Originally posted by The Mad Monk
View Post
Announcement
Collapse
No announcement yet.
The Apolyton hacking pool
Collapse
X
-
MY problem with WPC is I got banned without breaking any rules at all and even Solver admitted it. He just got upset with something I said on CG and so banned me at WPC. Some people just shouldn't be mods.Scouse Git (2) La Fayette Adam Smith Solomwi and Loinburger will not be forgotten.
"Remember the night we broke the windows in this old house? This is what I wished for..."
2015 APOLYTON FANTASY FOOTBALL CHAMPION!
Comment
-
5th time has now happened. It claims someone uploaded a trojan and that's how they're getting in.Try http://wordforge.net/index.php for discussion and debate.
Comment
-
Well holy gargoyles!
vBulletin sites have been getting hacked left and right recently, but upgrading the forums doesn't solve anything by itself. You're getting lots of fake users created with admin rights that haven't been removed. You also almost certainly have a plugin installed that calls system() in PHP to give a backdoor, tied to the AJAX start hook. And remove the damn upgrade scripts from the server once you're done upgrading! The scripts are there right now which adds another half a dozen easy ways to hack into the forum.Solver, WePlayCiv Co-Administrator
Contact: solver-at-weplayciv-dot-com
I can kill you whenever I please... but not today. - The Cigarette Smoking Man
Comment
-
Oh right, that's my issue with WPC. They took Solver away from Apolyton.Click here if you're having trouble sleeping.
"We confess our little faults to persuade people that we have no large ones." - François de La Rochefoucauld
Comment
-
Ok, to whoever runs this joint now (still CyberShy?):
I just fixed the forum front page and removed some backdoors. You had 3 backdoors running at the same time! The ones that I mentioned with system(), and also one called c99shell - you can look it and its capabilities up online.
There's also an impressive 20 backdoor admin accounts created today. I'm in the process of deleting them. Remove your darn upgrade script or else this will likely not last an hour.
EDIT: Okay, those admin accounts are gone. I found another 3 backdoors running as plugins. I'm surprised they haven't smothered one another. Why in the blazes do you not have system() and eval() disabled in php.ini?Last edited by Solver; September 9, 2013, 17:06.Solver, WePlayCiv Co-Administrator
Contact: solver-at-weplayciv-dot-com
I can kill you whenever I please... but not today. - The Cigarette Smoking Man
Comment
-
Awesome, intelligent gibberish tech talk.
Solver
I guess you Soviets are good for something.Do not fear, for I am with you; Do not anxiously look about you, for I am your God.-Isaiah 41:10
I praise you because I am fearfully and wonderfully made - Psalms 139.14a
Also active on WePlayCiv.
Comment
-
... and that's it, I am going to bed. There was another attempt to do the same thing 5 minutes ago but I deleted that in time. Unless somebody reacts quickly, the forums will have been defaced again anyway by the time I wake up.
The front page of the site itself is still borked, and I think that some other security hole might have been inserted in addition to the ones I've mentioned. Also, in the unlikely event any of those hackers had any brains, they would have downloaded the hashed passwords of the admin, so CyberShy should change his just in case.Solver, WePlayCiv Co-Administrator
Contact: solver-at-weplayciv-dot-com
I can kill you whenever I please... but not today. - The Cigarette Smoking Man
Comment
Comment