Board Logo

We're back
vanderaj - December 13th, 2006 at 02:39 AM

Hi there,

The host has been broken into due to someone using the same name and password on an account with shell access. The attacker probably used this to take over the system, and from there, destroy the entire server.

Most likely we're going to move to a better hoster with no other stupid users.

Sorry for the interruption.

Andrew


h - December 13th, 2006 at 06:16 AM

cheers for your hard work.. thanks..


Gibbo - December 13th, 2006 at 06:31 AM

Damn script kiddies!

Thanks for getting things back on track mate. Grrr hate that crap....


kombikim - December 13th, 2006 at 06:35 AM

thanks Andrew


rose - December 13th, 2006 at 07:06 AM

Thanks heaps Andrew


MickH - December 13th, 2006 at 08:08 AM

Geez that must piss you admin people off:ninja:.......Good work guys.:beer


BASHOdi - December 13th, 2006 at 09:31 AM

:beerWell done on the quick recovery --only question is why ???would someone do this there's no profit for anyone of any kind anyway --again WELL DONE !!
Cheers , Al .


CAFFINEPUSHERMAN - December 13th, 2006 at 09:33 AM

keep up the good work:tu:


Schmoburger - December 13th, 2006 at 10:21 AM

is it just me or have we lost a hellavalot of stuff... my postcount has dropped by about a hundred or so! :duh


amazeer - December 13th, 2006 at 10:39 AM

Quote:
Originally posted by BASHOdi
only question is why ???would someone do this there's no profit for anyone of any kind anyway --again WELL DONE !!
Cheers , Al .


Its 20th/21st century vandalism. They break websites for the same reason they break windows.



[ Edited on 13-12-2006 by amazeer ]


dvs_vw - December 13th, 2006 at 10:55 AM

hmmm good to see it back up, but I lost my posts from last week which means I need 5 again to U2U someone....bugger!


vwpete - December 13th, 2006 at 11:03 AM

Quote:
Originally posted by vanderaj
Hi there,

The host has been broken into due to someone using the same name and password on an account with shell access. The attacker probably used this to take over the system, and from there, destroy the entire server.

Most likely we're going to move to a better hoster with no other stupid users.

Sorry for the interruption.

Andrew


"Shell access" I was gonna start my top tips and question ya need for shell access, but hey I is sure you have been given plenty of info already.

But I do wonder why ya blaming your host, if someone has just done a brut force attack and managed to get a password to an admin account, then the prob it with your lack of admin account naming conventions and password complexity rules not with the host.

Either way hooray for backups


rupewrecht - December 13th, 2006 at 11:08 AM

yay for the forums being back- even in a timewarp!


68AutoBug - December 13th, 2006 at 11:10 AM

Thanks Andrew...

Lee


vw54 - December 13th, 2006 at 12:00 PM

I wish i had the knowledge to catch n kick them up the arse

or do a similar thing to there computor and systems even better


MickH - December 13th, 2006 at 12:35 PM

Quote:
Originally posted by vwpete
Quote:
Originally posted by vanderaj
Hi there,

The host has been broken into due to someone using the same name and password on an account with shell access. The attacker probably used this to take over the system, and from there, destroy the entire server.

Most likely we're going to move to a better hoster with no other stupid users.

Sorry for the interruption.

Andrew


"Shell access" I was gonna start my top tips and question ya need for shell access, but hey I is sure you have been given plenty of info already.

But I do wonder why ya blaming your host, if someone has just done a brut force attack and managed to get a password to an admin account, then the prob it with your lack of admin account naming conventions and password complexity rules not with the host.

Either way hooray for backups



HeHe...do you know who you are giving advise to?? I'm sure Andrew and Brad are well aware of what they are doing..:thumb


pete wood - December 13th, 2006 at 12:45 PM

thanx for all the hard work Andrew.

cheers...:beer


MISS VDUB - December 13th, 2006 at 02:50 PM

Thanks heaps guys!

As always, love ya work, its appreciated by us all sooo much! :kiss

Ash x


oval TOFU - December 13th, 2006 at 03:27 PM

Thanks Andy, you rock (Zoolander style)


VWFOOL - December 13th, 2006 at 04:03 PM

2007 events are all gone


penguin - December 13th, 2006 at 07:29 PM

Well done to all you Admin folk who worked to get this back.


Joel - December 13th, 2006 at 08:19 PM

if theres one positive of this happening atleast the clock is on time now not 20 mins fast like it used to be


ashlogan - December 13th, 2006 at 09:27 PM

glad everything is sorted, i am a returning member that got very confised by all of these shenanigans.


Volkswagenboy - December 13th, 2006 at 09:33 PM

So what did you guys do?
Changed the oil to Shell oil? Sorry but I have no idea what has happened!!??!!??
-Staggers.


Notch Nut - December 13th, 2006 at 09:48 PM

Great work guys.:smilegrin:
- Adam


Schmoburger - December 13th, 2006 at 11:04 PM

I think I broke my wookie... :duh


vanderaj - December 16th, 2006 at 02:46 AM

Quote:
Originally posted by vwpete
"Shell access" I was gonna start my top tips and question ya need for shell access, but hey I is sure you have been given plenty of info already.


The other account is not run or owned by me, but by the hoster or someone else. If it was up to me, there would be no one else on our host.

Quote:

But I do wonder why ya blaming your host, if someone has just done a brut force attack and managed to get a password to an admin account, then the prob it with your lack of admin account naming conventions and password complexity rules not with the host.

Either way hooray for backups


Again, it's not us at fault. Security is my day job. If I had a choice in the matter, I would be completely running this system instead of someone who doesn't seem to give a crap. There are still crashed databases five or six days after the attack. Unacceptable.

Andrew


vwpete - December 17th, 2006 at 01:19 PM

Top quality
The host must be sweating, I wonder how many accounts got taken out?
You just gotta lov shared hosting plans!, but on the other hand if VM plans are out of reach for this forum and nobody here can patch a box or VM instance onto a DMZ for you. Then an occasionally hacked $10 per month hosting plan anint too bad.

Chances are your current host, has taken this as a bit of a wake up call and has sorted out its security issues.

By the way it was not my intention to “teach you to suc eggs” as it were so do accept my apology if that’s how my previous or current post came across.

Cheers Pete


jason1957 - December 18th, 2006 at 05:25 PM

Thanks Heaps Guys you do a great job with keeping this site going for all of us, now I just have to stay on it until tomorrow morning to get my lost posts back:mad:

And Again Thanks :thumb