Close
Page 1 of 2 12 LastLast
Results 1 to 10 of 14
  1. #1
    Man In The Box jhood001's Avatar
    Join Date
    Jan 2011
    Location
    Westminster
    Posts
    1,612

    Default Hacked by islamic extremists!

    One of my company's development servers along with two of our client's servers were just hacked.

    All files wiped out and islamic extremist propaganda put in its place. This means war!

    And similar to another attack on our country of another nature in the past, they didn't come from Iraq, Iran, Syria, Afghanistan, Libya, 'palestine', etc. They originated from Saudi Arabia.

  2. #2
    Fallen Member
    Join Date
    May 2010
    Location
    Smyrna, GA
    Posts
    6,748

    Default

    Quote Originally Posted by jhood001 View Post
    One of my company's development servers along with two of our client's servers were just hacked.

    All files wiped out and islamic extremist propaganda put in its place. This means war!

    And similar to another attack on our country of another nature in the past, they didn't come from Iraq, Iran, Syria, Afghanistan, Libya, 'palestine', etc. They originated from Saudi Arabia.

    Man that sucks.


    Here's to having a great disaster/CERT program in place!
    Bring up back up servers on seperate location, reroute DNS

    Pull those compromised servers down, amend firewall policies, path the intrusion, eliminate platforms, remove/replace drive, and NSA/DHS probably would like the drives that were compromised.

  3. #3
    Man In The Box jhood001's Avatar
    Join Date
    Jan 2011
    Location
    Westminster
    Posts
    1,612

    Default

    Quote Originally Posted by Byte Stryke View Post
    Man that sucks.


    Here's to having a great disaster/CERT program in place!
    Bring up back up servers on seperate location, reroute DNS

    Pull those compromised servers down, amend firewall policies, path the intrusion, eliminate platforms, remove/replace drive, and NSA/DHS probably would like the drives that were compromised.
    Fortunately, we don't have to do anything quite that elaborate. We had a copy of fckeditor's file manager without any restricted access to it. They just uploaded a .php file and ran the damn thing. Sloppy on our behalf, but we got'er fixed.

  4. #4
    Rebuilt from Salvage TFOGGER's Avatar
    Join Date
    Dec 2008
    Location
    Aurora
    Posts
    7,784

    Default

    Quote Originally Posted by Byte Stryke View Post
    Man that sucks.


    Here's to having a great disaster/CERT program in place!
    Bring up back up servers on seperate location, reroute DNS

    Pull those compromised servers down, amend firewall policies, path the intrusion, eliminate platforms, remove/replace drive, and NSA/DHS probably would like the drives that were compromised.
    You forgot "trace IP, send 100 pounds of bacon wrapped C4"...
    Light a fire for a man, and he'll be warm for a day, light a man on fire, and he'll be warm for the rest of his life...

    Discussion is an exchange of intelligence. Argument is an exchange of
    ignorance. Ever found a liberal that you can have a discussion with?

  5. #5
    Machine Gunner Hoosier's Avatar
    Join Date
    Nov 2009
    Location
    Stone City
    Posts
    1,518

    Default

    Quote Originally Posted by jhood001 View Post
    Fortunately, we don't have to do anything quite that elaborate. We had a copy of fckeditor's file manager without any restricted access to it. They just uploaded a .php file and ran the damn thing. Sloppy on our behalf, but we got'er fixed.
    I used to use that piece of software, behind a user/pass wall.

    Did they get shell access? Did you look for root kits? Unless you're running the latest and greatest Linux it's pretty likely that once they have a local shell they can find an exploit to elevate privileges and install a root kit. This isn't something they have to be a master hacker for, just copy/paste commands off websites and any retard can be hacking.

    Honestly I don't think I'd trust the box again. In this day and age it is (should be) far easier to just blast off and nuke the site from orbit. It's the only way to be sure.

    H.

  6. #6
    Fallen Member
    Join Date
    May 2010
    Location
    Smyrna, GA
    Posts
    6,748

    Default

    Quote Originally Posted by Hoosier View Post
    I used to use that piece of software, behind a user/pass wall.

    Did they get shell access? Did you look for root kits? Unless you're running the latest and greatest Linux it's pretty likely that once they have a local shell they can find an exploit to elevate privileges and install a root kit. This isn't something they have to be a master hacker for, just copy/paste commands off websites and any retard can be hacking.

    Honestly I don't think I'd trust the box again. In this day and age it is (should be) far easier to just blast off and nuke the site from orbit. It's the only way to be sure.

    H.

    /agree... why I Said bring up the back up servers.

    if they dont have that kind of resource, at least nuke/pave and restore from a previous backup. fix the exploit and then bring it back on line

  7. #7
    QUITTER Irving's Avatar
    Join Date
    Nov 2008
    Location
    Denver, CO
    Posts
    46,527
    Blog Entries
    1

    Default

    You should back trace them.
    "There are no finger prints under water."

  8. #8
    65 yard Hail Mary
    Join Date
    Oct 2010
    Location
    Parker CO
    Posts
    2,981

    Default

    Quote Originally Posted by Irving View Post
    You should back trace them.
    And then find their location and send them some Tactical Bacon.

  9. #9
    Beer Meister DFBrews's Avatar
    Join Date
    Dec 2010
    Location
    With the classyish Hipsters...Stapleton
    Posts
    3,175

    Default

    Quote Originally Posted by mcantar18c View Post
    And then find their location and send them some Tactical Bacon.
    why waste good bacon pickled pigs feet should be more than adequate.
    You sir, are a specialist in the art of discovering a welcoming outcome of a particular situation....not a mechanic.

    My feedback add 11-12 ish before the great servpocaylpse of 2012

  10. #10
    Man In The Box jhood001's Avatar
    Join Date
    Jan 2011
    Location
    Westminster
    Posts
    1,612

    Default

    Thank you fall for your advice...

    After much deliberation, I'm going with the pickled pigs feet. I'm keeping my god-damned bacon.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •