![]() |
|
|
||||||||
| Forum Announcements Come here to learn of the latest and greatest events taking place at TFF. |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
![]() |
![]() |
|
| Level: 33 | HP: 70 / 802 |
|
EXP: 11% |
|
![]() |
#1 (permalink) | ||
|
Eye In The Sky
Join Date: Feb 1999
Location: Columbia, M-O-O
Posts
1,509
Gil: 1,356,788.59
![]() ![]() ![]() ![]() |
TFF was professionally hacked last night... and no it wasn't the stupid little Phish image that just replaced the index.html... this was far more elaborate.
Someone uploaded fake bank pages to TFF and redirected Barclay bank users to our servers IP to get financial information and other secure data... this is otherwise known as "Pharming". It is rather popular, especially to larger sites. I was even contacted by Cyota, which is the world's largest financial anti fraud firm. I sent them a .zip file of ALL the hacked files that were uploaded so they can hopefully track who did this. They told me hundreds of sites daily get Pharmed and it is quite the online epidemic. I have already changed FTP passwords and the CP password and other precautionary steps so this will not happen again. Just wanted to say sorry for the inconvenience and trouble. This is probably the most serious hack TFF has had in the 5 years we have been online. This will not happen again! I dont know why my host put up that 'excessive resources' message, because that wasn't the case... it was in fact b/c we were hacked... but TFF is having server usage issues that I am still working on. If I can't bring it down I will move TFF to a new server that has 'semi-dedicated' servers so we can move TFF to a server with more resources. More information on Pharming can be read here: http://www.azcentral.com/arizonarepu...harming19.html I'm still a noob to all of this and my apologies... I got the damn site up as QUICK as i could... even skipped 2 classes today. I gave everyone 250 gold pieces! enjoy |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 31 | HP: 227 / 759 |
|
EXP: 38% |
|
![]() |
#2 (permalink) | ||
|
I am what I am
Join Date: Feb 2006
Location: USA
Posts
1,320
Gil: 20,053.81
![]() ![]() ![]() ![]() |
Do we have to change our passwords too? And that is GAY! Goddamn hackers, they should die. No one hurts my TFF and gets away with it, *Rips off shirt revealing BoD tattoo*, ARGH MATEY!
P.S. - I <3 you got getting it back up. Let's help protect our beloved forum § Artist of blood stained walls
__________________
![]() New to role-playing? Looking to learn how to do it or improve your writing? Check out TFF's Official Role-playing Academy (<--Link). We accept everyone and have no requirements to join, only that you want to learn.
![]() |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 24 | HP: 80 / 594 |
|
EXP: 79% |
|
![]() |
#3 (permalink) | ||
|
Asian Sophomore Manga-ka
Join Date: Jun 2005
Location: BRB - I have a lot of projects and homework to do. So when I'm free I'll be back.
Posts
752
Gil: 63,922.54
![]() |
It's alright Fuzz at least I know TFF is safe now. When I tried getting into TFF there was this link that showed up, I think you have already found it by now, but I just want to tell you just in case.
http://www.sputnik.lunarpages.com After the slash mark it had something like 'suspended page'. I'm not too sure about it, but I think you can find out what it means. I hope this helps.
__________________
My Myspace Manga-ka / Creator of Levantine / Student / Future doctor / Friend / Adventurer of Life : I drew that avatar |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 27 | HP: 80 / 652 |
|
EXP: 10% |
|
![]() |
#4 (permalink) | ||
|
熱血のバダズ (hot blooded badass)
Join Date: Jun 2004
Location: In my mecha Soulgain, going Kirin on your evil heart
Posts
926
Gil: 53,830.33
![]() ![]() |
So that's what happened, eh? I thought TFF had kicked the bucket for good, I had a real scare there. But, they're messing with us, so I assume we should mess real bad with 'em, right?
To get it right, they used the second style of pharming, the "DNS poisoning", I assume? So that the users of TFF were sent somewhere else while the bank's users were sent here and then the info would be picked up by the hackers. C###, that's real bad... Besides, it affected both the main page and the forums. In my case, redirection was to a stargate.lunarpages, I think. I wasn't affected that much, tho. Different time zone.
__________________
New version? New, condensed, sig version 2.1.0!! Doc Rocco is a Freya fanboy, yet he cheats her for Edea Watch my works live! Updating upon request!! (What's with a little bit of shameless self-promotion, eh? ^__^) Siggy is here: |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 33 | HP: 70 / 802 |
|
EXP: 11% |
|
![]() |
#5 (permalink) | ||
|
Eye In The Sky
Join Date: Feb 1999
Location: Columbia, M-O-O
Posts
1,509
Gil: 1,356,788.59
![]() ![]() ![]() ![]() |
Yeah, sputnik.lunarpages.com is our current server node, so that would make sense... I believe the stargate address is just where suspended accounts get redirected to, not sure though.
Regardless, it is all worked out now. I even tracked the IP of the SOB that did this from the server logs and reported it to Cyota. It was a well done hack and it happens to a lot of sites, but I hope they can figure out some of the larger sources of these hacks. T. G - yeah, it was DNS Poisioning Pharming for sure... meaning they will change the IP or DNS entries on a real banking site and have the user be redirected to TFF to finish the account in a 'fake' database that was nested here. Really strange stuff for sure, took most of the day to fix. EDIT: No we dont have to change any forum passwords. I just had to change the admin control panel and main FTP account passwords, so don't worry about it, we're safe. |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 27 | HP: 137 / 662 |
|
EXP: 48% |
|
![]() |
#6 (permalink) | ||
|
Doing what you can't.
Join Date: Jan 2006
Location: Central Wisconsin
Posts
957
Gil: 25,933.20
![]() ![]() ![]() ![]() |
I have no idea what the hell you just said.
But hey. Damn good work getting it back up, and hopefully (though doubtfully), they'll track down who did it. And thanks for the gold! ![]()
__________________
![]() Sig courtesy of Plastik Assassin. In Honored Memory
SPC Thomas Day Caughman 3rd PLT A Co. 458 En. Bn. Baghdad, Iraq CPL Steven Shannon 1st PLT C Co. 397 En., TF 321 Ramadi, Iraq |
||||||||
|
|
|
||||||||
![]() |
![]() |
| Sponsored Links |
![]() |
![]() |
|
| Level: 66 | HP: 1630 / 1636 |
|
EXP: 47% |
|
![]() |
#7 (permalink) | ||
|
Head Administrator
Join Date: Aug 2002
Location: Mount Olympus
Posts
10,727
Gil: 2,304,291.17
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Heh, it's funny too, because I freaked the shit out of him this morning.
I called him while he was still sleeping or busy or something. It was about 10am. I saw the bandwidth exceeded notice, so I thought I would give Fuzz a call to let him know, right? I left a message explaining what I saw, and then I got a call back a couple hours later while I was at work. We weren't busy, so I answered it, and you all should have heard the string of profanities which left Fuzz's mouth. It was quite out of character, but I'll be damned if I wouldn't have reacted the same way myself. Anyway, he said he'd have the place back up and running before I got home from work, and sure enough, he was right. Props to Fuzz for sorting this shit out.
__________________
![]() 75 {Can I have it?} SOLDIER's back, babeh.
|
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 33 | HP: 70 / 802 |
|
EXP: 11% |
|
![]() |
#8 (permalink) | ||
|
Eye In The Sky
Join Date: Feb 1999
Location: Columbia, M-O-O
Posts
1,509
Gil: 1,356,788.59
![]() ![]() ![]() ![]() |
hahaha, yeah, Cesar heard the 'mad' Fuzz this morning.
I woke up and saw I missed a call from Cesar, so I knew right away something was up... because I figured he wasn't calling to say whats up at 10:00 in the morning. So i check TFF and of course it is down, then I have 5 different e-mails from my host, support guy, and a financial fraud firm located in the UK! I knew something serious happened... Took me 5 hours to get through all the e-mails, phone calls, and reorganizing all the files. I called you in a panic in the middle of all this, so I'm sure you heard some pretty fouuul language ^^ I was absolutely heated. |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 24 | HP: 80 / 594 |
|
EXP: 79% |
|
![]() |
#9 (permalink) | ||
|
Asian Sophomore Manga-ka
Join Date: Jun 2005
Location: BRB - I have a lot of projects and homework to do. So when I'm free I'll be back.
Posts
752
Gil: 63,922.54
![]() |
Must have been hard on you Fuzz, lol. I have never seen this side of Fuzz before, could you and Loco do a reanactment of what had happened? What kind of things would happen to TFF if the hacker had time to put some weird stuff on the forum? I'm just curious since I'm not really familiar with these kind of stuff.
__________________
My Myspace Manga-ka / Creator of Levantine / Student / Future doctor / Friend / Adventurer of Life : I drew that avatar |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 15 | HP: 19 / 373 |
|
EXP: 95% |
|
![]() |
#10 (permalink) | ||
|
World Maker, Sound Breaker
Join Date: Jul 2005
Location: Following the endless River stream of Time
Posts
291
Gil: 38,382.53
![]() |
I was wondering what happened, I totally freaked this Morning when the site was'nt working. Thanks for telling us fuzz, we should all work together to protect our forum from hackers!
__________________
Hand and Hand, Side by Side, We fight together forever Through time passes we will always share the same sun. " Wheither it be on the streets or in my home, i can still protect them with one sword." " No Matter how dark the night, morning always comes, and our journey begins anew." " I want the world to open its eyes and see the pain and suffering they are putting each other through, maybe then this nightmare will end." ~ Mike ~ The Ultima Knight ~ POKEMON DIAMOND AND PEARL RELEASES IN STORES ON SUNDAY APRIL 22th! RESERVE YOURS TODAY!
|
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 66 | HP: 1630 / 1636 |
|
EXP: 47% |
|
![]() |
#11 (permalink) | ||
|
Head Administrator
Join Date: Aug 2002
Location: Mount Olympus
Posts
10,727
Gil: 2,304,291.17
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Quote:
Quote:
__________________
![]() 75 {Can I have it?} SOLDIER's back, babeh.
|
||||||||
|
|
|
||||||||
![]() |
![]() |