1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Hacked!

Discussion in 'Site & Server Administration' started by Daz, Mar 19, 2007.

  1. #1
    Look at this,
    My whole site got taken down.
    150000 members DELETED.
    2 years of work.

    Owned SysTem By Akrep__KraL
    Owned SysTem By Akrep__KraL
    Owned SysTem By Akrep__KraL
    Owned SysTem By Akrep__KraL
    Owned SysTem By Akrep__KraL

    Is all I can see, and on one of my pages, i got this:
    [​IMG]


    I found out that its some big hacker group from turkey, obviously.


    I need help.
    If you can help in any way, shape or form please let me know.
    I'm quite helpless.
     
    Daz, Mar 19, 2007 IP
  2. Kerosene

    Kerosene Alpha & Omega™ Staff

    Messages:
    11,366
    Likes Received:
    575
    Best Answers:
    4
    Trophy Points:
    385
    #2
    Email your host immediately and see if they have backups.
     
    Kerosene, Mar 19, 2007 IP
  3. Judd

    Judd Active Member

    Messages:
    1,107
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    90
    #3
    yeah, sorry to hear man. I generally try to do backups at least once a week, just as preventative maintenance.
     
    Judd, Mar 19, 2007 IP
  4. Daz

    Daz Guest

    Messages:
    1,355
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Daz, Mar 19, 2007 IP
  5. Kerosene

    Kerosene Alpha & Omega™ Staff

    Messages:
    11,366
    Likes Received:
    575
    Best Answers:
    4
    Trophy Points:
    385
    #5
    Same here. It's a lesson you only need to learn once :(
     
    Kerosene, Mar 19, 2007 IP
  6. Daz

    Daz Guest

    Messages:
    1,355
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    0
    #6
    I have backups, and I make backups daily. Thats not the point.
    The point is someone managed to get into my site, take it down, and delete the players.
    There's no point in restoring the players until this issue is sorted, is there?
     
    Daz, Mar 19, 2007 IP
  7. GlobalGamingNews

    GlobalGamingNews Banned

    Messages:
    316
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #7
    What are you meaning when you say they deleted the site? Are you saying that it was a forum hack, or are you saying they took down a normal web site?
     
    GlobalGamingNews, Mar 19, 2007 IP
  8. adsblog

    adsblog Active Member

    Messages:
    659
    Likes Received:
    27
    Best Answers:
    0
    Trophy Points:
    70
    #8
    what is your CMS ?
     
    adsblog, Mar 19, 2007 IP
  9. Daz

    Daz Guest

    Messages:
    1,355
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    0
    #9
    The game is an online RPG.
    Its quite big, and has , as I said, over 150,000 members.
    We do not have any CMS or any backend to it - we use only SSH / phpmyadmin / ftp.


    They took down my site by Deleting the players table, and all 150,000 members.
    They then overwrote the cache page to be what I showed you in the first picture.
    Akrep__KraL is the person or alibi of the guy who hacked the site.
    Just google his name :/

    I found al ot of info about my site here:
    http://www.spygrup.org/showthread.php?p=122097#post122097

    If someone could help translate it form turkish to english it'd be great. Any other help?


    Also I figure its an SQL injection. The thing is, I recently hired someone to overhaul the site and secure it..
    We're looking into it now.
     
    Daz, Mar 19, 2007 IP
  10. shortd81

    shortd81 Banned

    Messages:
    2,007
    Likes Received:
    62
    Best Answers:
    0
    Trophy Points:
    0
    #10
    The same people hacked my site about 6 months ago. I got a public apology and also got his ip address from my host. They can get in ALOT of trouble if you find out who did it.

    I'll have my friend translate it when he gets off work.
     
    shortd81, Mar 19, 2007 IP
  11. GlobalGamingNews

    GlobalGamingNews Banned

    Messages:
    316
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Yeah, being able to read what they say would probably give a more difinitive view.

    My best guess is that:

    1. Maybe they performed some kind of Apache hack

    or

    2. Your PHP was opened up to some form of cross site scripting or sql injection.

    Have you been able to get in contact with your web host?
     
    GlobalGamingNews, Mar 19, 2007 IP
  12. Daz

    Daz Guest

    Messages:
    1,355
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Thanks,
    We know who did it. The site I posted, the guy who posted "MIssion Passed" is a "super moderator" on the forums.

    None of the access logs were deleted. We're getting all the info we can.
     
    Daz, Mar 19, 2007 IP
  13. Daz

    Daz Guest

    Messages:
    1,355
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    0
    #13
    XSS Is probably what it'll be.. But I'm hosting it directly at Layeredtech, no middle man.
    I'm putting a database restore on it now.
     
    Daz, Mar 19, 2007 IP
  14. T0PS3O

    T0PS3O Feel Good PLC

    Messages:
    13,219
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Block SSH/FTP and PHPMyAdmin by IP so only you and you only can access it. Restore the back-up so your audience isn't affected too much. Then start digging in log files and start talking to the host. Search for any files that are publicly writable and CHMOD them back to a secure setting. Then start sanitizing all SQL GET/POST input.
     
    T0PS3O, Mar 19, 2007 IP
  15. Daz

    Daz Guest

    Messages:
    1,355
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    0
    #15

    We started multiple times. There are hundreds and hundreds of pages that need securing.
    I wish I had more experience in such things.

    The thing that shames me about this, is seeing the Islamic Star next to their name.
    How can they even go by that?
    People like this are who drag the name of Islam down as a whole.
    I am a believer in Islam, and don't believe that ANYTHING radical or illegal done 'in the name of islam' is right.
     
    Daz, Mar 19, 2007 IP
  16. Daz

    Daz Guest

    Messages:
    1,355
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    0
    #16
    Well, just as a little update I spoke to him thanks to another DP member, and he will leave my sites alone from now on, apparently.

    Until it got to this a number of my other sites got taken down, along with several PHPBB forums (Which were just installed 2 days ago..).
    My VBulliten forum is still standing though :p
     
    Daz, Mar 19, 2007 IP
  17. nddb

    nddb Peon

    Messages:
    803
    Likes Received:
    30
    Best Answers:
    0
    Trophy Points:
    0
    #17
    I hope he told you how he got in, and how to fix it. It's only courteous. He didn't have to kill all your 150,000 users to deface the page... that's just malicious.
     
    nddb, Mar 19, 2007 IP
  18. tokyoice

    tokyoice Well-Known Member

    Messages:
    3,326
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    165
    #18
    Sorry to hear that, hope you get it sorted
     
    tokyoice, Mar 19, 2007 IP
  19. Daz

    Daz Guest

    Messages:
    1,355
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    0
    #19
    I just found out he also deleted EVERY single backup we had on the server.
    2 years of work.
    Gone.
     
    Daz, Mar 19, 2007 IP
  20. Judd

    Judd Active Member

    Messages:
    1,107
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    90
    #20
    oh man, no off site storage or hard copies on a disk?
     
    Judd, Mar 19, 2007 IP