|
|
|
|
|
|
|
|
|
|
Genma
Joined: 24 Sep 2000 Posts: 1150 Location: Singapore Country: |
Posted: Fri Mar 18, 2005 2:27 am Post subject: JDorama.com patched |
|
|
Finally back up. Spent some time souring the database and code for any other oddities the hacker introduced. Anywayz, here's what the notti boy/girl did...
- Changed "Discussion on Dramas" forum title and description into a floating HTML segment, which is the "hacked" message that some of you saw.
- Added an admin user called subzero.
- Set number of topics per page to 0, hence you get divide by zero errors and no topics in the forums nor inbox.
- Messed up some of the forum permissions to ADMIN only.. duh.. itchy fingers.
The above have been fixed. If more damage was done.. (hope not!) someone please point it out to me.
And, yes, the exploit was probably the "==" to "===" comparison code which gives the user admin access. Luckily, nothing much could be done via the admin panel. I've patched the forum to 2.0.13 manually. Hope all goes fine now! I'm gonna subscribe to whatever darn mailing list phpbb has for such updates.. _________________ @_@ <--- webmaster?
Last edited by Genma on Tue Feb 28, 2006 3:07 pm; edited 2 times in total
|
|
Back to top |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
bmwracer
Joined: 07 Jul 2003 Posts: 125547 Location: Juri-chan's speed dial Country: |
|
Back to top |
|
|
|
|
|
|
|
|
|
SyoCamui
Joined: 17 Jul 2004 Posts: 42 Location: USA Country: |
|
Back to top |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Guest
|
Posted: Fri Mar 18, 2005 6:15 am Post subject: |
|
|
|
|
Back to top |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
lilswtangel
Joined: 07 Dec 2004 Posts: 19 Location: New York City Country: |
|
Back to top |
|
|
|
|
|
|
|
|
|
eightysix
Joined: 08 Jan 2004 Posts: 1529 Location: United States Country: |
Posted: Fri Mar 18, 2005 8:51 am Post subject: |
|
|
Genma wrote: | Forgot one important note...
Welcome back to JDorama.com everyone! |
Good work, Genma. Otsukare!
|
|
Back to top |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
MixxDreamer
Joined: 06 May 2003 Posts: 3779 Location: so. cali, USA Country: |
Posted: Fri Mar 18, 2005 11:49 am Post subject: |
|
|
are you guys planning to check it out? he/she might set up a virus trap whoever sets on foot in there
|
|
Back to top |
|
|
|
|
|
|
|
|
|
eightysix
Joined: 08 Jan 2004 Posts: 1529 Location: United States Country: |
Posted: Fri Mar 18, 2005 1:02 pm Post subject: |
|
|
MixxDreamer wrote: | are you guys planning to check it out? he/she might set up a virus trap whoever sets on foot in there |
The channel is probably password protected anyway if they were smart.
Did anyone else notice that there's a slight rate limit on posting? Genma, could this be to prevent another DoS attack or is it a an added feature in the newest patch for phpBB?
|
|
Back to top |
|
|
|
|
|
|
|
|
|
bmwracer
Joined: 07 Jul 2003 Posts: 125547 Location: Juri-chan's speed dial Country: |
Posted: Fri Mar 18, 2005 1:04 pm Post subject: |
|
|
eightysix wrote: | Did anyone else notice that there's a slight rate limit on posting? Genma, could this be to prevent another DoS attack or is it a an added feature in the newest patch for phpBB? |
Rate limit??
|
|
Back to top |
|
|
|
|
|
|
|
|
|
eightysix
Joined: 08 Jan 2004 Posts: 1529 Location: United States Country: |
Posted: Fri Mar 18, 2005 1:17 pm Post subject: |
|
|
bmwracer wrote: |
Rate limit?? |
I wanted to edit a post right after I posted, and it gave me an error page saying that I can post immediately after I just posted. It's never happened to me before the site got upgraded.
|
|
Back to top |
|
|
|
|
|
|
|
|
|
bmwracer
Joined: 07 Jul 2003 Posts: 125547 Location: Juri-chan's speed dial Country: |
Posted: Fri Mar 18, 2005 1:25 pm Post subject: |
|
|
eightysix wrote: | I wanted to edit a post right after I posted, and it gave me an error page saying that I can post immediately after I just posted. It's never happened to me before the site got upgraded. |
I've had that happen to me in the past, but thought it was just a normal occurence...
|
|
Back to top |
|
|
|
|
|
|
|
|
|
dochira
Joined: 13 Oct 2004 Posts: 8550 Location: California Country: |
Posted: Fri Mar 18, 2005 1:40 pm Post subject: |
|
|
bmwracer wrote: |
I've had that happen to me in the past, but thought it was just a normal occurence... |
I'd try, but it might be seen as spam.
|
|
Back to top |
|
|
|
|
|
|
|
|
|
Genma
Joined: 24 Sep 2000 Posts: 1150 Location: Singapore Country: |
|
Back to top |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
eightysix
Joined: 08 Jan 2004 Posts: 1529 Location: United States Country: |
Posted: Sat Mar 19, 2005 4:41 am Post subject: |
|
|
Genma wrote: |
I've added a restriction to disallow posts within 30s in succession. Not because of the patch, just a setting. Is there a big compromise in convenience there? Let me know. |
No, not really. It's just me being curious. I hadn't seen it before so I was like, huh.
|
|
Back to top |
|
|
|
|
|
|
|
|
|
SyoCamui
Joined: 17 Jul 2004 Posts: 42 Location: USA Country: |
|
Back to top |
|
|
|
|
|
|
|
|
|
|
|
|
|
|