Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 06-09-2005, 12:58 AM   #1
Merrioc
Confirmed User
 
Join Date: Jul 2003
Posts: 249
hacked, can't prosecute but can I sue?

I will keep this brief someone hacked one of our servers and proceeded to delete the entire file system. I have filed a police report, but after meeting with the computer crimes division I was told I have no case since the IP of the attacker was from Intuit Inc corporate office in California (I am in California also) and could be ?anyone?. Though I have pounds of circumstantial information (all logging was done through NFS to a different box), I can?t prove ?who? was at the terminal when it occurred. I was put out of business by this action as well as destroyed year?s worth of work (don?t tell me about backups this WAS the backups). The police informed me that I may have a civil case. Suggestions? Lawyer recommendations?
Merrioc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:02 AM   #2
LiveDose
Show Yer Tits!
 
LiveDose's Avatar
 
Industry Role:
Join Date: Feb 2002
Location: Somewhere Out there...
Posts: 25,792
Kill the fucker.

No, seriously.
LiveDose is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:02 AM   #3
NTSS
Confirmed User
 
Join Date: Mar 2005
Location: Da Hood
Posts: 5,688
If the police investigate thoroughly, they should be able to find out exactly who did it. Sounds like they are not up to the task.
__________________
ICQ: 150-803-430
Email: marketing7(at)cox(dot)net
NTSS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:05 AM   #4
wdsguy
Ryde or Die
 
Industry Role:
Join Date: Dec 2002
Location: California-Shanghai
Posts: 19,568
you are screwed if they can't figured out who it is. Most likely the hacker was at a remote location and went through the attacking box.
wdsguy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:07 AM   #5
naitirps
Confirmed User
 
Join Date: May 2004
Location: ...
Posts: 761
My guess is a box at intuit was compromised and was just used as a route... also, the intuit box is already destroyed or cleaned most likely. do a reverse on it, or a trace, try to determine if its a core file system box of theirs such as a mail server or something of that sort... chances are it was compromised as well.

sucks bro, sorry for your loss - how did they get in?
__________________
Programmer
ICQ 44035273 | AIM spritwork | Email spritian at spritian dot com
naitirps is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:11 AM   #6
wdsguy
Ryde or Die
 
Industry Role:
Join Date: Dec 2002
Location: California-Shanghai
Posts: 19,568
have you tried contacting the Intuit system administrators for help on this? they might have some logs that might be helpful. If this was a backup machine, why was it connected to the net?
wdsguy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:11 AM   #7
Merrioc
Confirmed User
 
Join Date: Jul 2003
Posts: 249
In orange county California there is 1 (yes one) electronics crimes investigator. There is nothing to investigate. I know who did it (it was my former webmaster) he had a backdoor acct I was unaware of. I know he consulted to intuit at the time in question. I also was hosting his girls personal site. Basically it went down like this. His home PC logged into the FTP deleted her info (1 day before he had copied it to another server again its in the logs) went to lunch came back logged in again, copied the DB, logged out. Then only hit to her site that day not from his home IP, was the one hit from the intuit ip. 57 second later he logged in via ssh on the same intuit IP and did a rm ?rf / sudo command. There were no failed attempts at any point from the ip. It wasn?t brute force, and he used the extra acct that shouldn?t have been there.
Merrioc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:14 AM   #8
Merrioc
Confirmed User
 
Join Date: Jul 2003
Posts: 249
Quote:
Originally Posted by wdsguy
have you tried contacting the Intuit system administrators for help on this? they might have some logs that might be helpful. If this was a backup machine, why was it connected to the net?
I was in the process of consolidating and moving all my webservers. I had 6 servers at different datacenters around the country, I got a sweet hosting deal and was centralizing my servers. All the sites, DB, applications were being copied to this 1 box, which was the new box at the new datacenter, and was going to be the backup box. This happend litterally RIGHT after I had just finished the last server transfer.
Merrioc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:14 AM   #9
Alky
Confirmed User
 
Alky's Avatar
 
Join Date: Apr 2002
Location: Houston
Posts: 5,651
lol.... i dont get it... dont tell you to backup because they were the backups, but you had all the logs mirrored onto another server. seems like your priorities were a little screwed
Alky is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:16 AM   #10
Merrioc
Confirmed User
 
Join Date: Jul 2003
Posts: 249
Quote:
Originally Posted by wdsguy
have you tried contacting the Intuit system administrators for help on this? they might have some logs that might be helpful. If this was a backup machine, why was it connected to the net?
the system is 3 hops down on there IP block, possibly a server, but again, he did custom dev for them at that time frame so he was working on the server, I doubt it was a compromised box.

as far as the logs; no I just finally met with the Investigator today and I didn't want to contact them tell I knew if the police were gonna do anything or if I had a civil case.
Merrioc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:21 AM   #11
Merrioc
Confirmed User
 
Join Date: Jul 2003
Posts: 249
Quote:
Originally Posted by Alky
lol.... i dont get it... dont tell you to backup because they were the backups, but you had all the logs mirrored onto another server. seems like your priorities were a little screwed
my god Alky your right... well that just solves all my problems I feel so much better now.
Merrioc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:22 AM   #12
kernelpanic
Too lazy to set a custom title
 
Join Date: Jan 2005
Posts: 2,961
With that kind of police statement, you won't have grounds.
kernelpanic is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:45 AM   #13
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
if he only did rm -rf / it should be possible to recover all the data by the way...
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:54 AM   #14
Merrioc
Confirmed User
 
Join Date: Jul 2003
Posts: 249
police took the drive as 'evidence'
also it was a ReiserFS file sys not ext2/3 don't know how to recover it. If it was ext3 yea easy

sudo: merrioc : TTY=pts/4 ; PWD=/ ; USER=root ; COMMAND=/bin/rm -rfd

Last edited by Merrioc; 06-09-2005 at 01:55 AM..
Merrioc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 02:09 AM   #15
stev0
Confirmed User
 
stev0's Avatar
 
Join Date: Aug 2003
Location: Calgary, Alberta
Posts: 6,801
Someone hacked my server and replaced all of my links with their CeCash affiliate liniks a while back... I reported it, but unfortunately I never heard back...
stev0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 02:44 AM   #16
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
If he was in the United States (and still is) hit me up at v[at]weasel.net. I can be of help to you.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 02:46 AM   #17
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
BTW, I am kinda fucked up right now, I will get back to you in the morning or afternoon PST
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:16 PM   #18
SpikeTheJock
Registered User
 
Join Date: May 2005
Posts: 26
My site got hacked once - some hacking group from Brazil deleted all the content.
SpikeTheJock is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:21 PM   #19
decrypted
Confirmed User
 
Join Date: Dec 2004
Location: future-assassin.com
Posts: 370
google iptables and deny ssh from anyone except ur ip
__________________

Konrad - ICQ 59416956
decrypted is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:30 PM   #20
buddyjuf
Guest
 
Posts: n/a
really sorry to hear what happened dude
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:35 PM   #21
BukkakeBrown
Confirmed User
 
Join Date: Oct 2003
Location: Florida
Posts: 734
that sucks dude, i know how it feels
__________________
We are the only "Napster of Porn" and
we convert at 1:20 Test out promoting
us to your mainstream, adult and email
traffic, you will love promoting us!
BukkakeBrown is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:41 PM   #22
FilthyRob
Confirmed User
 
Join Date: Feb 2004
Location: Anaheim - CA
Posts: 6,741
That sucks dude! I feel like I am hacking myself today. I have deleted 1000's of my own pages.
__________________
AKA - Clubsexy
FilthyRob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 01:49 PM   #23
mikeyddddd
Viva la vulva!
 
mikeyddddd's Avatar
 
Join Date: Mar 2003
Location: you can't please everyone, so you got to please yourself
Posts: 16,557
Sure you can sue. Remember OJ? He was found innocent in criminal court, but liable in civil court.
mikeyddddd is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 02:27 PM   #24
iwantchixx
Too lazy to set a custom title
 
iwantchixx's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: The Boonies
Posts: 12,860
worst part is, if you went and punched the fucker the cops would be right there toa rrest you.

The law is fucked up sometimes. It doesn't take internet business seriously unless it's a fortune 500 company.
iwantchixx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 02:28 PM   #25
kernelpanic
Too lazy to set a custom title
 
Join Date: Jan 2005
Posts: 2,961
Quote:
Originally Posted by Merrioc
police took the drive as 'evidence'
also it was a ReiserFS file sys not ext2/3 don't know how to recover it. If it was ext3 yea easy

sudo: merrioc : TTY=pts/4 ; PWD=/ ; USER=root ; COMMAND=/bin/rm -rfd
Get the drive back from the cops and take it to data recovery specialists. Provided the cops didn't fuck it up, you can get most of the data back
kernelpanic is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 02:35 PM   #26
warlock5
Confirmed User
 
warlock5's Avatar
 
Join Date: Jan 2004
Location: Uranus
Posts: 2,808
Does he have any assets you can go after?
warlock5 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-09-2005, 03:23 PM   #27
Merrioc
Confirmed User
 
Join Date: Jul 2003
Posts: 249
I don't want to go after him, I want to go after intuit since it was there IP on an ADSL line (so I REALLY doubt its a server)...

I don't really care about him, he doesn't have enough asset to be worth my time... I got his best asset anyhow... his girl
Merrioc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.