Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Welcome Back DPF!
#1
Glad to finally see the Forum back! Can someone give a forensic update of what happened?!

I was starting to get the shakes [some kind of withdrawal symptoms].....better now. Big Grin
"Let me issue and control a nation's money and I care not who writes the laws. - Mayer Rothschild
"Civil disobedience is not our problem. Our problem is civil obedience! People are obedient in the face of poverty, starvation, stupidity, war, and cruelty. Our problem is that grand thieves are running the country. That's our problem!" - Howard Zinn
"If there is no struggle there is no progress. Power concedes nothing without a demand. It never did and never will" - Frederick Douglass
Reply
#2
Peter - thank you.

We will explain what happened, but perhaps without too many details as we are still running a live investigation into the perpetrators.

As per Magda's announcement, we would ask every member to change their password. Thank you.

Quote:Welcome back every one! Well we sure missed you and the forum but we hope to be back to normal operations now. The forum was hacked but thanks to the fantastic work of DPF member and techie extraordinaire and damn fine human being Peter Presland and our hosts it looks like everything has been restored intact. There has been a forum upgrade during this process as well. Working in different time zones in different languages with different companies and with visiting family and grand children to entertain has meant that it took longer than we planned but it has been thoroughly tested and checked and we decided it was ready to go live. We would also ask that you keep an eye on things and let us know if you notice any thing odd or strange. Odd files, behavior or strange member names on line for example. Just in case we missed some thing. But we are pretty confident we got it all. Please feel free to post all those things you saw the last week and were not able to do so. There is so much to catch up on.
"It means this War was never political at all, the politics was all theatre, all just to keep the people distracted...."
"Proverbs for Paranoids 4: You hide, They seek."
"They are in Love. Fuck the War."

Gravity's Rainbow, Thomas Pynchon

"Ccollanan Pachacamac ricuy auccacunac yahuarniy hichascancuta."
The last words of the last Inka, Tupac Amaru, led to the gallows by men of god & dogs of war
Reply
#3
I bet others too find new appreciation for this gathering place.
I missed this place.
Thanks to all.
Thanks to the mods and our host.
Sincerely
JimBig Grin
Read not to contradict and confute;
nor to believe and take for granted;
nor to find talk and discourse;
but to weigh and consider.
FRANCIS BACON
Reply
#4
NB - for about 15 minutes an hour ago, the Forum was not accessible...don't know what was going on.
"Let me issue and control a nation's money and I care not who writes the laws. - Mayer Rothschild
"Civil disobedience is not our problem. Our problem is civil obedience! People are obedient in the face of poverty, starvation, stupidity, war, and cruelty. Our problem is that grand thieves are running the country. That's our problem!" - Howard Zinn
"If there is no struggle there is no progress. Power concedes nothing without a demand. It never did and never will" - Frederick Douglass
Reply
#5
Summary
Administrator access was gained through a documented vulnerability in the vBulletin-Facebook/Ajax connect facility. vBulletin had issued a patch but it had't been applied. The site is now running on the latest stable release of v4.2 incorporating all security patches applied to date.

What they did
Privileged access facilitated the creation of 3 new administrator accounts - each using a different IP address. Following a clearly fraudulent application for legitimate membership, one of these accounts was quickly spotted and deleted because of its odd name. The other two were named respectively 'Admin' and 'Administrator' and were active long enough to run at least 2 rogue php scripts. Among other things, the result was the installation of a powerful php pseudo-shell with the same file system privileges as the dedicated Apache web-server user. This enabled the hackers to delete the previous day's backup, but fortunately not before a copy had been saved off-site (the one eventually used to restore the site). They also uploaded their 'trophy' page which confirmed the hack to those who make it their business to monitor the web for such things - for both good and bad reasons.

Also uploaded was a doctored and slightly-renamed vB php script and a whole raft of legitimately named - but illegitimate in content - .gz files replacing the regular ones. It is not clear what the precise capabilities of all these files and scripts are (yet), but its safe to say they are extensive - let your imagination loose on the possibilities.

In any event, the hack became obvious fairly quickly and a global htaccess block was put on the site immediately.

Extensive checking of the latest possible backup database was carried out; it was eventually restored to a newly-created and differently named database with different credentials; The old vBulletin system was deleted in its entirety and a brand new u-t-d one installed.

All this means that there are bound to be glitches in previously taken-for-granted facilities (for example the Facebook connect facility is currently disabled and may remain so as a matter of policy).

Please advise of anything that appears odd or different from what you are used to.

Whilst there can be no guarantees in such matters - other than the inevitability of further hacking attempts - the site seems to be OK again and lessons have been learned.
Peter Presland

".....there is something far worse than Nazism, and that is the hubris of the Anglo-American fraternities, whose routine is to incite indigenous monsters to war, and steer the pandemonium to further their imperial aims"
Guido Preparata. Preface to 'Conjuring Hitler'[size=12][size=12]
"Never believe anything until it has been officially denied"
Claud Cockburn

[/SIZE][/SIZE]
Reply
#6
Thanks for that detailed forensic analysis Peter. Any idea who 'done it'? [Did they leave any clues? hints?] As I remember their hack trophy page said something like Moroccan Liberation Front...or along those lines. Were there other vBulletin victims by the same group or person or entity?

Once when I tried to change my email, I was told my email was 'banned'. I haven't tried again...yet. Thanks greatly for the hard work you did!!! Bravo!
"Let me issue and control a nation's money and I care not who writes the laws. - Mayer Rothschild
"Civil disobedience is not our problem. Our problem is civil obedience! People are obedient in the face of poverty, starvation, stupidity, war, and cruelty. Our problem is that grand thieves are running the country. That's our problem!" - Howard Zinn
"If there is no struggle there is no progress. Power concedes nothing without a demand. It never did and never will" - Frederick Douglass
Reply
#7
Peter Lemkin Wrote:Thanks for that detailed forensic analysis Peter. Any idea who 'done it'? [Did they leave any clues? hints?] As I remember their hack trophy page said something like Moroccan Liberation Front...or along those lines. Were there other vBulletin victims by the same group or person or entity?

Best not to go into too much detail publicly.

The original exploit was by a Moroccan IP address and the trophy page was ostensibly in support of the Palestinian cause, which is sad considering the robust support for that cause here. However I think it unlikely that DPF was targeted for any reason other than that a vulnerability was discovered by people who search for such things globally and systematically. You will find several thousand similar hacks listed by various sites with a suitable Google search. Its also possible that the access credentials were then passed on (for a consideration or whatever - maybe even automatically through the trophy page) because a US IP address was also heavily involved after the initial hack.

We do know quite a bit more but best to stay mum while continuing to dig.

Peter Lemkin Wrote:Once when I tried to change my email, I was told my email was 'banned'. I haven't tried again...yet. Thanks greatly for the hard work you did!!! Bravo!

It IS possible they began interfering with high volume user accounts. If so, any such changes that were recognized as legitimate by the vB software (ie regular Administrator actions) and done before both the backup we used to restore the site and implementation of the htaccess block would remain in the database. I think it highly unlikely that any such possible changes contain viruses or other nasties though - but you can NEVER be 100% about these things. The entire database was been checked using vB tools and was reported clean.

That's why it would be good to hear of any other such anomalies.
Peter Presland

".....there is something far worse than Nazism, and that is the hubris of the Anglo-American fraternities, whose routine is to incite indigenous monsters to war, and steer the pandemonium to further their imperial aims"
Guido Preparata. Preface to 'Conjuring Hitler'[size=12][size=12]
"Never believe anything until it has been officially denied"
Claud Cockburn

[/SIZE][/SIZE]
Reply
#8
Peter Lemkin Wrote:Any idea who 'done it'? [Did they leave any clues? hints?] As I remember their hack trophy page said something like Moroccan Liberation Front...or along those lines. Were there other vBulletin victims by the same group or person or entity?
No it was the People's Liberation Front of Morocco.
"The philosophers have only interpreted the world, in various ways. The point, however, is to change it." Karl Marx

"He would, wouldn't he?" Mandy Rice-Davies. When asked in court whether she knew that Lord Astor had denied having sex with her.

“I think it would be a good idea” Ghandi, when asked about Western Civilisation.
Reply
#9
Magda Hassan Wrote:
Peter Lemkin Wrote:Any idea who 'done it'? [Did they leave any clues? hints?] As I remember their hack trophy page said something like Moroccan Liberation Front...or along those lines. Were there other vBulletin victims by the same group or person or entity?
No it was the People's Liberation Front of Morocco.

Magda, Peter, others in the know, I understand perfectly your wish to hold some information close to your chests for now [or forever]. I guess my wish was to know if it was the BIG BOYS or just some black hackers out for a 'lark'. The support for the Palestinians on the hack page tends to make it look either an indiscriminate hack of opportunity or a false-flag hack. I realize you might not know or have clues, and further if you do you might not care to share publicly. :Confusedhtf::
"Let me issue and control a nation's money and I care not who writes the laws. - Mayer Rothschild
"Civil disobedience is not our problem. Our problem is civil obedience! People are obedient in the face of poverty, starvation, stupidity, war, and cruelty. Our problem is that grand thieves are running the country. That's our problem!" - Howard Zinn
"If there is no struggle there is no progress. Power concedes nothing without a demand. It never did and never will" - Frederick Douglass
Reply
#10
Magda Hassan Wrote:
Peter Lemkin Wrote:Any idea who 'done it'? [Did they leave any clues? hints?] As I remember their hack trophy page said something like Moroccan Liberation Front...or along those lines. Were there other vBulletin victims by the same group or person or entity?
No it was the People's Liberation Front of Morocco.

Lol, we ARE in a Monty Python skit. I've suspected it for years.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  DPForum Back! Peter Lemkin 0 72 21-11-2024, 03:02 PM
Last Post: Peter Lemkin
  Back on line Magda Hassan 7 32,398 27-03-2020, 02:25 AM
Last Post: Magda Hassan

Forum Jump:


Users browsing this thread: 1 Guest(s)