Forum main page hacked. Check here for updates?

General discussion about Kanzenshuu, its content, features, contests, community, etc. This is NOT an off-topic forum!

Moderators: Kanzenshuu Staff, General Help

User avatar
SaiyaJedi
Kanzenshuu Co-Owner & Administrator
Posts: 2387
Joined: Sat Jan 10, 2004 11:24 pm
Location: Osaka
Contact:

Post by SaiyaJedi » Mon Jun 27, 2005 12:52 am

Mirai Trunks´s Nr. 1 fan wrote:Hmmm... yeah well that seems to be logical... there are a LOT of idiot hackers on the net...But whoever did it I hope you (or Julian) will be able to fix it...
The fix is known (and now we know what it is), but Mike would need to be the one to do the fixin'. Hopefully sometime this week, free-time permitting. Right, Mike? :)
Co-translator, Man-in-Japan, and Julian #1 at Kanzenshuu
最近、あんまし投稿してないねんけど、見てんで。いっつも見てる。

Ero-Sennin
Newbie
Posts: 22
Joined: Wed Apr 06, 2005 5:27 pm
Location: I'm behind you!
Contact:

Post by Ero-Sennin » Mon Jun 27, 2005 10:10 am

O.o If you know the fix Julian and we're waiting for Mike, judging by his normal ammount of free time this may take a week or two.

Oh well, idiot script kiddies should have their fingers cut off SLOWLY, with a spoon.

No to throw my question what on earth is the exploit he used to get into the script for the forum? Or did he just brute force it?
Dark souls come dime a dozen, a truely pure soul is priceless, whilst a truely corrupted one is worthless.

User avatar
SaiyaJedi
Kanzenshuu Co-Owner & Administrator
Posts: 2387
Joined: Sat Jan 10, 2004 11:24 pm
Location: Osaka
Contact:

Post by SaiyaJedi » Mon Jun 27, 2005 5:29 pm

Ero-Sennin wrote:O.o If you know the fix Julian and we're waiting for Mike, judging by his normal ammount of free time this may take a week or two.

Oh well, idiot script kiddies should have their fingers cut off SLOWLY, with a spoon.

No to throw my question what on earth is the exploit he used to get into the script for the forum? Or did he just brute force it?
That, I don't know. But apparently, the code is hidden somewhere in the vicinity of the title / description of the DaizEX "General Discussion" board, hence its name disappearing when the forum got hacked. If Mike can fix that, it should be set to rights. I think. :?
Co-translator, Man-in-Japan, and Julian #1 at Kanzenshuu
最近、あんまし投稿してないねんけど、見てんで。いっつも見てる。

User avatar
lost in thought
Advanced Regular
Posts: 1018
Joined: Tue Nov 30, 2004 5:01 pm
Location: Cudahy, Wisconsin
Contact:

Post by lost in thought » Mon Jun 27, 2005 9:04 pm

It looks like it's time for me to make a more informed post, about this.
SaiyaJedi wrote:The fix is known
Unless Mike has devised a fix that I have not heard of, this 'fix' is no longer known. Sadly.
Ero-Sennin wrote:No to throw my question what on earth is the exploit he used to get into the script for the forum? Or did he just brute force it?
From the looks of things, it was not brute force. However, according to what Mike found server side, the person in question uploaded a few .bak files, which are definitely not part of the forum software. Mike took steps and removed them, as well as took steps to repair the damage, one evening, based on my suggestions. It does go without saying that it failed.
SaiyaJedi wrote:But apparently, the code is hidden somewhere in the vicinity of the title / description of the DaizEX "General Discussion" board
The pre-formatted HTML, and Javascript sits there, but where it is loaded from is still unknown. My current theory is that he may have inserted it within one of the database tables that are called when loading the index page.

As far as the damage goes, Mike has based on my suggestions attempted to mend the problem, but had found no change. The next time I speak to him, I'll mention to him to examine the table files of his mySQL database, for the forum, and see if the problem lies there. Before this though, I'll attempt to gather what databases are involved in loading the indexes code.
Hopefully this can be solved without having to re-install the forum entirely, but if worse comes, that may be the only alternative. Sorry I can't provide more promising information on the matter, but hopefully I can determine the problem myself, and give Mike the hope of not having to loose all of the posts. Unless Mike re-installs before I can discuss this with him further.

User avatar
Videl
Newbie
Posts: 9
Joined: Tue Jun 28, 2005 1:24 am

stupid

Post by Videl » Tue Jun 28, 2005 1:39 am

the message is stupid and who ever did that really has no life and will enter the gates of hell and he will suffer!! :twisted:

User avatar
lost in thought
Advanced Regular
Posts: 1018
Joined: Tue Nov 30, 2004 5:01 pm
Location: Cudahy, Wisconsin
Contact:

Post by lost in thought » Tue Jun 28, 2005 4:43 am

Videl wrote:the message is stupid and who ever did that really has no life and will enter the gates of hell and he will suffer!!
One, so Mike doesn't have to; we like proper grammar here, so it would be much easier on you to use proper punctuation and capitalize the first word of your sentence. Thanks.

Two, thank you for relating what everyone has already pointed out ad nauseum.

Ero-Sennin
Newbie
Posts: 22
Joined: Wed Apr 06, 2005 5:27 pm
Location: I'm behind you!
Contact:

Post by Ero-Sennin » Tue Jun 28, 2005 6:40 am

An idea might be to compare the script between an unaltered version of the board, and the current script of this bored, a bit long winded but it may shed some light as to what said script kiddie did.

Though that said it's probably already been done...

On a second thought, might upgrading the board to the current script be an idea, but then again, like I said might of already been tried.
Dark souls come dime a dozen, a truely pure soul is priceless, whilst a truely corrupted one is worthless.

ChaotixXero
Beyond Newbie
Posts: 198
Joined: Wed Dec 29, 2004 5:40 am

Post by ChaotixXero » Tue Jun 28, 2005 9:08 am

Hey guys...Is it safe to go to the index? >_> <_<

It was kinda creepy. I just click forum link thing and I see the death angel thing and I go "WTF? :shock:?" Then I just checked out the site. >_>

Schuby
Newbie
Posts: 1
Joined: Tue Jun 28, 2005 1:21 pm
Location: Southern California
Contact:

Post by Schuby » Tue Jun 28, 2005 1:22 pm

I fixed the main page for you guys. I'll update the software as soon as possible.

Those asking what he did:

He injected HTML code into the "Forum Description" cell of one of the main tables loaded. This causes Index.php to compile whatever is in that cell (Html, javascript, etc..) when the page is loaded because it's looking for the Forum Description.

Edit: Fixed general discussion link as well.

And next time please don't delete .bak's, they are generally backup files :P

Edit 2: Forum software is now 2.0.16
www.schuby.org

User avatar
*PINHEAD*
OMG CRAZY REGEN
Posts: 814
Joined: Sun Jul 18, 2004 11:05 pm
Location: Los Angeles
Contact:

Post by *PINHEAD* » Tue Jun 28, 2005 4:15 pm

Ya fixed it? Sweet. I was getting tiring to have to go through the main page, click the forum link, and jump from board to board (too lazy to bookmark).
I was voted "most unique" and "most likely to become the next existential thinker" in high school.

User avatar
lost in thought
Advanced Regular
Posts: 1018
Joined: Tue Nov 30, 2004 5:01 pm
Location: Cudahy, Wisconsin
Contact:

Post by lost in thought » Tue Jun 28, 2005 6:37 pm

Ero-Sennin wrote:An idea might be to compare the script between an unaltered version of the board, and the current script of this bored, a bit long winded but it may shed some light as to what said script kiddie did.
That's what Mike, and I, had been doing. It did fail, but one failure is a stepping stone on the road to success.
Schuby wrote:He injected HTML code into the "Forum Description" cell of one of the main tables loaded. This causes Index.php to compile whatever is in that cell (Html, javascript, etc..) when the page is loaded because it's looking for the Forum Description.
Thank's for pointing that out, Schuby. I would have gotten around to remarking on that, but I was busy for the majority of the day. Either way though, atleast everythings in working order again.

User avatar
VegettoEX
Kanzenshuu Co-Owner & Administrator
Posts: 17742
Joined: Sat Jan 10, 2004 3:10 pm
Location: New Jersey
Contact:

Post by VegettoEX » Tue Jun 28, 2005 6:42 pm

Extreme thanks to Josh & Schuby. I would have eventually got around to fixing it, but this just makes it so much easier :). We all deeply appreciate it from the depths of HFIL.
:: [| Mike "VegettoEX" LaBrie |] ::
:: [| Kanzenshuu - Co-Founder/Administrator, Podcast Host, News Manager (note: our "job" titles are arbitrary and meaningless) |] ::
:: [| Website: January 1998 |] :: [| Podcast: November 2005 |] :: [| Fusion: April 2012 |] :: [| Wiki: 20XX |] ::

Locked