1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

DP defaced? (HACKED)

Discussion in 'Support & Feedback' started by mightyb, Apr 1, 2006.

  1. NeoGen

    NeoGen Writer

    Messages:
    2,303
    Likes Received:
    301
    Best Answers:
    0
    Trophy Points:
    230
    #61
    I posted this using germen proxy;)
     
    NeoGen, Apr 1, 2006 IP
  2. ResaleBroker

    ResaleBroker Active Member

    Messages:
    1,665
    Likes Received:
    50
    Best Answers:
    0
    Trophy Points:
    90
    #62
    ResaleBroker, Apr 1, 2006 IP
  3. LuffE

    LuffE Guest

    Messages:
    414
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    0
    #63
    Denmark here, saw it too.
     
    LuffE, Apr 1, 2006 IP
  4. Seiya

    Seiya Peon

    Messages:
    4,666
    Likes Received:
    404
    Best Answers:
    0
    Trophy Points:
    0
    #64
    Your lying dude im in the us and i post perfectly ifne :p
     
    Seiya, Apr 1, 2006 IP
  5. BigTicket

    BigTicket Peon

    Messages:
    197
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #65
    I agree otherwise why would some of us only get it about an hour after the first person to see it. I was on for a while and did not get it until just of few minutes ago.
     
    BigTicket, Apr 1, 2006 IP
  6. NeoGen

    NeoGen Writer

    Messages:
    2,303
    Likes Received:
    301
    Best Answers:
    0
    Trophy Points:
    230
    #66
    There seems to one more wierd problem, the forum is allowing to post even without a login:confused:
     
    NeoGen, Apr 1, 2006 IP
  7. SEO-MAN

    SEO-MAN Peon

    Messages:
    673
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #67
    :p :p It was 110% Fake!!! if a site gets defaced its not going to let you login to the site Plus if this was realy defaced then Shawn would have know about it since it didnt last long and he says he didnt know about it well if his server is close by and manged by him then he would have know and seeing he is here then he new about it even if he dont mange his own server. :p :p

    Plus if you check the tag of the person that was left nothing comes up in google which shows its even more fake.
     
    SEO-MAN, Apr 1, 2006 IP
  8. kinkarso

    kinkarso Well-Known Member

    Messages:
    358
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    120
    #68
    I was surfing through Digital Point, when suddenly, a page appeared instead of the index. :confused: . I managed to get a screen shot:

    [​IMG]

    Thank You,
    Donny
     
    kinkarso, Apr 1, 2006 IP
  9. dkessaris

    dkessaris Peon

    Messages:
    984
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #69
    I guess it's a joke since I have a cookie that expires tomorrow from forums.digitalpoint.com that is called hacked
     
    dkessaris, Apr 1, 2006 IP
  10. SEO-MAN

    SEO-MAN Peon

    Messages:
    673
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #70
    Well there will be more proof and it will come out that it was true that it was an april fools joke. :)
     
    SEO-MAN, Apr 1, 2006 IP
  11. NeoGen

    NeoGen Writer

    Messages:
    2,303
    Likes Received:
    301
    Best Answers:
    0
    Trophy Points:
    230
    #71
    No No its not fake..The site has been hacked its official now.. this is one of the most old trick used by hackers to change the index file.. the database remains same.. but when you login instead of index.php it would redirect to hacked html..

    Seems that .htaccess file has been compromised in this case..
     
    NeoGen, Apr 1, 2006 IP
  12. SEO-MAN

    SEO-MAN Peon

    Messages:
    673
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #72
    well then it would have been redircted then which it was not.

    if some one setup a 302 redirct you would have it redirct to a different page.
     
    SEO-MAN, Apr 1, 2006 IP
  13. LuffE

    LuffE Guest

    Messages:
    414
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    0
    #73
    [​IMG]
     
    LuffE, Apr 1, 2006 IP
  14. SEO-MAN

    SEO-MAN Peon

    Messages:
    673
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #74
    i would like to see it close so that i can read it since there are sites where you can make thoose fake newspapers or fake things like that.
     
    SEO-MAN, Apr 1, 2006 IP
  15. Roman

    Roman Buffalo Tamerâ„¢

    Messages:
    6,217
    Likes Received:
    592
    Best Answers:
    0
    Trophy Points:
    310
    #75
    Roman, Apr 1, 2006 IP
  16. LuffE

    LuffE Guest

    Messages:
    414
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    0
    #76
    Was just for a little smiley, its Kevin Mitnick :)
     
    LuffE, Apr 1, 2006 IP
  17. genkied

    genkied Active Member

    Messages:
    2,025
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    90
    #77
    i saw this
    [​IMG]
     
    genkied, Apr 1, 2006 IP
  18. NeoGen

    NeoGen Writer

    Messages:
    2,303
    Likes Received:
    301
    Best Answers:
    0
    Trophy Points:
    230
    #78
    Its not the redirect as its using .htaccess
    There are tow vulnerabilities were reported in vBulletin. A remote user can execute arbitrary commands on the target system. A remote user can also conduct cross-site scripting attacks.
    A file is included with the error in the Cache_library that allows a remote user to specify a remote location for the 'vbConfig_absolute_path' parameter to cause the target server to include and execute PHP code from the remote location. The PHP code, including operating system commands, will be executed with the privileges of the target web service.

    It is also reported that the 'index.php' script does not properly validate user-supplied input in the Itemid, vbmsg, and limit parameters. A remote user can create a specially crafted URL that, when loaded by a target user, will cause arbitrary scripting code to be executed by the target user's browser. The code will originate from the site running the vBulletin software and will run in the security context of that site. As a result, the code will be able to access the target user's cookies (including authentication cookies), if any, associated with the site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.

    Impact: A remote user can execute arbitrary PHP code and operating system commands on the target system with the privileges of the target web service. They can also different page every time and a cookie is set in their system namied hacked.

    A remote user can access the target user's cookies (including authentication cookies), if any, associated with the site running the vBulletinServer software, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.

    Seems that Shawn and his team have not appiled the latest patch, as the problem is more due to php than that of vBulletnn
     
    NeoGen, Apr 1, 2006 IP
  19. SEO-MAN

    SEO-MAN Peon

    Messages:
    673
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #79
    SEO-MAN, Apr 1, 2006 IP
  20. Roman

    Roman Buffalo Tamerâ„¢

    Messages:
    6,217
    Likes Received:
    592
    Best Answers:
    0
    Trophy Points:
    310
    #80
    Yeah, Must Be Shawn's stab at an April fools joke.

    Sorry, noticed the other thread after posting, you can move this there if you like.
     
    Roman, Apr 1, 2006 IP