Wordpress Theme - Wordpress Themes - Deaf Topics - Wordpress Themes - Computer Jobs

PDA

View Full Version : Getting hacked


Blogmaster
Jul 3rd 2005, 12:15 am
Has anyone ever received an email such as this one:

THIS FORUM HACKED BY TURKISH HACKER ENO7 Inbox

HACKED BY TURKISH HACKER ENO7 <info@surfingsandiego.com> to mike
More options Jul 2 (14 hours ago)

THIS FORUM HACKED BY TURKISH HACKER ENO7.

http://www.surfingsandiego.com/forum/ This forum has some security bugs i didnt erase anything... WARNED BY ENO7

---------------------------------------------------------------------------------------
Software provided by Web Wiz Forums version 7.9 - http://www.webwizforums.com
Free ASP Bulletin Board System - Download your free copy today!

Juls
Jul 3rd 2005, 12:57 am
no but i have heard of this type of email. it is more of a nice little note letting you know that the forum script that you are using is vulnerable. i would suggest updating the software if an update has been provided or swapping to another more secure script.

lucky it wasnt a black hat kiddie script or you would have lost all of your forum data.

good luck.

TommyD
Jul 3rd 2005, 7:05 am
Being the weekend, if you run into any problems getting the script updated, I would get into the habit of pulling a data backup frequently.

Only data since if a 'corrupted' file is installed when hacked, you don't want to reinstall from a backup, use a fresh install with the latest software.

BTW, have you forwarded the email to the forum script maker?

later,

tom

nddb
Jul 3rd 2005, 7:26 am
Is that the exact url they sent you? You should look at the source code of the url in the email, make sure they aren't trying to steal your cookies.

The only recent exploits I see are only for version 7.8, not 7.9, and they are just cross site scripting, and they don't work on 7.9 (tried the java alert box test).

It seems to me, if someone was legitimately out to warn you, they would have given you details of the exploit, not just said "I hacked your forum, it had some bugs, don't worry."

If you can, get the IP from the email, look through your web logs, see what that IP did. Or just generally see if anything strange is sent to your forum, or if anyone had access to admin areas. I would thoroughly check this out.

He could be looking for money. He could be messing with you. He could have legitimately found a hole, but why doesn't he give details on it?

Janissary
Jul 6th 2005, 12:57 pm
http://www.google.com.tr/search?q=HACKED+BY+TURKISH+HACKER+ENO7&sourceid=mozilla-search&start=0&start=0&ie=utf-8&oe=utf-8&client=firefox-a&rls=org.mozilla:tr-TR:official

Blogmaster
Jul 6th 2005, 2:10 pm
wow ... well at least I don't feel singled out :)

nddb
Jul 6th 2005, 8:33 pm
that's some nice ascii on the lesbian247 site. =)

I googled it, but didn't find anything, perhaps I just needed to use the turkish google. =)

Blogmaster
Jul 12th 2005, 6:13 pm
You know, this is almost funny but: the hacker went into our forum and posted ... then we secured it. Then one of the members started cursing him out, so the hacker went back in and banned the guy who cursed him.

santos
Jul 13th 2005, 11:11 am
There is same topic... i research him and i surprised look that link...

http://forums.digitalpoint.com/showthread.php?goto=newpost&t=21132

justicewhite
Jul 14th 2005, 1:32 am
You know, this is almost funny but: the hacker went into our forum and posted ... then we secured it. Then one of the members started cursing him out, so the hacker went back in and banned the guy who cursed him.

I wish all the hackers were as nice as this one :)

relixx
Aug 8th 2005, 12:23 am
He also got a local anime forum I'm a member of. He doesn't seem to do much damage, just trying to make a name for himself (like SarahK said, "Fame and glory!"). Then again, it could be a smokescreen... :/

SeNSe
Sep 11th 2005, 1:26 pm
i wish too justice :D:D

mightyb
Sep 11th 2005, 3:28 pm
Well a few years ago i have managed to find that phpbb MD5 id exploit, when it first been posted. I warned a few admins myself with similar emails. Obviously not "Im the evil script kiddy Hax3r, be warned!"

Cyptc
Oct 10th 2005, 1:09 am
LoL. Dont look like hes so nice. Just makin a name for himself.

WebGeek182
Mar 2nd 2007, 5:50 pm
Hacks can get ugly...I've had a server hacked by guys like this.