Server hacked

Discussion about hacker.org's server
Post Reply
User avatar
adum
Posts: 392
Joined: Thu Apr 19, 2007 12:49 pm
Contact:

Server hacked

Post by adum »

as you probably noticed, hacker.org was hacked last weekend. oh, the irony! :)

truth to be told, we hadn't spent much effort in securing the site. which was a little foolish.

as well as defacing the site, somebody dumped the user table with names and passwords. we use the phpbb2 reg system here, and i guess they don't salt their passwords, which is unfortunate. any password that is short or based on a dictionary word has probably been reversed at this time. therefore, it's very important to change your password to something robust, and if you used the same password on any other site or email account to change that too. sorry for any trouble.

i've spent some time closing out all the SQL injection points i could think of, but in case i missed something, if you happen to notice it please drop me a PM.
User avatar
PaRaDoX
Posts: 708
Joined: Fri Aug 22, 2008 5:52 am
Location: In your fridge, waiting to pop out and scare you.

Post by PaRaDoX »

lol yea, we'd just "notice an un-sterilized form: :3
Image

~You are a glitch in my reasoning.
plope0726
Posts: 826
Joined: Mon Dec 15, 2008 10:13 pm

Post by plope0726 »

:lol:
User avatar
S3th
Posts: 411
Joined: Thu Sep 11, 2008 8:35 am

Post by S3th »

Eh, My password was made up of Lower and uppercase, with numbers. sorta like
LiK3sH1HwN <Example.
And even if someone wanted to crack my account...Woopdie do, I created a new email address upon signing up here, so it wouldn't get far.
See through the master
Become the master
theStack
Posts: 72
Joined: Sun Nov 02, 2008 12:46 am

Post by theStack »

Well, I'm glad the site is back again, my apprehensions were that the bad guy destroyed the database and there were never made any backups of hacker.org.
Anyway, I noticed the system for the HVM challenges seems to be broken since the evil 0wnage:
Parse error: syntax error, unexpected T_STRING, expecting T_OLD_FUNCTION or T_FUNCTION or T_VAR or '}' in /home/.mazie/hacker_apache/html/hacker/html/hvm/hvmchallenge.php on line 3
adum, could you fix that please? :)
DanielG
Posts: 30
Joined: Thu Nov 13, 2008 10:34 am

Post by DanielG »

Also, the SVG version of the map isn't working.
Warning: domdocument() expects at least 1 parameter, 0 given in /home/.mazie/hacker_apache/html/hacker/html/challenge/svg/mapsvg.php on line 31

Fatal error: Call to undefined function: loadxml() in /home/.mazie/hacker_apache/html/hacker/html/challenge/svg/mapsvg.php on line 34
User avatar
teebee
Posts: 89
Joined: Mon Nov 10, 2008 3:21 pm
Location: Germany

Post by teebee »

Moreover, the system for the SuperHack challenges is broken:
Parse error: syntax error, unexpected T_STRING, expecting T_OLD_FUNCTION or T_FUNCTION or T_VAR or '}' in /home/.mazie/hacker_apache/html/hacker/html/sh/shack.php on line 3
and the php source of the SuperHack vm is not available at http://www.hacker.org/sh/shphp.phps.
User avatar
adum
Posts: 392
Joined: Thu Apr 19, 2007 12:49 pm
Contact:

Post by adum »

i'll fix all that stuff soon... thanks
Codux
Posts: 1
Joined: Thu Nov 20, 2008 4:15 pm
Location: IN Germany

Post by Codux »

Just a notice: Since the incident (i. e. since the hashes (and email) list is online) users might get bulk mail on the used mail address (I do). Only because of that I noticed that somthing is not ok (I was quite inactive the last time ;-) ).
I hope you haven't lost the fun on running the site!
C | Chaotic
O | Organized
D | Destructive
U | Unbelieveable
X | eXtreme
——
@milw0rm You didn't own my password… Bread is able to mould. What ability do you have? :þ
Defil3d
Posts: 4
Joined: Thu Mar 05, 2009 10:55 pm

Sup

Post by Defil3d »

Hello, I'm new to this site and since I saw that a hacking site just got hacked...All I can say is lol
User avatar
PaRaDoX
Posts: 708
Joined: Fri Aug 22, 2008 5:52 am
Location: In your fridge, waiting to pop out and scare you.

Re: Sup

Post by PaRaDoX »

Defil3d wrote:Hello, I'm new to this site and since I saw that a hacking site just got hacked...All I can say is lol
I wouldn't laugh, go start up a site of your own and watch what happens in like the first 2 days. (shitty free sites don't count, I mean one where you have to do the security, smartass)
Image

~You are a glitch in my reasoning.
Mr_K_13
Posts: 1
Joined: Wed Apr 16, 2008 3:28 am
Location: Australia

Post by Mr_K_13 »

Quite unfortunate, I hope all is fixed soon. =)
the_impaler
Posts: 61
Joined: Wed Apr 30, 2008 3:31 am

Post by the_impaler »

Please let us know when it's safe to change password back to 6 stars.
The stickies are not holding for long
On the other positive side - the only email I got so far was that I just inherited $13,000,000. I didn't know that adum was so rich. :wink:

cheers,
User avatar
m!nus
Posts: 202
Joined: Sat Jul 28, 2007 6:49 pm
Location: Germany

Post by m!nus »

58.4% of the passwords got cracked

the news is even on heise.de: http://www.heise.de/security/Nutzerpass ... ung/134052 (german)

maybe it's time for a new era on hacker.org, make it open source, so everyone can find vulnerabilities and let you fix them. :)


btw, how exactly did they get in the system, vulnerabilities in the challenge system or in the forum?
User avatar
S3th
Posts: 411
Joined: Thu Sep 11, 2008 8:35 am

Post by S3th »

"About the circumstances of the burglary, the operator is almost no information."
What happened adum. ;3
See through the master
Become the master
Post Reply