New Forum Code, Oh My!
#1
Posted 17 April 2006 - 12:08 PM
I'm looking into things now but early information suggests an SQL injection attack. I will keep everyone updated as I learn more.
#2
Posted 17 April 2006 - 12:22 PM
Organizer Vancouver Area Nerf Series
#3
Posted 17 April 2006 - 12:50 PM
No need, the headers won't tell me anything because I already know it was sent by our forum software. Fortunately I have admin logs that give me some information about how that happened. The possibilities are currently as follows:Thanks for getting on that so quick, Cxwq. Let me know if forwarding the email to you would help.
1. An account with admin privs was hacked by some asshat in Frankfurt and used to send a bulk spam message. If this was the case then it won't happen again as I just reset that account's PW.
2. There is an SQL injection vulnerability against our current version of IBF and some asshat in Frankfurt abused it to send a bulk spam message. I think this is probably the more likely possibility because we're running pretty old code. I'm going to upgrade the forum code sometime this week which should take care of things.
Either way, I appologize for the spam being sent out in my name.
#4
Posted 17 April 2006 - 05:59 PM
Anyone notice a difference?
Too bright... must...
kill...
monitor!
#5
Posted 17 April 2006 - 06:42 PM
So either way it was an asshat in Frankfurt. That makes me chuckle.
#6
Posted 17 April 2006 - 06:49 PM
It's so weird to see NH like this... and with this skin.
Fucking hackers too. I thought only NHq was that "n00b".
Not in the game anymore, but it was great while it lasted. Thanks for the great years of fun, NH!
--
Resident "Spawn of Talio"
#7
Posted 17 April 2006 - 06:50 PM
Yeah, bit strange seein the Haven so...Bright. I do believe my eyes will have to be ripped out soon.
So either way it was an asshat in Frankfurt. That makes me chuckle.
Actually, I later found it was an IP anonymizer in Frankfurt. The asshat turned out to be in Russia. So it goes with this Interweb stuff.
#8
Posted 17 April 2006 - 06:56 PM
<a href="http://www.albinobla.../flash/posting" target="_blank">Posting and You</a>
#9
Posted 17 April 2006 - 07:04 PM
We are lucky we have a well backed up website and webmaster who knows what he is doing. Our backlog of posts is intact, and that's all we can ask for in my opinion. Carry on people.
That's the truth. The last board crash I was on had to roll back a month in its backups before it could get back up. Nevermind that updating the board software there took a month. Thans for keeping it all in hand, Cx.
#10
Posted 17 April 2006 - 07:06 PM
So is this going to be a perminant thing now?
It's so weird to see NH like this... and with this skin.
Fucking hackers too. I thought only NHq was that "n00b".
An eye-soothing dark blue skin of some sort will be up soon. I just need to write one from scratch because the old CSS formats have been dumped by Invision.
As far as the haxor thing, ALL forum software gets exploited from time to time. That's just a fact of life running complicated php code that's externally accessible to anyone in the world. I just upgraded something like 12 versions, point versions, and security updates. Fortunately, the new update system is MUCH easier to use so it will be more convenient to stay up to date in the future.
#11
Posted 17 April 2006 - 07:20 PM
An eye-soothing dark blue skin of some sort will be up soon. I just need to write one from scratch because the old CSS formats have been dumped by Invision.
As far as the haxor thing, ALL forum software gets exploited from time to time. That's just a fact of life running complicated php code that's externally accessible to anyone in the world. I just upgraded something like 12 versions, point versions, and security updates. Fortunately, the new update system is MUCH easier to use so it will be more convenient to stay up to date in the future.
Oh, that sounds good then. Perhaps this won't be a total loss. I just loved how you had the portal page setup, you did a great job with that stuff.
I can't wait for the dark skin though.
Is it just me, or is the BB code a little different now? No uppercase code, and you need spaces inbetween the [____] and [/____]. Oh well.
Not in the game anymore, but it was great while it lasted. Thanks for the great years of fun, NH!
--
Resident "Spawn of Talio"
#12
Posted 17 April 2006 - 08:44 PM
And its good to see that the ole loser filter still works.
Edited by Illadar, 17 April 2006 - 09:08 PM.
#13
Posted 17 April 2006 - 08:56 PM
My monitor detests--scratch that, HATES everything about the shade white. It literally will display other colors in its place. As in...I have dots of purple in it all over the place. Does the same thing with black...
Well, the blue will be nice. I haven't had blue in forever. I used the grey/gray skin with the old/other/older forum.
One last question: Will I, with multiple firewalls and latest McAfee, with Netscape (Mozilla?), have to worry about that trojan/whateveritis invading my puter? I have some very dear files to me...ones which are not pr0n, in case anyone was wondering...let's just say they are worth money for me...
Well, nice to see that cx knows everything he needs to know to run a highly-succesful forum.
By the way, do you happen to know the address/location in lat-long of the hacker? I know a few people who have relations in Russia, and they owe me a favor.
#14
Posted 17 April 2006 - 09:28 PM
Not to sound racist or anything, but yes, dark skin is much better.
Aye, another Russian seems to be holding a prolonged grudge against us. I'd choose someplace happier than Frankfurt if I wanted an alias though...
Edited by LordoftheRing434, 17 April 2006 - 09:29 PM.
"I bluff it. I don't throw my weight around and say I know what I'm doing." ~ Mick Jagger
#15
Posted 18 April 2006 - 06:19 AM
It says primarily IE (Internet Explorer) so with your firewalls I bet it would have detected it.I have AVG, which I never really liked that much but just as I got directed to the site before it got blocked off it automatically popped up with (finally) a working heal button, after that i made sure to clean, and everything but but if I have a free version of AAVG and it caught multiples, McAfee, and the others you said Im guessing would have taken care of it. Also you said netscape, so I would be thinking a little safer anyway.
Guitar Heroes-Jimmy Paige, Eric Clapton, Jimi Hendrix, Kurt Cobain
Newly Found(thanks General)-Yngwie Malmstein, this guy is an accoustic expert.
#16
Posted 18 April 2006 - 03:46 PM
voila
Clicking on the Invision logo (where the NH logo used to be) will also take you to the portal now.
#17
Posted 18 April 2006 - 05:39 PM
Guitar Heroes-Jimmy Paige, Eric Clapton, Jimi Hendrix, Kurt Cobain
Newly Found(thanks General)-Yngwie Malmstein, this guy is an accoustic expert.
#18
Posted 18 April 2006 - 10:20 PM
Ha, alright. Sorry bout the asskissing, but it does make ya think.
Oh and GeneralPrimevil, you may have done this already, but try degaussing your monitor.
#19
Posted 19 April 2006 - 09:45 AM
Eyes...burning! I need my mellow blue!!!
-Groove
"Too close for missiles, I'm switchin' to guns"
#20
Posted 19 April 2006 - 03:46 PM
1) Will you be getting more skin plugins that are user adjustable? Not a big deal, just curious
2) Did you lose the Mods/Homemades/Store/DBf/Etc. Links alongside the CoC with the hack attack? If not and they are viewable elsewhere, could you point me in the proper direction? If not, any idea when they will be up?
#21
Posted 19 April 2006 - 04:46 PM
Very nice job with the new skin. I have a few questions though, and as always, I apologize if they have been answered, as I merely skimmed the thread.
1) Will you be getting more skin plugins that are user adjustable? Not a big deal, just curious
2) Did you lose the Mods/Homemades/Store/DBf/Etc. Links alongside the CoC with the hack attack? If not and they are viewable elsewhere, could you point me in the proper direction? If not, any idea when they will be up?
I think what you're talking about is the portal, not the skin. Still working on the skin.
As far as user customizable items, this is the lightweight portal that comes with Invision. I haven't yet decided whether to keep this one with its tight integration and easy customization or to go with a 3rd party portal that's more flexible and has more modules.
Regarding the static content (mods, dbf, etc) take a look 2" under the invision logo on the portal page.
#22
Posted 19 April 2006 - 06:22 PM
#23
Posted 19 April 2006 - 08:31 PM
AA
#24
Posted 20 April 2006 - 12:08 AM
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users