Announcement

Collapse
No announcement yet.

Blasted minis

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    Oh, no, Brian... I didn't think you were objecting to me particularly, or even doing anything but offering another point of view...

    That's fine.

    But you ought to know by now that I never pass up an opportunity to tell you lot what your Mod thinks about issues facing the forums.

    <hr>
    Andrew-- sorry to have alarmed you. It's one of my charming quirks to make sweeping generalizations like "Blasted Minis" while at the same time meaning only a few. The few "minis" of the type that get on my nerves are in fact easy to identify-- and would get on your nerves too, I bet. You know the kind-- don't listen, don't take instruction, a lot of loud bluster-- basically bulls in a china shop.

    Not only are you personally not like that, but you all should know, if you don't, that I would <u>never, ever, ever</u> "talk about you" behind your back. If I had a problem with you in my capacity as a Moderator, if somehow you didn't already know it in the thread we were in, I would email you. These forums were not built on, and would not survive with, the kind of sneaky, backstabbing behaviour you see on &lt;shudder&gt; Usenet...

    <hr>
    <font size=6><center>Thanks, Pauly!!! </center></font><hr>
    And since the thread is down (as is MHW), here's the summary of what happened.

    Some joker posted a new thread (called "hacked") in MHW Sunday...as the admin. Ant was out (having fun in his regular life!) for the day, but Kruzin was there immediately, and Jorden and I (speaking of mods involved) showed up shortly after. So did a LOT of members.

    This guy had broken into our UBB and given himself Admin privileges, in order-- he said-- to "help" us. He felt that this hard proof that our site was not secure would ensure that the hole in UBB was fixed.

    We said, "You know, you could have flippin' emailed Ant and told him, you didn't have to hack our site, dammit!" He said he had emailed Ant but that Ant hadn't responded.

    Meanwhilst, several members were backtracking him to find out who he was... he had made no attempt to hide his identity, nor had he damaged the site, because, in his words, he's a "decent guy", who "respects other people's property". People started posting his info: he's a 17 year old Dutch guy who had (at the time the info we found was posted) a small computer shop (later closed). A small argument began among the members as to whether he was a bad guy or not; apparently a few people felt that this was a good tactic to inspire Ant to take greater security measures. Most of us did not agree.

    Then the hacker admitted that he had <u>downloaded all our passwords</u>!!!

    This was a horse of a different color, obviously. Now the tone changed, as we (almost) all-- most of his "supporters" here fell away at this news-- tried to explain to him why what he had done was completely wrong. He did not get it. Somewhere in there was when I posted this thread in The 'Box, knowing that he probably was paying no attention to such a *cough*useless*cough* forum... and I posted nothing under my mod nick-- though he had my mod password, I hoped that he wasn't bothering to pull files on anyone who didn't "get in his face". So I figured that he didn't know who I was, since he had only found out about the forums the day before and had no experience with us. I've since heard that that dodge didn't work. Mostly I hoped that the longer we kept him online and talking, the more info we could get on him for any later prosecution-- and afaik, that <u>did</u> work .

    The fight went on. Our new friend was shocked at the massive resistance he encountered ( Long live the MURC!!! ), and his facade of "decency" began to crack. He <u>locked the thread</u> and demanded that we contact him by ICQ or email if we wanted to "debate 'ethical hacking'", as he called it.

    Kruzinn reopened the thread , and we both blasted him for his actions, reminding him that these were our forums and we could discuss any damn thing we chose.

    Sometime late in page 3 (the thread ultimately made it to 4 pages, some 116 posts), Ant came home, banned the guy and started cleaning up. Don't know when the threads were deleted, nor when MHW was taken down (Jord has since told me that MHW was locked at 15:29 GMT +1), nor who did so.

    I do know that a number of people (so far I've heard of at least 5) who found attacks in their firewall logs from IP addresses near his. Apparently he called some unethical friends and attacked some of us. Poor dZeus, who had asked him to help with security on his own server (when we thought he was a "nice" guy) was taken completely out of play and had to go to a friend's house to use their PC.

    So as Jord says, don't change your PW yet until we know that this ---blasted mini -- is locked out of our house and keep an eye on your firewall logs. Change other passwords, if they're the same as your MURC pw-- wouldn't want him reading your mail . Take whatever other security measures you see fit.

    Oh and remember: if you find any such problems on the forum-- hackers, downtime, those damn slow ads-- we are each and all allowed and advised to <u>email GA</u> (our hosts) at admin@gagames.com. Naturally, you can also email Ant or the mods and we'll forward it as well.

    <font size=5>If you posted on the forums (thereby logging your IP, which he had access to), and there was an attempted hack on your PC after the 20th (the date he said he emailed Ant), email Ant, any moderator, or GA with the IP you were hacked from!!!!</font>

    It was a hell of a day, frankly. Blows that whole "Aureal/Real/Netscape is spying on you" thing right out of the water, huh ?

    -----------------------------
    Holly



    [This message has been edited by motub (edited 24 July 2000).]
    Holly

    "All we need is a voluntary, free-spirited, open ended program of procreative racial deconstruction."
    -Jay Bulworth

    Comment


    • #17
      Holly, as the MHW forum is down an I am unable to re-read the thread, can you remind me/us what the IP addresses he was suspected of using.

      If he takes down my site I will be annoyed but not that bothered, If he does anything to do with my Companies site then that's a different matter!
      When you own your own business you only have to work half a day. You can do anything you want with the other twelve hours.

      Comment


      • #18
        Taz, the suspected IP address is anything going back to a Telekabel.Chello.nl address. (starts off with 212.187.xxx.xxx)

        Jord.
        Jordâ„¢

        Comment


        • #19
          Thanks Jorden, I installed ZoneAlert on Sunday just in case and it's been throwing up some security alerts. One of the IP addresses is for a Lycos Server, quite why it's trying to contact me I don't know. The other address is 216.33.125.196 which I haven't managed to trace yet. Jeez it's enough to make you paranoid
          When you own your own business you only have to work half a day. You can do anything you want with the other twelve hours.

          Comment


          • #20
            A lot of those are probably ad banners trying to d/l cookies, I think, Taz.
            Holly

            "All we need is a voluntary, free-spirited, open ended program of procreative racial deconstruction."
            -Jay Bulworth

            Comment


            • #21
              eeep, I thought I had done something wrong, I was so worried when at school I read your post but had to go and so couldn't read who you were annoyed at, I saw teenager and mini and I thought, I'm one of the only teenage minis, uh-oh what've I done, I can never post here agin. Thank god it wasn't me.
              P3 500 @ 600
              256MB PC133 RAM
              64MB PC100 RAM
              Primary: Gateway EV700 17"
              Secondary: AcerView 54eL 15"
              WinXP Professional Build 2600 (with Plus!, it's prettified!)
              G400 MAX (@ 171, 228)
              Monster Sound MX400
              512/128 DSL from SMC EZ Card
              Samsung 8X DVD-ROM
              ASUS P3B-F
              Logitech X1 Speakers
              Logitech Cordless Mouse SE
              Logitech Internet Keyboard
              19.1G IBM 60GXP
              8.4G Seagate
              1.57G Fujitsu

              Comment


              • #22
                Hmmm....

                Unfortunately my hardware firewall doesn't log. Ohwell....

                Dr. Mordrid

                Comment


                • #23
                  Taz, the suspected IP address is anything going back to a Telekabel.Chello.nl address. (starts off with 212.187.xxx.xxx)
                  That's like, 25% of the people in holland who have cable-internet.

                  Comment


                  • #24
                    Yeah but 25% of the people in Holland aren't trying to hack me and other members.

                    What, you think we're on some kind of witchhunt and we're going to hunt down and eat everyone from the same IP?

                    I mean, geez Rick, we know who this person is; he made no attempt to hide his identity (part of his "statement").

                    I'm just warning people that they may be at a higher risk than usual for outside intrusion.

                    ---------------------------
                    Holly

                    Comment


                    • #25
                      Don't know if this is related but on the 23'rd ZoneAlarm recorded the following:

                      FWIN,2000/07/23,21:35:26 -8:00 GMT,216.32.144.88:80,209.53.140.58:1094,TCP
                      FWIN,2000/07/23,21:36:00 -8:00 GMT,216.32.144.88:80,209.53.140.58:1105,TCP
                      FWIN,2000/07/23,21:36:30 -8:00 GMT,216.32.144.88:80,209.53.140.58:1070,TCP
                      FWIN,2000/07/23,21:36:36 -8:00 GMT,216.32.144.88:80,209.53.140.58:1100,TCP
                      FWIN,2000/07/23,21:36:42 -8:00 GMT,216.32.144.88:80,209.53.140.58:1059,TCP
                      FWIN,2000/07/23,21:37:00 -8:00 GMT,216.32.144.88:80,209.53.140.58:1098,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1037,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1041,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1048,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1057,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1060,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1062,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1066,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1069,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1073,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1076,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1045,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1096,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1107,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1033,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1036,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1039,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1043,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1046,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1050,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1051,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1054,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1056,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1064,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1068,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1075,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1091,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1095,TCP
                      FWIN,2000/07/23,21:45:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1101,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1032,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1034,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1040,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1044,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1047,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1052,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1055,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1061,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1065,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1072,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1077,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1097,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1092,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1104,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1111,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1106,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1110,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1124,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1081,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1031,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1035,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1038,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1042,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1053,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1058,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1063,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1067,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1074,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1078,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1049,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1093,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1099,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1102,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1108,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1115,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1122,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1089,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1087,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1117,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1071,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1083,TCP
                      FWIN,2000/07/23,21:45:44 -8:00 GMT,216.32.144.88:80,209.53.140.58:1088,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1114,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1118,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1119,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1123,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1079,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1082,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1116,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1103,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1109,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1120,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1121,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1125,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1080,TCP
                      FWIN,2000/07/23,21:46:14 -8:00 GMT,216.32.144.88:80,209.53.140.58:1090,TCP


                      Now this obviously isn't a 212 address but as I understand it hackers can use other address to run probes from?

                      Comment


                      • #26
                        Hi people,

                        I don't know the full story yet, but from the little I've read, could we have been a bit harsh on him?

                        Could he have done some real damage? Did he send any bogus posts?

                        I'm firmly against security by obscurity and I think demonstrated exploits are the best wake up call. But I still would'nt personally do it his way, prefering to inform a moderator or webmaster privately, demonstrating the exploit.

                        What better way to show web masters, moderators and users an insecurity, than by showing it being exploited for real.

                        PS, will banning him help since he has our passwords? The passwords are'nt encrypted?

                        Did he describe the hole?

                        Secure systems often get there thanks to guys that break 'n' tell (Sure, a private 'tell' would have been nicer, but what could he 'tell' without first a 'break'?).



                        ------------------
                        Linux /,Lin 'ucks/, n.1. able to be trusted; dependable.
                        2. (tr.) to make safe from attack. 3. having great power.
                        4. extremely effective or efficient.5. Adaptable or variable:
                        flexible OS
                        6.a. not enslaved or confined. b. to remove
                        obstructions or impediments.
                        Linux /,Lin 'ucks/, n.1. able to be trusted; dependable.
                        2. (tr.) to make safe from attack. 3. having great power.
                        4. extremely effective or efficient.5. Adaptable or variable:
                        flexible OS
                        6.a. not enslaved or confined. b. to remove
                        obstructions or impediments.

                        Comment


                        • #27
                          Shane:

                          I don't think we're being too harsh on him, we never asked him to try and hack the forums.

                          How would you like to come home one day, and finding some guy sitting in your living room telling you that he didn't take anything, but you really should change your locks ?

                          Some people can't seem to understand that the Internet isn't their playground.
                          "That's right fool! Now I'm a flying talking donkey!"

                          P4 2.66, 512 mb PC2700, ATI Radeon 9000, Seagate Barracude IV 80 gb, Acer Al 732 17" TFT

                          Comment


                          • #28
                            I'd like to place an order for 1 Supersized Monkey Brains, with extra cheese please!

                            On a side note you can goto Firewall Guide for info on protecting yourself while online.
                            "Be who you are and say what you feel, because those who mind don't matter, and those who matter don't mind." -- Dr. Seuss

                            "Always do good. It will gratify some and astonish the rest." ~Mark Twain

                            Comment


                            • #29
                              Hehe, CHHAS. That's probably the most fitting analogy yet.

                              ------------------
                              Ace

                              "..so much for subtlety.."

                              System specs:
                              Gainward Ti4600
                              AMD Athlon XP2100+ (o.c. to 1845MHz)

                              Comment


                              • #30
                                But if that same person is waving a gun, would you scream at him?... ya that's the ticket... BOOM you're dead.
                                "Be who you are and say what you feel, because those who mind don't matter, and those who matter don't mind." -- Dr. Seuss

                                "Always do good. It will gratify some and astonish the rest." ~Mark Twain

                                Comment

                                Working...
                                X