Yes, the site was down for a while.

Discussion in 'Site Feedback' started by DarkUnderlord, Sep 13, 2006.

Remove all ads!
Support Terra-Arcanum:

GOG.com

PayPal - The safer, easier way to pay online!
  1. DarkUnderlord

    DarkUnderlord Administrator Staff Member

    Messages:
    4,315
    Likes Received:
    5
    Joined:
    Nov 10, 2001
    Everything's back up now but we went down for a while yesterday. Somehow or another (still looking into it) we were hacked. The hack was running processes on the server. The website went down because we (and by we I mean Taluntain) took it offline to stop it.

    The files:
    • .log/jancok.pl
      .log/jancok.conf
      .log/jancok
    ... ended up in directories in the wiki (/images) and phpBB (/pafiledb) so I've upgraded everything as a result. It appears the hack got through an exploit in the wiki image uploading and an exploit in the pafiledb download mod. As the download mod doesn't appear to have an upgrade, it'll stay offline until such time as I either find one or find an alternative. Everything else should be back online and operational though. Let me know if you run into any problems.

    EDIT: Looks like there's been an exploit in the phpBB PAFileDB mod all along. There was an IRC bot hidden in there which I'm willing to bet is what allowed someone to upload these other scripts. PAFileDB itself as a stand-alone extension looks to be okay but the integration mod for phpBB is riddled with flaws.
     
  2. Frigo

    Frigo Active Member

    Messages:
    2,107
    Likes Received:
    0
    Joined:
    Jan 21, 2006
    on a side note, there's an exploit to even the newest (2.0.21) phpbb, but I don't know details
     
  3. Maximus

    Maximus New Member

    Messages:
    1,306
    Likes Received:
    0
    Joined:
    Mar 1, 2006
    The Avenging Angel (Hellbokos) was threatening the site and many of us a few days ago. Was it him?
     
  4. DarkUnderlord

    DarkUnderlord Administrator Staff Member

    Messages:
    4,315
    Likes Received:
    5
    Joined:
    Nov 10, 2001
    Could've been. I doubt it though. Usually the 12 year olds who threaten us after they've been banned try and take us down and replace the front page with an "OMG Haxx0r3d by teh |33+ k|dd|3", not run scripts in the background which clog up the server. This looks more like a fairly typical hack. Bot operated and not targeted at us specifically but usually using google to trawl for susceptible sites.
     
  5. TONGSyaBASS

    TONGSyaBASS Member

    Messages:
    772
    Likes Received:
    0
    Joined:
    Apr 19, 2005
    I liked the "don't panic" announcement.

    TA will be coming back soon.

    --The Management
     
  6. Maximus

    Maximus New Member

    Messages:
    1,306
    Likes Received:
    0
    Joined:
    Mar 1, 2006
Our Host!