 |
 |
| Author |
Message |
HaLo2FrEeEk Overlord Extraordinaire
 Joined: 15 Aug 2006 Posts: 5782 Status: Offline Style: Xbox 360 Location: Trying really hard to do something
|
Post subject: Sad |
|
|
I was going through some files on the server and I went into the template diectory, which contains the images and stylesheets that make Infectionist.com pretty. Insde I found two files that I was certain were not put there by me, one named style.php and the other named ho_header.php. I opened them in a PHP Editor and both contained very well-hidden exploit code. The code was base64 encoded and gzipped, then set to eval(), which means that when it's decrypted, it'll be executed.
The decrypted code was a very large PHP file that printed out multiple forms allowing anyone to execute PHP code, run shell commands, and basically do anything that I would be able to do. Here are screenshots of the 3 pages that you can get to with this script:
I've renamed the files (that's the blurred out section in the first screenshot) and also added a "die()" line at the beginning of the code, which kills it before it runs.
Very scary to imagine that someone could have deleted all the files on the server, or gained access to the database and cleared it.
The really scary thing is, how did someone get these files onto the server in the first place? The only thing I can think is that someone found my test directory, where I test out all my code ideas before putting them into "live" files. I don't generally delete things from that folder because I might need to come back to that example at a later date, sometimes I even make files in that directory public. Not anymore. I've put a password on the drectory and I'm the only one with access. It sucks that it came to that, but I do take the security of this site very seriously. I'm only one person and I can't find everything right as it happens, but I always find it.
I really want to mke things available, so it sucks that one shithead ruined it for all the other legitimate users, but that's how it has to be. I thought this site was small enough that it could fly under the radar, but apparently that's not the case. It's a bittersweet realization.
So, from here on out if you see a link with the path "/misc/testing/", it won't work anymore. Sorry, but I can't risk something like this screwing up what I've worked at for 4 and a half years.
Edit: Ok, I'm issuing a call to action! I just noticed that the frontpage had been modified as well, but stupid me, I didn't check the modified time before I removed the offending code saved the file, so I don't know WHEN the file was modified. I'm asking or everyone's help, scour the site, any accessible page should be looked at closely. Any links out of place, or to sites that I wouldn't link to, or in unusual places (the links added to the frontpage were below the bottom of the template, which should be touching the bottom of the window at all time.) Consider ANYTHING out of the ordinary to be a part of this, I mean ANYTHING. I can't find these all on my own, but I'll look in the places that you guys don't have access to. Please help me on this.
Also, I'm very sorry, but I'd recommend you all change your passwords. I know it sucks, but it's better to be safe than sorry. Imagine my pain, I have to change the passwords to the Dreamhost control panel, FTP, forum, all restricted sections of the site, and the admin control panel.
Submit anything that you find to this thread or PM me directly, I will do my absolute best to respond to each submission, and I will most certainly look into each one.
We really need to come together for this one, the site depends on it. _________________

~HaLo2FrEeEk
I wrote:
I'm sexy, admit it.
Are you?
Last edited by HaLo2FrEeEk on Wednesday, January 26, 2011 11:40:16 am; edited 1 time |
|
| Friday, December 10, 2010 7:07:27 am |
|
 |
| Author |
Message |
Poisonblood Proto-Gravemind

 Joined: 11 Apr 2007 Posts: 2724 Status: Offline Style: Xbox Xtreme Location: New Awesometon
|
Post subject: |
|
|
Holy shit, what an asshole move. Scout Wray is on the way, no dirty links will get past me. _________________

Pikachu Response to H2F Getting His Ass Kicked wrote:
"Carissa, take a picture of this. The guys down at Infectionist are gonna love this."
HaLo2FrEeEk wrote:
I guess I must be gay. And married...but totally gay, 100% flaming homosexual here.
|
|
| Friday, December 10, 2010 1:29:20 pm |
|
 |
 |
| Author |
Message |
Poisonblood Proto-Gravemind

 Joined: 11 Apr 2007 Posts: 2724 Status: Offline Style: Xbox Xtreme Location: New Awesometon
|
Post subject: |
|
|
Heh, that happened twice on HP. There now on Artistwith.in.
And by dirty I meant...mean, nasty? You dirty bastards!? Ain't no dirty bastard links getting past me! Like that. _________________

Pikachu Response to H2F Getting His Ass Kicked wrote:
"Carissa, take a picture of this. The guys down at Infectionist are gonna love this."
HaLo2FrEeEk wrote:
I guess I must be gay. And married...but totally gay, 100% flaming homosexual here.
|
|
| Friday, December 10, 2010 5:21:20 pm |
|
 |
 |
| Author |
Message |
Poisonblood Proto-Gravemind

 Joined: 11 Apr 2007 Posts: 2724 Status: Offline Style: Xbox Xtreme Location: New Awesometon
|
Post subject: |
|
|
|
bK x PwNeR wrote:
Well, you know you can trust us who have been around for years H2F. I would hate to see this place gone.
Muahahhahahah...lolwut. _________________

Pikachu Response to H2F Getting His Ass Kicked wrote:
"Carissa, take a picture of this. The guys down at Infectionist are gonna love this."
HaLo2FrEeEk wrote:
I guess I must be gay. And married...but totally gay, 100% flaming homosexual here.
|
|
| Friday, December 10, 2010 8:21:18 pm |
|
 |
| Author |
Message |
s.k. Pure Form

 Joined: 23 May 2010 Posts: 864 Status: Offline Style: Xbox 360 Location: Australia
|
Post subject: |
|
|
SHIIITTT!!!! Thats bad, I will now look on every page on this site _________________

Pikachu wrote:
Poisonblood wrote:
One time I tickled HaLo2FrEeEks balls with my tongue. But thats a story for a different time.
I hereby declare you a full-fledged faggot.
PROMOTE ME!! PROMOTE ME!! PROMOTE ME!! PROMOTE ME!! |
|
| Friday, December 10, 2010 9:04:57 pm |
|
 |
Page 1 of 2
|
|
All times are GMT - 8 Hours Goto page 1, 2 Next
|
|
Display posts from previous:
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
 |
|
|