Jump to content


Photo
* * * * * 1 votes

ProivRC Hacker


4 replies to this topic

#1 Rob Donovan

Rob Donovan

    rob@proivrc.com

  • Admin
  • 1,640 posts
  • Gender:Male
  • Location:Spain

Posted 01 November 2006 - 09:51 PM

Hi & welcome back all,

Well, Sunday night we got hacked and the front page of ProivRC was defaced.

Initially, I thought it was just that, but after a bit of looking around I noticed that someone had managed to install scripts to allow them to access my server via PHP.

This is why I took the site down as I could not verify 100% everything in every dir.

I presume they got in because I was running a fairly old version of the forum software, I wasnt particualy worried about it up till then because who is gonna hack a Proiv site!

However, obviously there are people with not much to do.

The IP originated over from Moldova, and I have contacted their ISP, but I dont expect much back from them.

Since the hack, I blocked the IP subnet that the user was coming in from, and in the last 3 days they have been trying to access the site again and looking for their scripts.

I've upgraded the software over the last 3 days to give us more security, something that I had been testing etc on another server for the last few weeks.

I have not been able to do everything I wanted, so I will continue to change stuff over the next few weeks.

Any questions just ask,

Rob D.

#2 Rick San Soucie

Rick San Soucie

    Member

  • Members
  • PipPip
  • 36 posts
  • Gender:Male
  • Location:Dallas, United States

Posted 01 November 2006 - 10:46 PM

Sorry you had to go through all of this. I missed your site.

#3 Rob Donovan

Rob Donovan

    rob@proivrc.com

  • Admin
  • 1,640 posts
  • Gender:Male
  • Location:Spain

Posted 01 November 2006 - 10:52 PM

Thanks Rick,

Kind of my own fault though for not keeping up with updates...

I'm normally over 'updating' on my PC, but you always learn the hard way.

But I just didnt expect a Proiv site to get hacked :)

Rob.

#4 andykay

andykay

    ProIV Guru

  • Members
  • PipPipPipPipPip
  • 204 posts
  • Gender:Male
  • Location:Cyberspace...looking for work

Posted 02 November 2006 - 12:11 AM

The RC was missed Rob. One may never realized how often they access a particular site :- until their expectations are dowsed with an unavailable sign. :)

Glad to have you back RC. :)
THE LIGHT AT THE END OF THE TUNNEL IS THE HEADLAMP OF THE TRAIN THAT'S ABOUT TO HIT YOU!!!

#5 twallis

twallis

    Member

  • Members
  • PipPip
  • 19 posts
  • Gender:Male
  • Location:Edinburgh

Posted 02 November 2006 - 01:43 AM

Thanks for the explanation,
Great to see things are backup and working again

Although I think have to log in again from my PC was more of a shock :)



Reply to this topic



  


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users