×
  • remind me tomorrow
  • remind me next week
  • never remind me
Subscribe to the ANN Newsletter • Wake up every Sunday to a curated list of ANN's most interesting posts of the week. read more

Forum - View topic
ANN front page Hacked?




Anime News Network Forum Index -> Site-related -> Bugs & Technical Questions
View previous topic :: View next topic  
Author Message
Shinotaku14
Encyclopedia Editor


Joined: 09 Aug 2003
Posts: 233
Location: Greenville or Rock Hill, SC
PostPosted: Sat Dec 18, 2004 1:16 pm Reply with quote
anytime I go to the front page of ANN i get a blank page with only the words "H4ck3rsBr Group" on it. It seems though, that everything else is working. Anybody else with this problem?
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger ICQ Number My Anime My Manga
Tempest
I Run this place.
ANN Publisher


Joined: 29 Dec 2001
Posts: 10421
Location: Do not message me for support.
PostPosted: Sun Dec 19, 2004 10:36 am Reply with quote
Yeah, a security bug in PHP was discovered Friday.

Yesterday I upgraded PHP4 to fix this hole, but I forgot to restart Apache. (meaning that while the new PHP was on the server, apache was running with the old one).

During the 30 minutes after I completed the upgrade, someone defaced the front page.

As soon as this was pointed out to me I restarted apache and replaced the default page, unfotunately it turns out that PHP didn't upgrade properly, so it took us a while to get it fixed.

My lack of knowledge / experience on the BSD platform (or any *nix platform for that matter) is occasionally a very big headache.

Fortunately, after several tries Dan figured out what the problem was and managed to fix it...

-t
Back to top
View user's profile Send private message Send e-mail My Anime My Manga
AstroNerdBoy



Joined: 03 Feb 2004
Posts: 413
Location: Denver, CO
PostPosted: Sun Dec 19, 2004 8:20 pm Reply with quote
Glad you guys are back!
Back to top
View user's profile Send private message Visit poster's website AIM Address
Justin



Joined: 07 Jul 2003
Posts: 16
Location: Newport Beach, CA
PostPosted: Mon Dec 20, 2004 1:56 am Reply with quote
That is unfortunate. I too was hacked.

These hackers took advantage of this security hole by using phpbb to inject an SQL statement giving them access to my entire site. They then uploaded two gigs of anime fansubs. That was fun.

MANY sites are in the process of upgrading at the moment. Good to see ANN back so soon!
Back to top
View user's profile Send private message Visit poster's website AIM Address MSN Messenger ICQ Number
Emerje



Joined: 10 Aug 2002
Posts: 7338
Location: Maine
PostPosted: Mon Dec 20, 2004 5:39 pm Reply with quote
I see the page was down today for a little while too, was it hacked again?

Emerje
Back to top
View user's profile Send private message Visit poster's website My Anime My Manga
biliano*



Joined: 11 Feb 2004
Posts: 0
PostPosted: Mon Dec 20, 2004 5:52 pm Reply with quote
I'm glad you were able to fix the problem so quickly. Even when you had that major hard drive crash back in July, you were able to get back online quickly.
Back to top
View user's profile Send private message My Anime My Manga
JinchuuGundam85



Joined: 24 Aug 2004
Posts: 149
PostPosted: Mon Dec 20, 2004 8:51 pm Reply with quote
I think this applies. I was on the forum and clicked refresh and a message came up saying that the page has been defaced. Was it just me or did this happen to others?
Back to top
View user's profile Send private message Send e-mail
dormcat
Encyclopedia Editor


Joined: 08 Dec 2003
Posts: 9902
Location: New Taipei City, Taiwan, ROC
PostPosted: Mon Dec 20, 2004 8:55 pm Reply with quote
JinchuuGundam85 wrote:
I think this applies. I was on the forum and clicked refresh and a message came up saying that the page has been defaced. Was it just me or did this happen to others?

Everyone. It happened at 17:09 PST (GMT -8) and lasted for ~40 minutes. Seems to me that this hacker either has targeted specifically at ANN or is an expert attacking PHP-based databases.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number My Anime My Manga
DragonsRevenge



Joined: 15 Nov 2004
Posts: 1150
PostPosted: Mon Dec 20, 2004 9:10 pm Reply with quote
It happened a few more times today, for me.
Back to top
View user's profile Send private message
daggerbob



Joined: 25 Dec 2003
Posts: 52
Location: Colorado, US
PostPosted: Mon Dec 20, 2004 9:46 pm Reply with quote
I noticed the deface message a few times this morning around 0800 MST.
Back to top
View user's profile Send private message My Anime My Manga
Justin



Joined: 07 Jul 2003
Posts: 16
Location: Newport Beach, CA
PostPosted: Mon Dec 20, 2004 11:29 pm Reply with quote
dormcat wrote:
Everyone. It happened at 17:09 PST (GMT -8) and lasted for ~40 minutes. Seems to me that this hacker either has targeted specifically at ANN or is an expert attacking PHP-based databases.


Actually, quite a few groups have automated jobs running right now. If you install any version of phpbb BELOW 2.0.11, you can pretty much just open your doors for the script. I installed 2.0.8 and less than an hour later, the same fansubs were uploaded to the exact samer directory again.

Some hacking groups are also running scripts going after WordPress sites as well. Those of us with either of these technologies running are on our toes.

Pretty much any site using any version of PHP 4 <= 4.3.9 or PHP 5 <= 5.0.2 and running the functions unserialize and realpath are easy targets. Be sure to email your host companies and make sure they have taken steps to prevent hacking attempts.
Back to top
View user's profile Send private message Visit poster's website AIM Address MSN Messenger ICQ Number
radicaledward



Joined: 02 Mar 2003
Posts: 776
PostPosted: Tue Dec 21, 2004 10:46 am Reply with quote
dormcat wrote:
Everyone. It happened at 17:09 PST (GMT -8) and lasted for ~40 minutes. Seems to me that this hacker either has targeted specifically at ANN or is an expert attacking PHP-based databases.
Nah, most of they are no skill script kiddies. The bane of every system admin's existance. Most of the people that would know what they are doing wouldn't leave something behind or they would have been more subtle about it.
Back to top
View user's profile Send private message My Anime My Manga
Emerje



Joined: 10 Aug 2002
Posts: 7338
Location: Maine
PostPosted: Tue Dec 21, 2004 11:50 am Reply with quote
radicaledward wrote:
Nah, most of they are no skill script kiddies. The bane of every system admin's existance. Most of the people that would know what they are doing wouldn't leave something behind or they would have been more subtle about it.


Indeed, it's like the kids that brag that they "hack" video games, when they're just using a GameShark. It's the wrong tools in the wrong hands.

Tell Tale sign? Most Schools have started vacation and the kids are restless. Wouldn't be surprised at all if we start seeing a swarm of spammers and trolls soon too.

Emerje
Back to top
View user's profile Send private message Visit poster's website My Anime My Manga
radicaledward



Joined: 02 Mar 2003
Posts: 776
PostPosted: Tue Dec 21, 2004 8:34 pm Reply with quote
Well some more information just turned up on NeverEverNoSanity - and apprently it is a worm that uses Google to look up potential target sites.

Here is an artical that just went up on Slashdot, but from the looks of it that worm is targeting phpBB installs.
Back to top
View user's profile Send private message My Anime My Manga
Display posts from previous:   
Reply to topic    Anime News Network Forum Index -> Site-related -> Bugs & Technical Questions All times are GMT - 5 Hours
Page 1 of 1

 


Powered by phpBB © 2001, 2005 phpBB Group