Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Worrying
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Worrying

 Post Reply Post Reply Page  123 7>
Author
l15aRd View Drop Down
Groupie
Groupie


Joined: 24 May 2002
Location: England
Status: Offline
Points: 121
Post Options Post Options   Thanks (0) Thanks(0)   Quote l15aRd Quote  Post ReplyReply Direct Link To This Post Topic: Worrying
    Posted: 22 September 2003 at 5:12am

This is quite worrying, I've had an individual, who has gained access to the super moderators accounts, the DB is held outside of the HTML area, and we bounce all ports bar the 80,21,23.

so I'm thinking that they must have got the db somehow??? and decrypted it, he seem to have a problem decrypting password with numbers in them, so have advised all moderators to change their password.

Has anyone any ideas how they have managed to do this.

I've currently got a dialogue running with the indiviual in question (imation) and have his source IP's as he seem to know how to spoof his IP after he found out I had his source one, and has said he gonna let me know how he did it, but....

He' has openly appologised for any disruption he's cause and assured us that he hasn't used or changed any info he's found, which is a good thing....

Thanks in Advance



Edited by l15aRd

DrunkenTechie.net

You can logoff, but you can never leave
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 22 September 2003 at 6:10am
In what way has he gained access to admin accounts?

Has he managed to login as someone else?
Or has he changed his own account to be in the admin group?

If you can give more details or findout how he has done this then I can investigate further.
Back to Top
l15aRd View Drop Down
Groupie
Groupie


Joined: 24 May 2002
Location: England
Status: Offline
Points: 121
Post Options Post Options   Thanks (0) Thanks(0)   Quote l15aRd Quote  Post ReplyReply Direct Link To This Post Posted: 22 September 2003 at 6:23am

At first he just registered as a normal user, started sl*gging everyone off, so we deleted his account and banned his IP.

He then spoofed his IP and re-registered and started sl*gging again, again we deleted his account and banned that IP, and went to GoStats (hit/stats counter) and got his source IP and set a mail to his ISP(s).

He then somehow got and logged in as myself and deleted my account, which I restored the DB to the night befores backup

Changed my password to something else (all letters) and he logged in again as myself and posted abusive content, another email was sent to his ISP's and a post was put on my site informing that if he persisted I'd inform internic.

Changed my password again (leters and numbers, which he must have a prob with), he logged in as someone else and posted an apologie and that when I opened a dialogue with him/her to find out how he did it, also advised all members to change their passwords.

It's abit worrying isn't it, we did everything bar bounce his IP at the firewall(s), but chance are he/she'd have spoofed their way around it.


DrunkenTechie.net

You can logoff, but you can never leave
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 22 September 2003 at 9:32am
As passwords in version 7 (which I presume you are using) are 160bit one way encrypted it shouldn't be possible to retreive the password.

As he has trouble guessing the password if it contains numbers it sounds like he is using brute force and some password guessing tool to bombarded the server with passwords till the correc t password is guessed.

If this is the case it maybe that he is remotely attacking the login page with passwords till it is guessed. In which case make sure you are running version 7.01 which has anti-bot mesures in the login form to prevent this.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 22 September 2003 at 9:35am
Also make sure you are using passwords that are difficult to guess, which it sounds like you are doing, with letters and numbers. This will prevent the user guessing passwords.
Back to Top
l15aRd View Drop Down
Groupie
Groupie


Joined: 24 May 2002
Location: England
Status: Offline
Points: 121
Post Options Post Options   Thanks (0) Thanks(0)   Quote l15aRd Quote  Post ReplyReply Direct Link To This Post Posted: 22 September 2003 at 9:36am

I'm using 7.01, I agree with the brute force thing, most probably Lopthcrack or something similar.

also our firewall are set to reject ping requests, and buonce any port bar 80,21,23, it'll be interesting to find out how they're doing it...



Edited by l15aRd

DrunkenTechie.net

You can logoff, but you can never leave
Back to Top
l15aRd View Drop Down
Groupie
Groupie


Joined: 24 May 2002
Location: England
Status: Offline
Points: 121
Post Options Post Options   Thanks (0) Thanks(0)   Quote l15aRd Quote  Post ReplyReply Direct Link To This Post Posted: 22 September 2003 at 9:40am
how about adding a number of password tries into a future version then it suspends the account, pending an unlock by admin/moderators, abit like NT based network logins?

Edited by l15aRd

DrunkenTechie.net

You can logoff, but you can never leave
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 22 September 2003 at 9:42am
Your log files may give some clues for page requests for the file login_user.asp.

If he is using a tool on this page to guess passwords it may give some clue.

Also are you using SQL server or Access? If it is Access is the database outside of the web root?
Back to Top
 Post Reply Post Reply Page  123 7>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.