Server hacked
Server hacked
as you probably noticed, hacker.org was hacked last weekend. oh, the irony!
truth to be told, we hadn't spent much effort in securing the site. which was a little foolish.
as well as defacing the site, somebody dumped the user table with names and passwords. we use the phpbb2 reg system here, and i guess they don't salt their passwords, which is unfortunate. any password that is short or based on a dictionary word has probably been reversed at this time. therefore, it's very important to change your password to something robust, and if you used the same password on any other site or email account to change that too. sorry for any trouble.
i've spent some time closing out all the SQL injection points i could think of, but in case i missed something, if you happen to notice it please drop me a PM.
truth to be told, we hadn't spent much effort in securing the site. which was a little foolish.
as well as defacing the site, somebody dumped the user table with names and passwords. we use the phpbb2 reg system here, and i guess they don't salt their passwords, which is unfortunate. any password that is short or based on a dictionary word has probably been reversed at this time. therefore, it's very important to change your password to something robust, and if you used the same password on any other site or email account to change that too. sorry for any trouble.
i've spent some time closing out all the SQL injection points i could think of, but in case i missed something, if you happen to notice it please drop me a PM.
Well, I'm glad the site is back again, my apprehensions were that the bad guy destroyed the database and there were never made any backups of hacker.org.
Anyway, I noticed the system for the HVM challenges seems to be broken since the evil 0wnage:
Anyway, I noticed the system for the HVM challenges seems to be broken since the evil 0wnage:
adum, could you fix that please?Parse error: syntax error, unexpected T_STRING, expecting T_OLD_FUNCTION or T_FUNCTION or T_VAR or '}' in /home/.mazie/hacker_apache/html/hacker/html/hvm/hvmchallenge.php on line 3
Also, the SVG version of the map isn't working.
Warning: domdocument() expects at least 1 parameter, 0 given in /home/.mazie/hacker_apache/html/hacker/html/challenge/svg/mapsvg.php on line 31
Fatal error: Call to undefined function: loadxml() in /home/.mazie/hacker_apache/html/hacker/html/challenge/svg/mapsvg.php on line 34
Moreover, the system for the SuperHack challenges is broken:
and the php source of the SuperHack vm is not available at http://www.hacker.org/sh/shphp.phps.Parse error: syntax error, unexpected T_STRING, expecting T_OLD_FUNCTION or T_FUNCTION or T_VAR or '}' in /home/.mazie/hacker_apache/html/hacker/html/sh/shack.php on line 3
Just a notice: Since the incident (i. e. since the hashes (and email) list is online) users might get bulk mail on the used mail address (I do). Only because of that I noticed that somthing is not ok (I was quite inactive the last time ).
I hope you haven't lost the fun on running the site!
I hope you haven't lost the fun on running the site!
C | Chaotic
O | Organized
D | Destructive
U | Unbelieveable
X | eXtreme
——
@milw0rm You didn't own my password… Bread is able to mould. What ability do you have? :þ
O | Organized
D | Destructive
U | Unbelieveable
X | eXtreme
——
@milw0rm You didn't own my password… Bread is able to mould. What ability do you have? :þ
- PaRaDoX
- Posts: 708
- Joined: Fri Aug 22, 2008 5:52 am
- Location: In your fridge, waiting to pop out and scare you.
Re: Sup
I wouldn't laugh, go start up a site of your own and watch what happens in like the first 2 days. (shitty free sites don't count, I mean one where you have to do the security, smartass)Defil3d wrote:Hello, I'm new to this site and since I saw that a hacking site just got hacked...All I can say is lol
~You are a glitch in my reasoning.
-
- Posts: 61
- Joined: Wed Apr 30, 2008 3:31 am
58.4% of the passwords got cracked
the news is even on heise.de: http://www.heise.de/security/Nutzerpass ... ung/134052 (german)
maybe it's time for a new era on hacker.org, make it open source, so everyone can find vulnerabilities and let you fix them.
btw, how exactly did they get in the system, vulnerabilities in the challenge system or in the forum?
the news is even on heise.de: http://www.heise.de/security/Nutzerpass ... ung/134052 (german)
maybe it's time for a new era on hacker.org, make it open source, so everyone can find vulnerabilities and let you fix them.
btw, how exactly did they get in the system, vulnerabilities in the challenge system or in the forum?