Go to Post your time is better spent in the stands, watching what the robots actually do, as opposed to listening to the builders talk about what they're [I]supposed[/I] to do. - sanddrag [more]
Home
Go Back   Chief Delphi > Technical > IT / Communications > Website Design/Showcase
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Closed Thread
 
Thread Tools Rate Thread Display Modes
  #1   Spotlight this post!  
Unread 24-10-2007, 16:48
Scott L.'s Avatar
Scott L. Scott L. is offline
Registered User
FRC #0222 (Tigertrons)
Team Role: Engineer
 
Join Date: Sep 2003
Rookie Year: 1998
Location: Tunkhannock PA
Posts: 290
Scott L. is just really niceScott L. is just really niceScott L. is just really niceScott L. is just really niceScott L. is just really nice
Send a message via AIM to Scott L.
Talking Re: Hacked

DDNS:
http://www.EditDNS.net is another good dynamic DNS, it works with domains like abc.xyz
Where abc is the Second level domain and xyz is the top level domain.
Its free to use and alows control over the A, AAA, MX, NS, SRV, CNAME
More advanced features cost $6 for 6 months access to setup, but once set you don't need to pay after the 6 months unless you need to change a more advanced feature. I use the free service with my self hosted web sites and it works great.

Hosting:
The company I work with uses host rocket to host theirs and their customers sites on.
http://www.hostrocket.com/
They have 24/7 tech support (Actually called at 2am on Saturday)

Misc:
I haven't had much php or mySQL experience yet (I use SQL express and ASP.net 2.0), but would recomend making sure everything is up to date, and recheck all settings for any possible security holes.

I have two dual Xeon 2.6GHz HT (Device manager shows 4 CPUs) servers each with 1GB of Ram, striping Raid on Data Drives (SCSI LVD), 250GB SAN Storage for backups, VPN/Firewall router between servers and Internet
I used one of these servers to host the live web cast of PARC X.
__________________
You can do anything, if you put your mind to it!!!
http://asp.shinraikon.com
  #2   Spotlight this post!  
Unread 25-10-2007, 00:40
Tristan Lall's Avatar
Tristan Lall Tristan Lall is offline
Registered User
FRC #0188 (Woburn Robotics)
 
Join Date: Aug 2001
Rookie Year: 1999
Location: Toronto, ON
Posts: 2,484
Tristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond reputeTristan Lall has a reputation beyond repute
Re: Hacked

Just to prove that Jacob's suggestion works, I'm making this post on my university's Windows Server 2003 terminal server, connected over Remote Desktop to a Windows XP virtual machine, which is itself connected over Remote Desktop to a Windows 98 virtual machine. Both VMs are running locally on Windows Vista (no, I didn't nest those too). It all seems to work pretty well (if you can tolerate 8-bit colour).
  #3   Spotlight this post!  
Unread 25-10-2007, 11:59
EHaskins EHaskins is offline
Needs to change his user title.
AKA: Eric Haskins
no team (CARD #6 (SCOE))
Team Role: College Student
 
Join Date: Jan 2006
Rookie Year: 2006
Location: Elkhorn, WI USA
Posts: 998
EHaskins has a reputation beyond reputeEHaskins has a reputation beyond reputeEHaskins has a reputation beyond reputeEHaskins has a reputation beyond reputeEHaskins has a reputation beyond reputeEHaskins has a reputation beyond reputeEHaskins has a reputation beyond reputeEHaskins has a reputation beyond reputeEHaskins has a reputation beyond reputeEHaskins has a reputation beyond reputeEHaskins has a reputation beyond repute
Send a message via MSN to EHaskins
Re: Hacked

Quote:
Originally Posted by Tristan Lall View Post
Just to prove that Jacob's suggestion works, I'm making this post on my university's Windows Server 2003 terminal server, connected over Remote Desktop to a Windows XP virtual machine, which is itself connected over Remote Desktop to a Windows 98 virtual machine. Both VMs are running locally on Windows Vista (no, I didn't nest those too). It all seems to work pretty well (if you can tolerate 8-bit colour).
You can change the color settings. Open the RDC windows, click "Options", Click the "Display" tab, and change it.
__________________
Eric Haskins KC9JVH
  #4   Spotlight this post!  
Unread 24-10-2007, 06:32
Timothy D. Ginn's Avatar
Timothy D. Ginn Timothy D. Ginn is offline
I check here maybe once a year.
no team
 
Join Date: Apr 2003
Rookie Year: 2002
Location: Port Perry, ON. Canada
Posts: 247
Timothy D. Ginn is a name known to allTimothy D. Ginn is a name known to allTimothy D. Ginn is a name known to allTimothy D. Ginn is a name known to allTimothy D. Ginn is a name known to allTimothy D. Ginn is a name known to all
Send a message via ICQ to Timothy D. Ginn Send a message via AIM to Timothy D. Ginn Send a message via MSN to Timothy D. Ginn Send a message via Yahoo to Timothy D. Ginn
Re: Hacked

I'm surprised that so far people have missed the obvious step of first looking at what you've got that you control before assuming that the problem is with the host (which it may well be, but, that shouldn't be the first thing to check for).

Questions you should ask yourself include:
What software do you have installed in your webspace? (check and make sure there aren't little temporary things installed just for testing that were never removed and never properly secured, this happens often)
Is it up to date? (this can especially be a problem if your team is using a CMS or old versions of phpBB2 or other forum software)
If what you've got is custom written, has it been checked over by someone knowledgable other than just the person who wrote it? If not, maybe it's time to audit it.
Assuming you have access to the web server access logs and error logs, read them carefully for the period of time before the last time you had problems. If the exploit is attacking something your team has control over, it's likely to appear strange and show up there. Be especially vigilant for things like phpShell and such which you don't recognize as being part of a normal type of request.
__________________
Alumni of FRC Team 1006
Former mentor of Full Lego Alchemist (FLL 5621) - Sempar School / Computing Students' Association of Queen's University
  #5   Spotlight this post!  
Unread 24-10-2007, 08:02
robostangs548's Avatar
robostangs548 robostangs548 is offline
Team 548 General Motors Robostangs
AKA: Mason Falk
FRC #0548 (General Motors Robostangs)
Team Role: Mentor
 
Join Date: Dec 2006
Rookie Year: 1999
Location: Northville
Posts: 421
robostangs548 has a brilliant futurerobostangs548 has a brilliant futurerobostangs548 has a brilliant futurerobostangs548 has a brilliant futurerobostangs548 has a brilliant futurerobostangs548 has a brilliant futurerobostangs548 has a brilliant futurerobostangs548 has a brilliant futurerobostangs548 has a brilliant futurerobostangs548 has a brilliant futurerobostangs548 has a brilliant future
Send a message via AIM to robostangs548
Re: Hacked

I have been using bravehost.com for close to 5 years now, and I have NEVER ran into something like this. It may cost a little more (I pay $4.99/mo with 30gig of space and 600gig of bandwidth) but I have had absolutely no problems with there service. If you ask me, there setup is the cleanest easiest to work with, and most secure setup that is out there. Check it out, I would definitely say that they are my favorite, because I also have a godaddy.com and hostmonster.com hosting account, but I am definitely gona switch them over, because I really was not impressed with there service. But seriously, that is ridiculous.
__________________
Mason Falk (Team 548)
General Motors Proving Grounds Robostangs
Northville, MI USA
  #6   Spotlight this post!  
Unread 24-10-2007, 08:55
wilsonmw04's Avatar
wilsonmw04 wilsonmw04 is online now
Coach
FRC #1086 (Blue Cheese)
Team Role: Teacher
 
Join Date: Dec 2006
Rookie Year: 2007
Location: Midlothian, VA
Posts: 1,884
wilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond repute
Re: Hacked

another site that I admin was hacked in the same way fairly recently. They replaced my site with some stupid splash screen, with the fools handle, a Turkish flag and a scrolling banner stating how "uber" this guy/gal was.

After some digging, We found that this person was exploiting a weakness in phpbb we were using. After updating the software, we haven't had a problem. no matter what you do you will always have a problem with security if you use a popular piece of software.
__________________
Currently: Coach FRC 1086/FTC 93
2006-2011 Coach FRC 2106/FTC 35
If you come to a FRC event to see a robot competition, you are missing the point.
  #7   Spotlight this post!  
Unread 24-10-2007, 10:20
whytheheckme's Avatar
whytheheckme whytheheckme is offline
Registered User
AKA: Jacob Komar
no team
 
Join Date: Feb 2006
Rookie Year: 2005
Location: Providence, RI
Posts: 1,320
whytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond reputewhytheheckme has a reputation beyond repute
Send a message via ICQ to whytheheckme Send a message via AIM to whytheheckme Send a message via MSN to whytheheckme Send a message via Yahoo to whytheheckme
Re: Hacked

It appears that this site is very cleancut and is lacking 3rd party apps (less the Google Gadget app, but I doubt there is a security problem in that). I looked at the source code, and everything looks HTML and Javascript.

Then I found forum.punahourobotics.org
It appears that they have the latest version of Simple Machines.

But I got to thinking, doesn't Simple Machines use MySQL, and PHP? That must mean that there is a MySQL server running on box188.bluehost.com, and perhaps this is the security hole. Check your MySQL version and patches, make sure it's all up to date.

What's odd is that a hacker would put this much effort into splashing a robotics team's website. Seems like it would be a fairly low-target kind of domain to hit.

Jacob
  #8   Spotlight this post!  
Unread 24-10-2007, 11:39
wilsonmw04's Avatar
wilsonmw04 wilsonmw04 is online now
Coach
FRC #1086 (Blue Cheese)
Team Role: Teacher
 
Join Date: Dec 2006
Rookie Year: 2007
Location: Midlothian, VA
Posts: 1,884
wilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond reputewilsonmw04 has a reputation beyond repute
Re: Hacked

What they do is troll the internet looking for large hosting systems. Most of their accounts are small and use PhP Or MySQL. They don't care how big or small the site is. They do it for kicks.

Why do folks spray paint builds? Because they have brains no bigger than your average canine...
__________________
Currently: Coach FRC 1086/FTC 93
2006-2011 Coach FRC 2106/FTC 35
If you come to a FRC event to see a robot competition, you are missing the point.

Last edited by wilsonmw04 : 24-10-2007 at 16:00.
Closed Thread


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
pic: Hacked Google Camera #1 Alex698 Extra Discussion 7 12-03-2006 13:32
pic: Hacked Google Camera Picture #2 Alex698 Extra Discussion 8 12-03-2006 00:17
Our forum has been hacked Shlomi32 Website Design/Showcase 1 27-01-2006 01:19
Hacked! Denman Website Design/Showcase 19 18-07-2004 12:04


All times are GMT -5. The time now is 16:02.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi