Forum of Doom wrecked by vandals

Want to promote your fantasy football website, here's the place.

Moderator: TFF Mods

Post Reply
IronAge_Man
Veteran
Veteran
Posts: 267
Joined: Tue Jul 09, 2002 12:32 pm
Location: Northern Ireland
Contact:

Forum of Doom wrecked by vandals

Post by IronAge_Man »

It looks like the Forum of Doom, home of the forums for Heresy, Spyglass and Hasslefree Miniatures has been totalled by some script kiddies.

I hope Andy Foster had some backups.

:(

http://www.heresyminiatures.com/news2.htm

Reason: ''
Emberbreeze
Super Star
Super Star
Posts: 788
Joined: Thu Feb 19, 2004 7:10 pm
Location: Bracknell, Berks
Contact:

Post by Emberbreeze »

Hope they can restore the database :(

Reason: ''
[size=150][color=#FF3333][b]Hag Graef Dragons[/b][/color][/size] [size=117]1st UK :wink: NAF Dark Elf Coach[/size]
[size=150][color=#FF3333][b]Silvania Suckers[/b][/color][/size] [size=117]Most experienced :wink: NAF Vampire Coach[/size]
User avatar
Chairface
Da Fig Finda
Posts: 5399
Joined: Fri Jul 25, 2003 3:18 pm
Location: London Ontario Canada

Post by Chairface »

Andy just sent this out:

Hi all!

Bad news first then - the Forum of Doom got hacked again, this time
not a worm, it was done deliberately by some bored german teenagers
(I assume teenager). Apparently declaring themselves to be members
of "team Infinity" (http://www.inf.hitdemon.com) they have wiped the
database etc and replaced it with a charming message exulting in
their work. The main site was not affected, so I assume it was some
sort of weakness in the version of phpbb2 I was running. If any of
my german customers can find out more info for me, there are some
clues to follow: fortunately, Artemis Black was browsing the forum
as it was hacked, spotted the weird new member name and noted the
IP. The IP address, 134.76.122.71 can be traced to a german
university and the webaddress/ip thingy of dfnhome171.gwdg.de. This
led to:

Georg-August-Universität
Wilhelmsplatz 1 (Aula)
37073 Göttingen
Tel. +49 (0)551 / 39-0
Fax +49 (0)551 / 39-4135
poststelle@uni-goettingen.de

Not that I expect to get anywhere with this line of enquiry, but you
never know, I've emailed them and we'll see if they can help. Anyone
who knows about this sort of thing please do email me at the regular
address if you can help track the person down, or advise me as to
what the security issue was. andy@heresyminiatures.com

Of course, the tech support poeple have gone home so I have to wait
until tomorrow to find out if the database can be restored via some
handy back-up or not...if not we'll unfortunately have to reboot the
FoD

The Good News:

Salute 2005 is on Saturday! We'll be there (maybe not awake, but
definitely there), just opposite the main door and slightly to the
left, next to Ainsty Casting and our friends Hasslefree Miniatures!
We're madly casting stuff still, but if anyone wants to place an
order to pick up on the day, do let us know by thursday!

The Netherlord is really on its last legs now: the moulds are almost
dead and the flash is becoming quite unsightly - this is definitely
your last chance to order one of these masive demons. I'll be
replacing it with some new sculpts later this year, all going well!

More news soon!

Andy Foster
Heresy

Reason: ''
http://www.impactminiatures.com
User avatar
Chairface
Da Fig Finda
Posts: 5399
Joined: Fri Jul 25, 2003 3:18 pm
Location: London Ontario Canada

Post by Chairface »

Which is exactly what was in Iron Man's link. :oops: Sorry!

Reason: ''
http://www.impactminiatures.com
User avatar
DoubleSkulls
Da Admin
Posts: 8219
Joined: Wed May 08, 2002 12:55 pm
Location: Back in the UK
Contact:

Post by DoubleSkulls »

There is a vulnerability in some older versions of phbBB so you ought to update to the latest version.

The IP address is probably entirely innocent. A competent hacker would just be using them to route through. Of course if its stupid kids they could have left a trail...

Reason: ''
Ian 'Double Skulls' Williams
Pink Horror
Emerging Star
Emerging Star
Posts: 501
Joined: Tue Jun 26, 2001 12:00 am
Location: San Jose, CA

Post by Pink Horror »

ianwilliams wrote:The IP address is probably entirely innocent. A competent hacker would just be using them to route through. Of course if its stupid kids they could have left a trail...
I've never heard of a competent hacker.

Reason: ''
Post Reply