Go Back   Super Soaker Central > Water guns > Community
User Name
Password
Register FAQ Members List Calendar Mark Forums Read


Welcome to the SSC Forums! You are currently viewing our boards as a guest which gives you limited access. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and more. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact us.
Reply
 
Thread Tools
Old 03-08-2008, 10:08 AM   #1
isoaker_com
Super Moderator
 
isoaker_com's Avatar
 
Join Date: Oct 2004
Location: Somewhere
Posts: 250
UserID: 301
Default WaterWarfare.com Hacked Again!?

Despite Ben's valiant efforts thusfar at removing malicious code some spam bot has been inserting into WWc's forums, it seems like the problem continues to return.

Sadly, WWc has been hacked again (same doiop.com link inserted). Not sure if anyone knows how the bot is managing to insert something into the scripts. That said, until that board is patched and security tightened, I do not presently recommend using that site unless you have Ad-Block up and running, verifying that no weird links or scripts are being loaded while browsing that board.

__________________
:: Leave NO one dry! :: iSoaker.com ::
isoaker_com is offline   Reply With Quote
Old 03-08-2008, 12:12 PM   #2
Silence
Administrator
 
Silence's Avatar
 
Join Date: Apr 2006
Location: Virginia
Posts: 3,246
UserID: 576
Default Re: WaterWarfare.com Hacked Again!?

Hmm...we could:
1) Just update the forums frequently.
2) Research how the attacks are being made.
3) Experiment ourselves - suspends logins, etc. to see if that's how the crackers are entering.

But all of those sound tedious.

NoScript doesn't show any scripts on the site...I'm not sure how AdBlock Plus handles scripts though, since it's in the background much more than NoScript is. Both Firefox extensions do block spammy scripts and ads, though.
__________________
Forum Rules
Silence is offline   Reply With Quote
Old 03-16-2008, 09:39 AM   #3
isoaker_com
Super Moderator
 
isoaker_com's Avatar
 
Join Date: Oct 2004
Location: Somewhere
Posts: 250
UserID: 301
Default Re: WaterWarfare.com Hacked Again!?

Looks like DX's account on WWc has been compromised. Either that or DX is now calling himself an egyptian hacker on WWc. O_o Granted, might have been done through a funky SQL injection and not actually by accessing DX's account, but it's hard to tell.

__________________
:: Leave NO one dry! :: iSoaker.com ::
isoaker_com is offline   Reply With Quote
Old 03-16-2008, 10:25 AM   #4
Silence
Administrator
 
Silence's Avatar
 
Join Date: Apr 2006
Location: Virginia
Posts: 3,246
UserID: 576
Default Re: WaterWarfare.com Hacked Again!?

Look at DX's profile. It says he was last active yesterday at 11:29 PM (EDT), the exact same time he made that post. Somebody definitely got his account.
__________________
Forum Rules
Silence is offline   Reply With Quote
Old 03-16-2008, 10:47 AM   #5
Ben
Founder
 
Ben's Avatar
 
Join Date: Mar 2003
Location: Maryland
Posts: 5,974
UserID: 1
Default Re: WaterWarfare.com Hacked Again!?

I assume that this guy injected a new password into the database. The passwords are encrypted, so he couldn't have figured out the password easily.

I've shut the board down at least semi-permanently. I would make an SQL backup, but only the root admin (DX) can do that. I might inject a new password myself to do that...

By the way, the IP address of the offender was 41.235.177.119. I checked here and he didn't register. He had to register at WWC to do the attack however, as I suspected. His username was frankneshtayen.
__________________
email: ben at sscentral dot org / Forum rules

Read this page before emailing me.

Do not send me a PM or email with a water gun question if someone else could answer the question. Post at the forums. You will get a response from me along with others' views or ideas.

Do not send me a PM or email about reading a certain post unless it's been a few days since you've posted. I try to read every post.
Ben is offline   Reply With Quote
Old 03-16-2008, 01:59 PM   #6
Silence
Administrator
 
Silence's Avatar
 
Join Date: Apr 2006
Location: Virginia
Posts: 3,246
UserID: 576
Default Re: WaterWarfare.com Hacked Again!?

Wow...his IP address really does point to Egypt. You may as well ban any new members with Egypt IPs until we get the matter resolved. Since WWc is so inactive, I doubt we'll get any legit new users until then.

Also, frankneshtayen obviously didn't do the earlier hacks. He just joined, plus his message was neither malicious nor opportunistic.
__________________
Forum Rules
Silence is offline   Reply With Quote
Old 03-16-2008, 02:26 PM   #7
CROC
Senior Member
 
CROC's Avatar
 
Join Date: Mar 2006
Location: Ontario, Canada (GTA)
Posts: 287
UserID: 569
Default Re: WaterWarfare.com Hacked Again!?

The forums are down again. I'm guessing this is due to the recent discovery, right?

Off topic:
Is Extrawater vulnerable to SQL, or is it the old isoaker forum and WWC?
__________________
~CROC~(c 'rock)n.
-The master of ideas, and the occasional mod (Works with mr. dude)
Mods: 3xA combat - CPS Turbine - Super Flash Flood - (working on CPH)
CROC is offline   Reply With Quote
Old 03-16-2008, 03:14 PM   #8
Ben
Founder
 
Ben's Avatar
 
Join Date: Mar 2003
Location: Maryland
Posts: 5,974
UserID: 1
Default Re: WaterWarfare.com Hacked Again!?

SQL is a database language. If your website does not use SQL, there is no reason to be alarmed.

At first I thought the old iSoaker.com forum was prone to SQL injection attacks, but after trying to set my post count to one more to see if I knew how to, I found out that they later updated it to fix the problem. You can break the query on Ikonboard, but you can't put any new query in.

WWC is prone to them in a few spots and I could fix them, but I don't have FTP access. Until then, I will keep the board offline. I might reopen it but with no registrations, but it's not being used by anyone except for hackers, so I thought it would be best to shut it down.
__________________
email: ben at sscentral dot org / Forum rules

Read this page before emailing me.

Do not send me a PM or email with a water gun question if someone else could answer the question. Post at the forums. You will get a response from me along with others' views or ideas.

Do not send me a PM or email about reading a certain post unless it's been a few days since you've posted. I try to read every post.

Last edited by Ben : 03-16-2008 at 03:20 PM.
Ben is offline   Reply With Quote
Old 03-16-2008, 03:44 PM   #9
Silence
Administrator
 
Silence's Avatar
 
Join Date: Apr 2006
Location: Virginia
Posts: 3,246
UserID: 576
Default Re: WaterWarfare.com Hacked Again!?

Extrawater itself isn't vulnerable. IPB 1.3, which InvisionFree runs, does use databases, but it likely isn't vulnerable. I'm fairly sure IPS must have plugged in the holes by the time they were done with v1.
__________________
Forum Rules
Silence is offline   Reply With Quote
Old 03-16-2008, 04:54 PM   #10
CROC
Senior Member
 
CROC's Avatar
 
Join Date: Mar 2006
Location: Ontario, Canada (GTA)
Posts: 287
UserID: 569
Default Re: WaterWarfare.com Hacked Again!?

What I meant was:

Is the forum vulnerable to an SQL injection like at WWC?
__________________
~CROC~(c 'rock)n.
-The master of ideas, and the occasional mod (Works with mr. dude)
Mods: 3xA combat - CPS Turbine - Super Flash Flood - (working on CPH)
CROC is offline   Reply With Quote
Old 03-16-2008, 05:36 PM   #11
Silence
Administrator
 
Silence's Avatar
 
Join Date: Apr 2006
Location: Virginia
Posts: 3,246
UserID: 576
Default Re: WaterWarfare.com Hacked Again!?

Your forums are hosted by InvisionFree, which uses IPB 1.3. As I said, I don't know for sure, but I'm guessing there aren't any big holes where they forgot to filter out malicious code from input. If you want a solid answer, then no, your forums aren't vulnerable.
__________________
Forum Rules
Silence is offline   Reply With Quote
Old 03-16-2008, 05:58 PM   #12
Ben
Founder
 
Ben's Avatar
 
Join Date: Mar 2003
Location: Maryland
Posts: 5,974
UserID: 1
Default Re: WaterWarfare.com Hacked Again!?

Here's another weird twist: someone tried to recover my password. I'd post the IP address, but the person was using a proxy and it wouldn't help. I'm trying to log into the admin CP, but it appears they did something to change my password now. I will have to use the security flaws in IPB to continue now. If anyone (Adrian) has access, please check this out.

Edit: Okay, I've reset my password and I'm back now. I do not know what else happened at WWC while I was gone. I've disabled registration now as another precaution.
__________________
email: ben at sscentral dot org / Forum rules

Read this page before emailing me.

Do not send me a PM or email with a water gun question if someone else could answer the question. Post at the forums. You will get a response from me along with others' views or ideas.

Do not send me a PM or email about reading a certain post unless it's been a few days since you've posted. I try to read every post.

Last edited by Ben : 03-16-2008 at 06:05 PM.
Ben is offline   Reply With Quote
Old 03-16-2008, 07:29 PM   #13
Silence
Administrator
 
Silence's Avatar
 
Join Date: Apr 2006
Location: Virginia
Posts: 3,246
UserID: 576
Default Re: WaterWarfare.com Hacked Again!?

Check poly's profile...I can't get the IP address (or anything else, for that matter) unless it's from a post. Funny...3 registrations in as many days for a very inactive site.
__________________
Forum Rules
Silence is offline   Reply With Quote
Old 03-16-2008, 08:02 PM   #14
Ben
Founder
 
Ben's Avatar
 
Join Date: Mar 2003
Location: Maryland
Posts: 5,974
UserID: 1
Default Re: WaterWarfare.com Hacked Again!?

I already did. He seems legit. At this point, there's nothing else we can do to prevent hack attacks. You can only log in if you're an administrator. You can register, but I have to check it over. Hopefully this will deter the hack attacks.

The entire thing is weird. I'm wondering if WWC was posted on some hacker board and they wanted to deface it or something. Luckily we had some protections in place at that time.
__________________
email: ben at sscentral dot org / Forum rules

Read this page before emailing me.

Do not send me a PM or email with a water gun question if someone else could answer the question. Post at the forums. You will get a response from me along with others' views or ideas.

Do not send me a PM or email about reading a certain post unless it's been a few days since you've posted. I try to read every post.
Ben is offline   Reply With Quote
Old 03-17-2008, 11:36 AM   #15
CROC
Senior Member
 
CROC's Avatar
 
Join Date: Mar 2006
Location: Ontario, Canada (GTA)
Posts: 287
UserID: 569
Default Re: WaterWarfare.com Hacked Again!?

I found an SQL injection prevention thing. If you understand it, it might help the forums at WWC
http://www.tizag.com/mysqlTutorial/m...-injection.php
__________________
~CROC~(c 'rock)n.
-The master of ideas, and the occasional mod (Works with mr. dude)
Mods: 3xA combat - CPS Turbine - Super Flash Flood - (working on CPH)
CROC is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT -5. The time now is 05:26 AM.


Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 2.2.2
Copyright ©2003 - 2008 The Super Soaker Central project