Go Back   Super Soaker Central > Super Soaker Central > News
User Name
Password
FAQ Members List Calendar Mark Forums Read


Welcome to the SSC Forums! You are currently viewing our boards as a guest which gives you limited access. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and more. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact us.
Important note: The SSC forums are now in archive mode. WaterWar.net is the new online discussion board for the water gun hobby.

Reply
 
Thread Tools
Old 09-13-2011, 07:45 PM   #1
Ben
Founder
 
Ben's Avatar
 
Join Date: Mar 2003
Location: Maryland
Posts: 6,447
UserID: 1
Default SSC images subdomain hacked

A week and a half ago someone uploaded a new index.html file to our images subdomain. I believe this was due to the permissions of the public_html directory being too permissive as there is no indication that the hacker knows any of SSC's passwords. I have changed the appropriate passwords regardless and have removed the file.

Firefox and other browsers may report that images.sscentral.org is an attack site because of this hack. I'm working on fixing that. Edit: This was fixed rather quickly.
__________________

[email address] / Please read this before emailing or PMing me

Do not ask me water gun questions by email or PM. Please post the question at the forum. Private questions and suggestions are welcome by PM and email. Also, I do not sell or buy water guns online.

Last edited by Ben : 09-18-2011 at 10:33 PM.
Ben is offline   Reply With Quote
Old 11-23-2011, 07:02 AM   #2
Marlon28
Junior member
 
Marlon28's Avatar
 
Join Date: Nov 2011
Posts: 3
UserID: 2579
Default Re: SSC images subdomain hacked

It seems that your hosting allows wildcard subdomains. You can enter anything in and it would be accepted. The solution would be to stop your hosting answering for these queries and redirect /delete from there.
Marlon28 is offline   Reply With Quote
Old 11-24-2011, 10:38 PM   #3
Ben
Founder
 
Ben's Avatar
 
Join Date: Mar 2003
Location: Maryland
Posts: 6,447
UserID: 1
Default Re: SSC images subdomain hacked

How are the wildcard subdomains related to this problem? It seems that someone used a script to upload a file to a subdomain that was in use.
__________________

[email address] / Please read this before emailing or PMing me

Do not ask me water gun questions by email or PM. Please post the question at the forum. Private questions and suggestions are welcome by PM and email. Also, I do not sell or buy water guns online.
Ben is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off

All times are GMT -5. The time now is 02:31 PM.


Powered by vBulletin
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Copyright ©2003 - 2011 The Super Soaker Central project