Clan x86

General Forums => General Discussion => Topic started by: Newby on December 01, 2005, 10:25:24 PM

Title: Uh...
Post by: Newby on December 01, 2005, 10:25:24 PM
Why is my name N00bie? Which one of you sick admin fuckers did this? :P
Title: Re: Uh...
Post by: MyndFyre on December 01, 2005, 10:26:40 PM
Evidently we've all also been taken off of admin?
Title: Re: Uh...
Post by: Newby on December 01, 2005, 10:27:15 PM
Yeah. iago stop being gay, just beacuse we set your face as favicon means nothing. :-*

EDIT -- Hmm, how about just giving us admin and/or x86 back? :O
Title: Re: Uh...
Post by: Joe on December 01, 2005, 10:28:46 PM
I hope this doesn't have anything to do with me telling Topaz to go away.
Title: Re: Uh...
Post by: Newby on December 01, 2005, 10:29:20 PM
Quote from: Joe[e2] on December 01, 2005, 10:28:46 PM
I hope this doesn't have anything to do with me telling Topaz to go away.

Topaz can't hack, lol.
Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 10:29:42 PM
Me too... I didn't change my name either...

QuoteOMgZ!11!1 I wuz HaxxED!@!

Haha...
Title: Re: Uh...
Post by: Joe on December 01, 2005, 10:31:16 PM
look at me im untouchable GG.
Title: Re: Uh...
Post by: Newby on December 01, 2005, 10:31:29 PM
Quote from: Sigh Dough on December 01, 2005, 10:29:42 PM
Me too... I didn't change my name either...

QuoteOMgZ!11!1 I wuz HaxxED!@!

Haha...

Hmm, iago has a sick sense of humor. That almost sounds as dumb as something a "blackhat" would say.
Title: Re: Uh...
Post by: Joe on December 01, 2005, 10:33:16 PM
/me adds to the confusion.

EDIT -
Crap, it didn't work. =(
Title: Re: Uh...
Post by: Newby on December 01, 2005, 10:34:01 PM
Quote from: Joe[e2] on December 01, 2005, 10:33:16 PM
/me adds to the confusion.

Considering the path of actions taken thus far, whoever is doing this (I suspect quik now) doesn't care about anyone outside of administrators. :P
Title: Re: Uh...
Post by: Furious on December 01, 2005, 10:35:04 PM
Very odd situation :/
Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 10:37:08 PM
Quote from: N00bee on December 01, 2005, 10:31:29 PM
Quote from: Sigh Dough on December 01, 2005, 10:29:42 PM
Me too... I didn't change my name either...

QuoteOMgZ!11!1 I wuz HaxxED!@!

Haha...

Hmm, iago has a sick sense of humor. That almost sounds as dumb as something a "blackhat" would say.
Quote from: N00bee on December 01, 2005, 10:34:01 PM
Quote from: Joe[e2] on December 01, 2005, 10:33:16 PM
/me adds to the confusion.

Considering the path of actions taken thus far, whoever is doing this (I suspect quik now) doesn't care about anyone outside of administrators. :P

I'm not an admin.  O_o
Title: Re: Uh...
Post by: Newby on December 01, 2005, 10:37:42 PM
Quote from: Sigh Dough on December 01, 2005, 10:37:08 PM
I'm not an admin.  O_o

Well, you were a global mod...
Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 10:38:46 PM
Quote from: N00bee on December 01, 2005, 10:37:42 PM
Well, you were a global mod...

Oh, that's right.  This is rather strange.  :\
Title: Re: Uh...
Post by: Joe on December 01, 2005, 10:46:41 PM
Quote from: Sigh Dough on December 01, 2005, 10:38:46 PM
Quote from: N00bee on December 01, 2005, 10:37:42 PM
Well, you were a global mod...

Oh, that's right. [...]

Wow, you're really depressed about losing it, aren't you? =p
Title: Re: Uh...
Post by: Newby on December 01, 2005, 10:48:39 PM
Quote from: Joe[e2] on December 01, 2005, 10:46:41 PM
Quote from: Sigh Dough on December 01, 2005, 10:38:46 PM
Quote from: N00bee on December 01, 2005, 10:37:42 PM
Well, you were a global mod...

Oh, that's right. [...]

Wow, you're really depressed about losing it, aren't you? =p

Right now, there's bigger issues to be concerned with. Like, who did this, and if they still have access, and if it was even a breach of security. I think it was just a leader (drunk) who decided to have fun.

Though, whoever did it should realize that there's no way to get admin back now.
Title: Re: Uh...
Post by: Joe on December 01, 2005, 10:52:36 PM
Until iago gets home theres not much we can do except sit-and-spin. Perhaps you should call him?
Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 10:53:17 PM
Quote from: Joe[e2] on December 01, 2005, 10:46:41 PM
Wow, you're really depressed about losing it, aren't you? =p

I never really knew I had it.  I thought being able to moderate all boards was a privilege of being a member.  Guess I was wrong, though.  :P
Title: Re: Uh...
Post by: Newby on December 01, 2005, 10:54:00 PM
Quote from: Joe[e2] on December 01, 2005, 10:52:36 PM
Until iago gets home theres not much we can do except sit-and-spin. Perhaps you should call him?

I tried. His phone is off.

Eh, I guess we can wait... fuck.
Title: Re: Uh...
Post by: Furious on December 01, 2005, 10:54:09 PM
Quote from: N00bee on December 01, 2005, 10:48:39 PM
Quote from: Joe[e2] on December 01, 2005, 10:46:41 PM
Quote from: Sigh Dough on December 01, 2005, 10:38:46 PM
Quote from: N00bee on December 01, 2005, 10:37:42 PM
Well, you were a global mod...

Oh, that's right. [...]

Wow, you're really depressed about losing it, aren't you? =p

Right now, there's bigger issues to be concerned with. Like, who did this, and if they still have access, and if it was even a breach of security. I think it was just a leader (drunk) who decided to have fun.

Though, whoever did it should realize that there's no way to get admin back now.

I doubt it was a "leader", drunk or not, if you noticed:

QuoteOMgZ!11!1 I wuz HaxxED!@!

Is at the end of most of the mod's / admin's signature, looks like someone was trying to make a point?
Title: Re: Uh...
Post by: Newby on December 01, 2005, 10:57:18 PM
Quote from: Furious on December 01, 2005, 10:54:09 PM
I doubt it was a "leader", drunk or not, if you noticed:

QuoteOMgZ!11!1 I wuz HaxxED!@!

Is at the end of most of the mod's / admin's signature, looks like someone was trying to make a point?

Could be a sick minded joke.

I'm leaning towards an exploit run against darkside, seeing as how it has many users (mysql && unix accounts) and services running.
Title: Re: Uh...
Post by: iago on December 01, 2005, 10:59:50 PM
Haha, you guys are weird.  I'm going to go back to doing homework, and I'll assume it'll be fixed :)

<edit>
Come to think of it, hmm @ error logs, pages and pages of:

Quote............
Dec  1 18:30:13 darkside ftpd[11586]: [ID 214291 daemon.notice] FTP LOGIN REFUSED (ftp not in /etc/passwd) FROM S0106000f3d4eeba9.sc.cable.net [24.79.140.178], anonymous
Dec  1 18:30:15 darkside ftpd[11587]: [ID 214291 daemon.notice] FTP LOGIN REFUSED (ftp not in /etc/passwd) FROM S0106000f3d4eeba9.sc.cable.net [24.79.140.178], anonymous
Dec  1 18:30:15 darkside ftpd[11588]: [ID 214291 daemon.notice] FTP LOGIN REFUSED (ftp not in /etc/passwd) FROM S0106000f3d4eeba9.sc.cable.net [24.79.140.178], anonymous
..........
.. and so on.

The odd part is, I've never run FTP on any of my computers. A Mystery!
Title: Re: Uh...
Post by: Joe on December 01, 2005, 11:05:16 PM
CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP! CONTACT HIS ISP!

EDIT -
And while we're at it, it wasn't us. Fix it please.
Title: Re: Uh...
Post by: MyndFyre on December 01, 2005, 11:06:17 PM
OMG Joe, the lack of moderation and stuff is no excuse to start spamming.
Title: Re: Uh...
Post by: deadly7 on December 01, 2005, 11:08:24 PM
QuoteLocation: Canada [City: Vancouver, British Columbia]

NOTE: More information appears to be available at ZS178-ARIN.


OrgName:    Shaw Communications Inc.
OrgID:      SHAWC
Address:    Suite 800
Address:    630 - 3rd Ave. SW
City:       Calgary
StateProv:  AB
PostalCode: T2P-4L4
Country:    CA

ReferralServer: rwhois://rs1so.cg.shawcable.net:4321

NetRange:   24.76.0.0 - 24.79.255.255
CIDR:       24.76.0.0/14
NetName:    SHAW-COMM
NetHandle:  NET-24-76-0-0-1
Parent:     NET-24-0-0-0-0
NetType:    Direct Allocation
NameServer: NS2SO.CG.SHAWCABLE.NET
NameServer: NS1SO.CG.SHAWCABLE.NET
Comment:    ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate:    2000-12-15
Updated:    2003-06-20

OrgAbuseHandle: SHAWA-ARIN
OrgAbuseName:   SHAW ABUSE
OrgAbusePhone:  +1-403-750-7420
OrgAbuseEmail:  **************@sjrb.ca

OrgTechHandle: ZS178-ARIN
OrgTechName:   Shaw High-Speed Internet
OrgTechPhone:  +1-403-750-7428
OrgTechEmail:  *******@sjrb.ca

# ARIN WHOIS database, last updated 2005-12-01 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
Also myndy, you're still in the x86 group, you could hit the "delete button". All members are mods of Gen Discussion.
Title: Re: Uh...
Post by: iago on December 01, 2005, 11:10:35 PM
Great! He's somewhere in Canada!

btw, anybody know what this means?

Dec  1 19:48:18 darkside dtlogin[15760]: [ID 699796 user.error] sunray_get_user:pam_sm_auth: pam_get_user returned 6 (PAM_CONV_ERR)
Dec  1 19:48:18 darkside dtlogin[15760]: [ID 699796 user.error] sunray_get_user:pam_sm_auth: pam_get_user returned 6 (PAM_CONV_ERR)
Dec  1 19:51:06 darkside dtlogin[8975]: [ID 699796 user.error] sunray_get_user:pam_sm_auth: pam_get_user returned 6 (PAM_CONV_ERR)
Dec  1 19:51:06 darkside dtlogin[8975]: [ID 699796 user.error] sunray_get_user:pam_sm_auth: pam_get_user returned 6 (PAM_CONV_ERR)

Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 11:12:20 PM
Not really, but here's a nice man page (http://uw714doc.sco.com/en/man/html.X1/dtlogin.X1.html) for dtlogin.  Looks bad :\
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:13:04 PM
Quote from: deadly7 on December 01, 2005, 11:08:24 PM
Also myndy, you're still in the x86 group, you could hit the "delete button". All members are mods of Gen Discussion.

I can't seem to moderate.... can you?
Title: Re: Uh...
Post by: Joe on December 01, 2005, 11:14:10 PM
Client didn't want to send password, according to google.
Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 11:14:39 PM
Quote from: N00bee on December 01, 2005, 11:13:04 PM
I can't seem to moderate.... can you?

Nope, no go.  I've been removed from the Global Moderator group, it seems...
Title: Re: Uh...
Post by: deadly7 on December 01, 2005, 11:16:00 PM
Sunray is something that's designed to help against hacking and theft of information and stuff on the computer.. do you have it installed?

And someone tried to login to darkside with those ID's mentioned and got an error with an authorization, and it returned a packet to them.  I don't know what the packet said though.. I've never seen PAM_CONV_ERR before. I'm assuming it's PAM(what is PAM* on your computer iago) Conversation Error.. and it probably returned some info that the exploiter needed.

Edit: iago, what versions of:
Apache
mySQL
PHP

are you running?
Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 11:18:12 PM
I know he's running 1.3.33 Apache.  I don't know about MySQL or PHP, but I'd guess 4.4.0+ for PHP.
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:20:57 PM
What. the. fuck?
Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 11:21:35 PM
Fucking shit... theme just changed on me.  You guys?

Nevermind, just took a look.  Default Theme is changed...

Quote from: Yaago on December 01, 2005, 09:07:47 PM
There's no real reason to upgrade to 1.3.34.  They fixed a "vulnerability" that could lead to http smuggling attacks or something stupid.  Nothing I'm worried about :)

Maybe it's something he should have worried about? :(
Title: Re: Uh...
Post by: deadly7 on December 01, 2005, 11:21:45 PM
beautiful, it was PHC..
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:22:46 PM
Uh...
Title: Re: Uh...
Post by: iago on December 01, 2005, 11:23:21 PM
Ok, I need to get some homework done and go to bed.  For the time being:

- There are no odd services listening or connections established.  But that doesn't mean anything.
- I've changed the root password, but I don't believe that he ever got access to root.
- I've changed the MySQL password (you might have noticed the authentication failure). 
- I've hacked the SMF board to give myself administrator-type power.  I don't have time to muck around with names and stuff tonight, maybe later.  If you're nice.
- I've disconnected everybody who had an active connection.

For everything else, I'm going to leave it as business as usual.  I can't tell what happened, so there's no sense in closing the gate after the horse escaped. 

To be continued...
Title: Re: Uh...
Post by: deadly7 on December 01, 2005, 11:24:44 PM
It was PHC.
When i had gone to http://www.x86labs.org/forum/ a second ago it said "PHC OWNED YOU" in the corner with no images or anything.
Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 11:25:21 PM
Yep, it said "Oh my goddess, it's a Phrack High Council"
Title: Re: Uh...
Post by: iago on December 01, 2005, 11:26:23 PM
Everything should be ok now.  I'm reasonably sure he didn't have root, and the passwords have been changed.  I doubt whoever did it had the presense of mind to leave a backdoor.  I'll look into it tomorrow.

Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 11:27:33 PM
Quote from: iago on December 01, 2005, 11:26:23 PM
Everything should be ok now.  I'm reasonably sure he didn't have root, and the passwords have been changed.  I doubt whoever did it had the presense of mind to leave a backdoor.  I'll look into it tomorrow.

Alright, have fun with your homework.
Title: Re: Uh...
Post by: Joe on December 01, 2005, 11:27:49 PM
Quote- I've disconnected everybody who had an active connection.

For the record, my SSH connection is still open.

Also, I'd like to remind you that SQL isn't exposed to the open internet, which means its automatically excluded from being the entry-point of the hacking. It was exploited through something else.
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:28:29 PM
Quote from: Joe[e2] on December 01, 2005, 11:27:49 PM
Quote- I've disconnected everybody who had an active connection.

For the record, my SSH connection is still open.

Also, I'd like to remind you that SQL isn't exposed to the open internet, which means its automatically excluded from being the entry-point of the hacking. It was exploited through something else.

Did you connect after he did it? Perhaps he didn't kill anyone on port 22, seeing as how he had to connect to it via port 22 to do anything.
Title: Re: Uh...
Post by: iago on December 01, 2005, 11:29:22 PM
Quote from: Joe[e2] on December 01, 2005, 11:27:49 PM
Quote- I've disconnected everybody who had an active connection.

For the record, my SSH connection is still open.

Also, I'd like to remind you that SQL isn't exposed to the open internet, which means its automatically excluded from being the entry-point of the hacking. It was exploited through something else.

Don't forget that web apps (like, any programs written in php by anybody on this forum) also have access to MySQL.
Title: Re: Uh...
Post by: deadly7 on December 01, 2005, 11:30:37 PM
 [22:29:48.289] <deadly7[x86]> Hrm.
[22:29:52.385] <deadly7[x86]> Whoever did it had complete access to /forum/
[22:30:02.159] <deadly7[x86]> The mySQL database password is PLAINTEXT in it.
[22:30:09.159] <deadly7[x86]> Which is SMF's fault..
[22:30:15.178] <deadly7[x86]> IPB, LDU, all others don' thave plaintext mysql
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:31:45 PM
Phrack High Council will do anything for you.

Oh boy, good job at halting access to darkside, iago.
Title: Re: Uh...
Post by: Towelie on December 01, 2005, 11:32:03 PM
lol this is wierd. I wonder who did it
Title: Re: Uh...
Post by: iago on December 01, 2005, 11:33:08 PM
Quote from: deadly7 on December 01, 2005, 11:30:37 PM
[22:29:48.289] <deadly7[x86]> Hrm.
[22:29:52.385] <deadly7[x86]> Whoever did it had complete access to /forum/
[22:30:02.159] <deadly7[x86]> The mySQL database password is PLAINTEXT in it.
[22:30:09.159] <deadly7[x86]> Which is SMF's fault..
[22:30:15.178] <deadly7[x86]> IPB, LDU, all others don' thave plaintext mysql


There's nothing wrong with storing plaintext credentials under a locked file.  Unless you enter a password every time you run it, they have to be stored in a recoverable way anyway.  Why bother giving people a false sense of security? If anything, that does more harm than good.
Title: Re: Uh...
Post by: Joe on December 01, 2005, 11:40:05 PM
Joeforums weren't defaced. More secure than SMF. G_G.
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:41:20 PM
Hmm @ phc..
Title: Re: Uh...
Post by: MyndFyre on December 01, 2005, 11:42:03 PM
Quote from: Joe[e2] on December 01, 2005, 11:40:05 PM
Joeforums weren't defaced. More secure than SMF. G_G.
Linux doesn't get viruses written for it for the same reason Joeforums weren't defaced: nobody uses it.

UPDATE:
(http://www.jinxbot.net/pub/phc.jpg)
Hrm.
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:47:17 PM
I got that too.

Well, I got two messages. One said that, one said to point out his name was yellow. :/
Title: Re: Uh...
Post by: Sidoh on December 01, 2005, 11:48:33 PM
That's really weird.

Yeah, I got it too... I was doing homework and I head the Outlook "you have unread messages" noise.
Title: Re: Uh...
Post by: Towelie on December 01, 2005, 11:49:31 PM
who would waste their time on this lol
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:50:22 PM
Quote from: Toweliex86] link=topic=3984.msg42100#msg42100 date=1133498971]
who would waste their time on this lol

Immature kids with nothing better to do.
Title: Re: Uh...
Post by: Towelie on December 01, 2005, 11:53:27 PM
hah, I would much rater do other things. . .  ;D Anyways, what do you plan on doing about it once you find out who it was?
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:55:38 PM
Quote from: Toweliex86] link=topic=3984.msg42102#msg42102 date=1133499207]
hah, I would much rater do other things. . .  ;D Anyways, what do you plan on doing about it once you find out who it was?

We can't do much... maybe just ban the proxy or IP he was on and move on with our lives.

Patch the vulnerabilities too.
Title: Re: Uh...
Post by: Towelie on December 01, 2005, 11:56:52 PM
do you know what he used to hack into here?
Title: Re: Uh...
Post by: MyndFyre on December 01, 2005, 11:58:05 PM
Quote from: Toweliex86] link=topic=3984.msg42107#msg42107 date=1133499412]
do you know what he used to hack into here?
L33T HAX!  :P 
Title: Re: Uh...
Post by: Newby on December 01, 2005, 11:59:07 PM
Quote from: Toweliex86] link=topic=3984.msg42107#msg42107 date=1133499412]
do you know what he used to hack into here?

Probably some script he found on a security board.
Title: Re: Uh...
Post by: Towelie on December 02, 2005, 12:04:05 AM
wow.. I googled Phrack High Council and they seem like mentally challenged people with nothing else better to do but being ass holes
Title: Re: Uh...
Post by: Newby on December 02, 2005, 12:22:07 AM
Well, I'd almost bet money that this is the work of c0n...

My PM box is full of "hono rux".
Title: Re: Uh...
Post by: Sidoh on December 02, 2005, 12:24:18 AM
Quote from: N00bee on December 02, 2005, 12:22:07 AM
Well, I'd almost bet money that this is the work of c0n...

My PM box is full of "hono rux".

We did ban him permanently a while ago... that alone would probably be enough to torque him off.
Title: Re: Uh...
Post by: Sty on December 02, 2005, 12:28:29 AM
Notice no one messed with my name... It's because they (whoever it may be) fears my omfg leet wrath! (Which amounts to nothing)

Anyways, this is quite interesting, I got quite a laugh out of Sigh Dough's name change anyway.
Title: Re: Uh...
Post by: Sidoh on December 02, 2005, 12:43:05 AM
Quote from: Sty on December 02, 2005, 12:28:29 AM
Notice no one messed with my name... It's because they (whoever it may be) fears my omfg leet wrath! (Which amounts to nothing)

Anyways, this is quite interesting, I got quite a laugh out of Sigh Dough's name change anyway.

Haha.  They've only seemed to mess with people who were in the administrator/global moderator groups.
Title: Re: Uh...
Post by: Screenor on December 02, 2005, 02:25:45 AM
To be all out honest, c0n DID IM me the other day mentioning x86 a lot, so ugh. :-\

I don't feel safe with you iago anymore. :(
Title: Re: Uh...
Post by: deadly7 on December 02, 2005, 08:24:26 AM
iago's a horrible serveradmin! :P
Title: Re: Uh...
Post by: Armin on December 02, 2005, 08:38:46 AM
I'm still an admin, check out my members title.
Title: Re: Uh...
Post by: Blaze on December 02, 2005, 08:42:32 AM
You wish. ;-)

I love you guys es es es es new names, you should keep 'em, other then mindfire; thats just plain stupid.
Title: Re: Uh...
Post by: Sidoh on December 02, 2005, 09:25:12 AM
Quote from: Blaze on December 02, 2005, 08:42:32 AM
You wish. ;-)

I love you guys es es es es new names, you should keep 'em, other then mindfire; thats just plain stupid.

I actually thought that was the best one, just because of it's subtlety.
Title: Re: Uh...
Post by: Joe on December 02, 2005, 12:22:29 PM
Sigh.. dough.

Sidoh LOL.

Hm, MyndyFyry, thanks for pointing out the lack of moderation. I only pasted it a couple hundred times for emphasis.

Something I realized last night, but didn't think was serious until now: the icon in the firefox address bar has changed. It looks sorta like a flame, but if I get my eyes closer (it starts hurting), it looks sorta like an animated dude with a large nose.
Title: Re: Uh...
Post by: Hitmen on December 02, 2005, 12:48:46 PM
iago, stop messing with them and just admit you were fucking with them already :)
Title: Re: Uh...
Post by: Sidoh on December 02, 2005, 12:58:28 PM
This doesn't seem much like an iago joke to me...
Title: Re: Uh...
Post by: MyndFyre on December 02, 2005, 01:24:37 PM
Quote from: Sigh Dough on December 02, 2005, 12:58:28 PM
This doesn't seem much like an iago joke to me...
To quote Quik (or Kwick, whichever), iago doesn't know how to have fun.  :P
Title: Re: Uh...
Post by: Super_X on December 02, 2005, 03:29:56 PM
Quote from: Sigh Dough on December 02, 2005, 12:58:28 PM
This doesn't seem much like an iago joke to me...

Well, if you look at the shakespearian refrence in his name, it almost seems like an iago (Othello) joke, or prank of sorts.
Title: Re: Uh...
Post by: Sidoh on December 02, 2005, 03:31:22 PM
Quote from: Super_X on December 02, 2005, 03:29:56 PM
Well, if you look at the shakespearian refrence in his name, it almost seems like an iago (Othello) joke, or prank of sorts.

His name has no representation of his intentions.
Title: Re: Uh...
Post by: Super_X on December 02, 2005, 03:37:53 PM
Well, maybe he got the idea (assuning he did it.) from his name.
Title: Re: Uh...
Post by: Sidoh on December 02, 2005, 03:53:48 PM
Quote from: Super_X on December 02, 2005, 03:37:53 PM
Well, maybe he got the idea (assuning he did it.) from his name.

Just because he derived his name from a character that would do something this sly does not mean he himself would do such a thing; this is a silly argument.
Title: Re: Uh...
Post by: Super_X on December 02, 2005, 03:56:23 PM
<3 Yeah it is a silly argument, but it was fun. <33 I win.
Title: Re: Uh...
Post by: Sidoh on December 02, 2005, 03:58:16 PM
Quote from: Super_X on December 02, 2005, 03:56:23 PM
I win.

Nu uh.
Title: Re: Uh...
Post by: Joe on December 02, 2005, 05:31:01 PM
Nuh*, I win.
Title: Re: Uh...
Post by: Quik on December 02, 2005, 06:49:43 PM
Actually, the name iago comes from the days when he was into backstabbing: he found it funny that ignorant Battle.net kiddies didn't see his name and realize he was going to backstab them from the beginning.
Title: Re: Uh...
Post by: Blaze on December 02, 2005, 07:16:00 PM
I wish I could do a backstab with him....  :(

btw, someone want to do a bs run?
Title: Re: Uh...
Post by: GameSnake on December 02, 2005, 07:38:02 PM
How the hell is this topic this big?
Title: Re: Uh...
Post by: MyndFyre on December 02, 2005, 07:43:37 PM
Sure, you don't care about being haxxed.
Title: Re: Uh...
Post by: Joe on December 02, 2005, 08:21:59 PM
I just changed my sig. You can too, I suppose? Might be able to change your name too.
Title: Re: Uh...
Post by: GameSnake on December 02, 2005, 10:21:51 PM
Quote from: GameSnake on December 02, 2005, 07:38:02 PM
How the hell is this topic this big?
Seriously where did this topic come from?!
Title: Re: Uh...
Post by: Ergot on December 02, 2005, 10:27:17 PM
From them being h4x0r3d duh :/ I like the new names :)
Title: Re: Uh...
Post by: Towelie on December 02, 2005, 10:34:18 PM
at first I thought Kwick was a new guy:-)
Title: Re: Uh...
Post by: MyndFyre on December 02, 2005, 10:49:23 PM
OK, iago got me back my permissions and I reset the admins.  People should be able to update their names again.  Sidoh should do so :P

If anyone has any problems with anything, please let me know.  The permissions were kind of weird, but I think I got them back to normal.
Title: Re: Uh...
Post by: iago on December 02, 2005, 10:51:22 PM
As MyndFyre said (while I was typing this, *grr*), he straightened everything up.  You can fix your names (Except Sigh Dough.. we alll agree that you should keep that name). 

As far as we can tell, somebody either found out or guessed an Administrator's password on the forum (probably Quik, he's a n00b (kidding)).  We've fixed it so he can't get back in through that route.  Hopefully that's all he did...

Hopefully, it's all back to normal.  I'm still going to dig through some logs and see if I can find out who actually did it.  All I know at this point is that he was going through a proxy, but I might be able to dig up some records on the proxy, who knows?

Stay tuned!
Title: Re: Uh...
Post by: Ergot on December 02, 2005, 10:53:59 PM
I like it as Sigh Dough :). This is better than any movie this year o_o.
Title: Re: Uh...
Post by: Joe on December 02, 2005, 11:03:21 PM
Quote from: MyndFyrex86] link=topic=3984.msg42214#msg42214 date=1133581763]
OK, iago got me back my permissions and I reset the admins. People should be able to update their names again. Sidoh should do so :P

If anyone has any problems with anything, please let me know. The permissions were kind of weird, but I think I got them back to normal.

yeah I'm not moderator of off-topic yet..
Title: Re: Uh...
Post by: iago on December 02, 2005, 11:31:49 PM
Quote from: Joe[e2] on December 02, 2005, 11:03:21 PM
Quote from: MyndFyrex86] link=topic=3984.msg42214#msg42214 date=1133581763]
OK, iago got me back my permissions and I reset the admins. People should be able to update their names again. Sidoh should do so :P

If anyone has any problems with anything, please let me know. The permissions were kind of weird, but I think I got them back to normal.

yeah I'm not moderator of off-topic yet..

Hmm, how'd we miss that?  Well, I'll get right on that. 
Title: Re: Uh...
Post by: iago on December 03, 2005, 02:05:29 PM
Hmm, I was checking up on some things, and I wonder if this might be a problem:

Quote
root@darkside:~# chkrootkit
ROOTDIR is `/'
Checking `amd'... not infected
Checking `basename'... not infected
Checking `biff'... not infected
Checking `chfn'... INFECTED
Checking `chsh'... INFECTED
Checking `cron'... not infected
Checking `date'... INFECTED
Checking `du'... not infected
Checking `dirname'... not infected
Checking `echo'... not infected
Checking `egrep'... not infected
Checking `env'... not infected
Checking `find'... not infected
Checking `fingerd'... not infected
Checking `gpm'... not found
Checking `grep'... not infected
Checking `hdparm'... not found
Checking `su'... not infected
Checking `ifconfig'... not infected
Checking `inetd'... not tested
Checking `inetdconf'... not infected
Checking `identd'... not found
Checking `killall'... not infected
Checking `ldsopreload'... not tested
Checking `login'... not infected
Checking `ls'... INFECTED
Checking `lsof'... not found
Checking `mail'... not infected
Checking `mingetty'... not found
Checking `netstat'... not infected
Checking `named'... not infected
Checking `passwd'... not infected
Checking `pidof'... not found
Checking `pop2'... not found
Checking `pop3'... not found
Checking `ps'... INFECTED
.............. [it goes on like that]

*** WARNING: illegal modifications were made to certain system files, indicative of an infection!!!
*** the infection started between 06 Nov 2005 18:10:00 and 06 Nov 2005 18:30:00
*** BACK UP ALL IMPORTANT DATA AND SHUT DOWN IMMEDIATELY


:-/

Anybody remember what happened on November 6?  It was a long time ago :(
Title: Re: Uh...
Post by: Newby on December 03, 2005, 02:21:01 PM
What happened November 6th? :|
Title: Re: Uh...
Post by: Towelie on December 03, 2005, 02:53:32 PM
no idea, that sucks :-P
Title: Re: Uh...
Post by: Screenor on December 03, 2005, 03:26:13 PM
Ugh, this is a perfect application as to why you do not run porn.wmv.exe.

Nov 6 was about the time BnetAxe was hacked..that's about it. :-\
Title: Re: Uh...
Post by: iago on December 03, 2005, 05:05:35 PM
Hmm, on that day there was a lot of traffic from 207.180.144.222...

Also, I checked up on the proxy that the "pnc" account was using.. I found their logs, an it turns out that 207.180.144.222 was the ip that was posting as phc, so I'm sure it's the same guy.

So I looked up the ip 207.180.144.222 on the forums, and there is one account associated with it: Hitmen

Also, Nov, 6 was the day that Hitmen created his account on this forum. 

Also, Dec. 1 (the day of the "incident") was Hitmen's birthday. 

Now, the problem is, I always thought that the Hitmen I knew was inept.  So how, suddenly, did this happen? 

Your answer is as good as mine..... for the time being, I'm not sure how to proceed...
Title: Re: Uh...
Post by: Newby on December 03, 2005, 05:44:39 PM
Hmm....

Wtf?

Well, I'm gonna ban Hitmen, and have a very long discussion on AIM.
Title: Re: Uh...
Post by: Newby on December 03, 2005, 05:51:52 PM
Quote from: Scr33n0r on December 03, 2005, 03:26:13 PM
Ugh, this is a perfect application as to why you do not run porn.wmv.exe.

Nov 6 was about the time BnetAxe was hacked..that's about it. :-\

Eh, wouldn't affect you in Linux.
Title: Re: Uh...
Post by: Screenor on December 03, 2005, 06:14:41 PM
But why would Hitmen do it? Possibly not the real Hitmen? I don't know him really at all, but he seems a bit more controlled then that.

Also, who does all that then leaves it to be that obvious. Almost as if someone wanted Hitmen gone.
Title: Re: Uh...
Post by: Joe on December 03, 2005, 06:20:38 PM
And whos to say this wasn't meant to be a nice little tap on the shoulder saying "you're not as secure as you think"? We all thought darkside was imbreachable, but aparently he wasn't. If he was a real "blackhat", he would have just deleted the whole database. He distroyed next to nothing, except maybe 30 minutes of MyndFyre's time when he set permissions back.
Title: Re: Uh...
Post by: Warrior on December 03, 2005, 07:22:38 PM
Who is this "We"? Nothing is inbreachable. Maybe you sleep at nighty knowing that but I sure don't.
Title: Re: Uh...
Post by: Blaze on December 03, 2005, 07:40:56 PM
I don't know hitmen very well, but he doesn't seem to be a person to do something stupid like that...
Title: Re: Uh...
Post by: Towelie on December 03, 2005, 08:31:41 PM
Quote from: Scr33n0r on December 03, 2005, 03:26:13 PM
Ugh, this is a perfect application as to why you do not run porn.wmv.exe.

Nov 6 was about the time BnetAxe was hacked..that's about it. :-\
Ok, for one thing, if you dl porn dont open it if its an exe, that is just plain stupid :).
Title: Re: Uh...
Post by: RoMi on December 03, 2005, 09:59:11 PM
What if its like a porn game though? Like pin the tale on the hooker, that ones always a blast.
Title: Re: Uh...
Post by: Blaze on December 03, 2005, 10:14:17 PM
Quote from: RoMi on December 03, 2005, 09:59:11 PM
What if its like a porn game though? Like pin the tale on the hooker, that ones always a blast.
I love you. :)
Title: Re: Uh...
Post by: Joe on December 03, 2005, 11:17:17 PM
@Romi: Then you use a virus scanner first?

@Newby: How do you know iago isn't stupid enough to run a virus in wine? (No offence iago =p)

@Warrior: cave is imbreachable. The only one who has any password to him is me. Its not written down anywhere. Hes not exposed to the internet. Breach please.
Title: Re: Uh...
Post by: Ergot on December 03, 2005, 11:19:38 PM
Cave is not imbreachable. One can easily sit down and guess at it or other methods. The person with the password can always be tortured.
Title: Re: Uh...
Post by: Joe on December 03, 2005, 11:23:40 PM
Then breach it!
Title: Re: Uh...
Post by: Ergot on December 03, 2005, 11:45:12 PM
I can't drive. Just because I can't breach I doesn't mean your neighbor can't.
Title: Re: Uh...
Post by: Joe on December 03, 2005, 11:48:33 PM
I don't think anyone within a mile (probably safe to go further than that) has even heard of Linux.
Title: Re: Uh...
Post by: iago on December 04, 2005, 01:14:51 AM
Quote from: Joe[e2] on December 03, 2005, 11:23:40 PM
Then breach it!

In theory, I could drive to your house, break in, boot off a Linux cd, reset your password.  Game over. 

Title: Re: Uh...
Post by: Joe on December 04, 2005, 01:16:26 AM
Heck, if you drive to my house, I'll gladly give you access to cave..

EDIT -
Answer my PM please.
Title: Re: Uh...
Post by: iago on December 04, 2005, 01:20:01 AM
Quote from: Joe[e2] on December 04, 2005, 01:16:26 AM
Answer my PM please.

It sucked and I chose not to answer it. 

Actually, I don't have your password, it's hashed, and I don't feel like creating a new one.  :P
Title: Re: Uh...
Post by: Joe on December 04, 2005, 02:54:11 AM
Sent another, less sucky one.
Title: Re: Uh...
Post by: Sidoh on December 04, 2005, 02:55:36 AM
Your box being breached without some other entity interacting with it is not impossible, just highly improbable.
Title: Re: Uh...
Post by: Hitmen on December 04, 2005, 03:08:07 AM
You guys are losers
Title: Re: Uh...
Post by: Joe on December 04, 2005, 03:10:01 AM
Omg, hitmen hacked it again iago, plz stop him. =(
Title: Re: Uh...
Post by: Newby on December 04, 2005, 03:05:47 PM
Quote from: Joe[e2] on December 04, 2005, 03:10:01 AM
Omg, hitmen hacked it again iago, plz stop him. =(

Uhh, he used a proxy. And I banned the proxy. Good job.
Title: Re: Uh...
Post by: trust on December 04, 2005, 08:26:38 PM
Quote from: Sidoh on December 04, 2005, 02:55:36 AM
Your box being breached without some other entity interacting with it is not impossible, just highly improbable.

Explain? Is it going to hack itself?
Title: Re: Uh...
Post by: Sidoh on December 04, 2005, 10:27:31 PM
Quote from: OG Trust on December 04, 2005, 08:26:38 PM
Explain? Is it going to hack itself?

Pretty much.  Electron tunneling...