwq

    Member

  • Founders
  • 3,634 posts

Posted 17 April 2006 - 12:50 PM

Thanks for getting on that so quick, Cxwq. Let me know if forwarding the email to you would help.

No need, the headers won't tell me anything because I already know it was sent by our forum software. Fortunately I have admin logs that give me some information about how that happened. The possibilities are currently as follows:

1. An account with admin privs was hacked by some asshat in Frankfurt and used to send a bulk spam message. If this was the case then it won't happen again as I just reset that account's PW.

2. There is an SQL injection vulnerability against our current version of IBF and some asshat in Frankfurt abused it to send a bulk spam message. I think this is probably the more likely possibility because we're running pretty old code. I'm going to upgrade the forum code sometime this week which should take care of things.

Either way, I appologize for the spam being sent out in my name.
  • 0
<meta name="cxwq" content="mostly water">

#4 cxwq

cxwq

    Member

  • Founders
  • 3,634 posts

Posted 17 April 2006 - 05:59 PM

Yeah, so we're back up.

Anyone notice a difference?


Too bright... must...

kill...


monitor!
  • 0
<meta name="cxwq" content="mostly water">

#5 dragon26

dragon26

    Member

  • Members
  • 19 posts

Posted 17 April 2006 - 06:42 PM

Yeah, bit strange seein the Haven so...Bright. I do believe my eyes will have to be ripped out soon.

So either way it was an asshat in Frankfurt. That makes me chuckle.
  • 0
Sometimes you just have to bash a n00b into the ground.-Suave

#6 Black Wrath

Black Wrath

    Member

  • Members
  • 1,071 posts

Posted 17 April 2006 - 06:49 PM

So is this going to be a perminant thing now?

It's so weird to see NH like this... and with this skin.

Fucking hackers too. I thought only NHq was that "n00b".
  • 0
Xx_Black-Wrath_xX of The Canadian Foam Militia

Not in the game anymore, but it was great while it lasted. Thanks for the great years of fun, NH!
--
Resident "Spawn of Talio"

#7 cxwq

cxwq

    Member

  • Founders
  • 3,634 posts

Posted 17 April 2006 - 06:50 PM

Yeah, bit strange seein the Haven so...Bright. I do believe my eyes will have to be ripped out soon.

So either way it was an asshat in Frankfurt. That makes me chuckle.



Actually, I later found it was an IP anonymizer in Frankfurt. The asshat turned out to be in Russia. So it goes with this Interweb stuff.
  • 0
<meta name="cxwq" content="mostly water">

#8 The Infinite Shindig

The Infinite Shindig

    Arma-what-now?

  • Contributors
  • 1,383 posts

Posted 17 April 2006 - 06:56 PM

We are lucky we have a well backed up website and webmaster who knows what he is doing. Our backlog of posts is intact, and that's all we can ask for in my opinion. Carry on people.
  • 0
Shindig of the Lawn Chair Mafia

<a href="http://www.albinobla.../flash/posting" target="_blank">Posting and You</a>

#9 Carbon

Carbon

    Contriberator

  • Moderators
  • 1,894 posts

Posted 17 April 2006 - 07:04 PM

We are lucky we have a well backed up website and webmaster who knows what he is doing. Our backlog of posts is intact, and that's all we can ask for in my opinion. Carry on people.


That's the truth. The last board crash I was on had to roll back a month in its backups before it could get back up. Nevermind that updating the board software there took a month. Thans for keeping it all in hand, Cx.
  • 0
Hello. I am Indigo of the Rainbow Clan. You Nerfed my father. Prepare to die.

#10 cxwq

cxwq

    Member

  • Founders
  • 3,634 posts

Posted 17 April 2006 - 07:06 PM

So is this going to be a perminant thing now?

It's so weird to see NH like this... and with this skin.

Fucking hackers too. I thought only NHq was that "n00b".


An eye-soothing dark blue skin of some sort will be up soon. I just need to write one from scratch because the old CSS formats have been dumped by Invision.

As far as the haxor thing, ALL forum software gets exploited from time to time. That's just a fact of life running complicated php code that's externally accessible to anyone in the world. I just upgraded something like 12 versions, point versions, and security updates. Fortunately, the new update system is MUCH easier to use so it will be more convenient to stay up to date in the future.
  • 0
<meta name="cxwq" content="mostly water">

#11 Black Wrath

Black Wrath

    Member

  • Members
  • 1,071 posts

Posted 17 April 2006 - 07:20 PM

An eye-soothing dark blue skin of some sort will be up soon. I just need to write one from scratch because the old CSS formats have been dumped by Invision.

As far as the haxor thing, ALL forum software gets exploited from time to time. That's just a fact of life running complicated php code that's externally accessible to anyone in the world. I just upgraded something like 12 versions, point versions, and security updates. Fortunately, the new update system is MUCH easier to use so it will be more convenient to stay up to date in the future.


Oh, that sounds good then. Perhaps this won't be a total loss. I just loved how you had the portal page setup, you did a great job with that stuff.

I can't wait for the dark skin though.

Is it just me, or is the BB code a little different now? No uppercase code, and you need spaces inbetween the [____] and [/____]. Oh well.
  • 0
Xx_Black-Wrath_xX of The Canadian Foam Militia

Not in the game anymore, but it was great while it lasted. Thanks for the great years of fun, NH!
--
Resident "Spawn of Talio"

#12 Illadar

Illadar

    Member

  • Members
  • 131 posts

Posted 17 April 2006 - 08:44 PM

So can we like... set up an Attack barrier, to screw the bastards next... unless they went through a Defense barrier. Enough Ghost in the Shell references, what I'm really posting about is: How close to the Haven that we all know and love will this be with the new version of invision. Are we talking like exact clone, that the average(me) won't even notice, or will the differnce be apparent.
And its good to see that the ole loser filter still works.

Edited by Illadar, 17 April 2006 - 09:08 PM.

  • 0

#13 GeneralPrimevil

GeneralPrimevil

    Member

  • Members
  • 578 posts

Posted 17 April 2006 - 08:56 PM

Yeah, this is a bit...wierd...I kinda like...but my eyes are starting to burn.

My monitor detests--scratch that, HATES everything about the shade white. It literally will display other colors in its place. As in...I have dots of purple in it all over the place. Does the same thing with black...

Well, the blue will be nice. I haven't had blue in forever. I used the grey/gray skin with the old/other/older forum.

One last question: Will I, with multiple firewalls and latest McAfee, with Netscape (Mozilla?), have to worry about that trojan/whateveritis invading my puter? I have some very dear files to me...ones which are not pr0n, in case anyone was wondering...let's just say they are worth money for me...

Well, nice to see that cx knows everything he needs to know to run a highly-succesful forum.

By the way, do you happen to know the address/location in lat-long of the hacker? I know a few people who have relations in Russia, and they owe me a favor.
  • 0
"Fear the man with one gun, for he probably knows how to use it."

#14 LordoftheRing434

LordoftheRing434

    Member

  • Members
  • 565 posts

Posted 17 April 2006 - 09:28 PM

CX handled this magnitude of a hack with grace and flair. It's good to know the NIC can rely on someone with such dominant skill.

Not to sound racist or anything, but yes, dark skin is much better.

Aye, another Russian seems to be holding a prolonged grudge against us. I'd choose someplace happier than Frankfurt if I wanted an alias though...

Edited by LordoftheRing434, 17 April 2006 - 09:29 PM.

  • 0
And when he gets to Heaven, to St. Peter he will tell, "One more soldier reporting sir, I've served my time in hell."

"I bluff it. I don't throw my weight around and say I know what I'm doing." ~ Mick Jagger

#15 NirvanaScorpion

NirvanaScorpion

    Member

  • Members
  • 120 posts

Posted 18 April 2006 - 06:19 AM

"If you visited the site between 8:19AM and 3:30PM on 4/17 and are using IE without having applied critical windoze updates then you probably have a trojan/keylogger/adware."

It says primarily IE (Internet Explorer) so with your firewalls I bet it would have detected it.I have AVG, which I never really liked that much but just as I got directed to the site before it got blocked off it automatically popped up with (finally) a working heal button, after that i made sure to clean, and everything but but if I have a free version of AAVG and it caught multiples, McAfee, and the others you said Im guessing would have taken care of it. Also you said netscape, so I would be thinking a little safer anyway.
  • 0
"If rock n rolls illegal throw my a** in jail" - Kurt Cobain

Guitar Heroes-Jimmy Paige, Eric Clapton, Jimi Hendrix, Kurt Cobain

Newly Found(thanks General)-Yngwie Malmstein, this guy is an accoustic expert.

#16 cxwq

cxwq

    Member

  • Founders
  • 3,634 posts

Posted 18 April 2006 - 03:46 PM

It's a bit of a proto-portal, but not too bad for a morning's work. I'll set up a redirect on the http://nerfhaven.com/ front page when I have it tweaked a bit more.

voila

Clicking on the Invision logo (where the NH logo used to be) will also take you to the portal now.
  • 0
<meta name="cxwq" content="mostly water">

#17 NirvanaScorpion

NirvanaScorpion

    Member

  • Members
  • 120 posts

Posted 18 April 2006 - 05:39 PM

Whoa, pretty nice. I have to say, not at all bad for the amount of time you had to start with pretty much nothing. Cant wait for your new skin though.
  • 0
"If rock n rolls illegal throw my a** in jail" - Kurt Cobain

Guitar Heroes-Jimmy Paige, Eric Clapton, Jimi Hendrix, Kurt Cobain

Newly Found(thanks General)-Yngwie Malmstein, this guy is an accoustic expert.

#18 Anothernoob

Anothernoob

    Member

  • Members
  • 71 posts

Posted 18 April 2006 - 10:20 PM

Yea CX deserves a round of applause. Seriously. I wouldn't say this if running Nerfhaven was the only thing he had to do in life, but I suspect he's busy. He's taking time out of his life ya'll. Devotion.

Ha, alright. Sorry bout the asskissing, but it does make ya think.

Oh and GeneralPrimevil, you may have done this already, but try degaussing your monitor.
  • 0

#19 Groove

Groove

    Certified Badass

  • Founders
  • 1,673 posts

Posted 19 April 2006 - 09:45 AM

Thanks for getting this back up and running Cx, although not at full-steam-ahead working capacity, something is better than nothing. Keep us updated on the situation.

Eyes...burning! I need my mellow blue!!!

-Groove
  • 0

"Too close for missiles, I'm switchin' to guns"


#20 Rambo

Rambo

    Fear the Robble...

  • Members
  • 1,807 posts

Posted 19 April 2006 - 03:46 PM

Very nice job with the new skin. I have a few questions though, and as always, I apologize if they have been answered, as I merely skimmed the thread.

1) Will you be getting more skin plugins that are user adjustable? Not a big deal, just curious
2) Did you lose the Mods/Homemades/Store/DBf/Etc. Links alongside the CoC with the hack attack? If not and they are viewable elsewhere, could you point me in the proper direction? If not, any idea when they will be up?
  • 0

#21 cxwq

cxwq

    Member

  • Founders
  • 3,634 posts

Posted 19 April 2006 - 04:46 PM

Very nice job with the new skin. I have a few questions though, and as always, I apologize if they have been answered, as I merely skimmed the thread.

1) Will you be getting more skin plugins that are user adjustable? Not a big deal, just curious
2) Did you lose the Mods/Homemades/Store/DBf/Etc. Links alongside the CoC with the hack attack? If not and they are viewable elsewhere, could you point me in the proper direction? If not, any idea when they will be up?


I think what you're talking about is the portal, not the skin. Still working on the skin.

As far as user customizable items, this is the lightweight portal that comes with Invision. I haven't yet decided whether to keep this one with its tight integration and easy customization or to go with a 3rd party portal that's more flexible and has more modules.

Regarding the static content (mods, dbf, etc) take a look 2" under the invision logo on the portal page.
  • 0
<meta name="cxwq" content="mostly water">

#22 One Man Clan

One Man Clan

    TOFTS

  • Contributors
  • 2,170 posts

Posted 19 April 2006 - 06:22 PM

uh, just make it dark. That'll do it for me.
  • 0
I hate you.

#23 AirApache

AirApache

    Member

  • Members
  • 743 posts

Posted 19 April 2006 - 08:31 PM

Leave for a week and the forum gets hacked... well, glad to see NH still up and running.

AA
  • 0
Indiana '11

#24 Rambo

Rambo

    Fear the Robble...

  • Members
  • 1,807 posts

Posted 20 April 2006 - 12:08 AM

Bah, somehow I managed to lose paint? And my Freehand/Fireworks won't install so my screenshot is useless. Anyway, if you scroll to the bottom there is a skin selector. I know there are lots of plug-ins for it for other skins. Thanks for the info about the additional pages, I usually go straight to the forum.
  • 0


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users