View Single Post
 
Old 02-23-2006, 04:13 PM Level: 33   HP: 69 / 804
Fuzz's HPFuzz's HP
  EXP: 16%
Fuzz's XPFuzz's XP
  #5 (permalink)
Fuzz
Eye In The Sky
 
Fuzz's Avatar
 

Join Date: Feb 1999
Location: Columbia, M-O-O

   Posts    1,514
        
Gil: 1,363,886.97

Fuzz jumps rope with Freya - (lv 5)Fuzz jumps rope with Freya - (lv 5)Fuzz jumps rope with Freya - (lv 5)Fuzz jumps rope with Freya - (lv 5)
Yeah, sputnik.lunarpages.com is our current server node, so that would make sense... I believe the stargate address is just where suspended accounts get redirected to, not sure though.

Regardless, it is all worked out now. I even tracked the IP of the SOB that did this from the server logs and reported it to Cyota. It was a well done hack and it happens to a lot of sites, but I hope they can figure out some of the larger sources of these hacks.

T. G - yeah, it was DNS Poisioning Pharming for sure... meaning they will change the IP or DNS entries on a real banking site and have the user be redirected to TFF to finish the account in a 'fake' database that was nested here.

Really strange stuff for sure, took most of the day to fix.

EDIT: No we dont have to change any forum passwords. I just had to change the admin control panel and main FTP account passwords, so don't worry about it, we're safe.
__________________
Webmaster @ thefinalfantasy.com
webmaster@thefinalfantasy.com
Fuzz is offline       
 
 
Page generated in 0.10648 seconds with 13 queries