Site Sabotaged. Post Mortem in progress
#1
Site Sabotaged. Post Mortem in progress
It appears that somebody decided to try to sabotage the site. Thankfully I was able to restore it relatively quickly from a backup but I have no idea how long it was down. 

Due to the nature of this I'm going to require some time to figure this out and I have no idea whether or not they're going to attack again. 

I already have a good idea of who the culprit was. I'm not going to say their name but seriously: Fuck you.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,240
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
12-18-2021, 07:44 PM
#2
RE: Site Sabotaged. Post Mortem in progress
So the way in which they tried to take down the site was not particularly clever. They used a vulnerability in a plug-in that I had left inadvertently enabled even though we no longer use it, which allowed for HTML tags.

Without going into too much detail they use this to insert an arbitrarily long string which crashed the database. They also attempted to use it to install an IP logger on the index page. This failed miserably, as the parser validation caught it.

Because of this I have cleaned up the plugins no longer in use and rolled back the database to this afternoon, two hours or so ago. I didn't see any real post during that time so if there is anything missing let me know but I don't think there should be.

I've also cleaned up and validated most of the system files to make sure that nothing else was touched.

I'm not going to give the culprit the time of day or even name him but his attempt at leaving a breadcrumb to try to turn me against one of the competitors that we have was pretty insidious of him and I'm not amused at it. It's a good thing that I didn't jump to conclusions and actually checked my logging.

With that said if anybody has any questions or concerns regarding the recent down time, or has any information that could lead to future problems by all means let us know or pass it anonymously to staff@irixnet.org if you're afraid of reprisal.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,240
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
12-18-2021, 08:16 PM
#3
RE: Site Sabotaged. Post Mortem in progress
Two questions:

A. This was unrelated to the issue the other day where the cert for the forums was coming up as invalid?
B. Any danger of passwords getting compromised, or was this just a crash-for-the-lulz incident?

Computers: Amiga 1200, DEC VAXStation 4000/60, DEC MicroPDP-11/73
Synthesizers: Roland JX-10/SH-09/MT-32/D-50, Yamaha DX7-II/V50/TX7/TG33/FB-01, Korg MS-20 Mini/ARP Odyssey/DW-8000/X5DR, Ensoniq SQ-80, E-mu Proteus/2, Nord Lead 2, Behringer Model D
commodorejohn
PDP-X

Trade Count: (0)
Posts: 367
Threads: 7
Joined: May 2018
Find Reply
12-18-2021, 09:26 PM
#4
RE: Site Sabotaged. Post Mortem in progress
A. That was caused by a python failure -- see the thread on that.

B. No. I have his logs here and he didn't even try to read the (hashed) password data. Salted and such makes it difficult to attack.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,240
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
12-18-2021, 10:33 PM
#5
RE: Site Sabotaged. Post Mortem in progress
Thank you VERY MUCH for your thorough (& swift) actions - many kudos and plaudits should go your direction, sir....
crimsonVGX
O2

Trade Count: (0)
Posts: 1
Threads: 0
Joined: Feb 2020
Find Reply
12-18-2021, 11:03 PM
#6
RE: Site Sabotaged. Post Mortem in progress
Very nice work. And thanks for keeping this site up.

Fuel Fuel
Mark_G
Sgi Fuel user

Trade Count: (0)
Posts: 11
Threads: 4
Joined: Jun 2018
Location: Belgium
Find Reply
12-19-2021, 01:37 AM
#7
RE: Site Sabotaged. Post Mortem in progress
I'm disappointed someone actually thinks taking us (or anyone else) for that matter offline would make things better. No. Not at all.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,240
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
12-19-2021, 02:11 AM
#8
RE: Site Sabotaged. Post Mortem in progress
(12-18-2021, 10:33 PM)Raion Wrote:  B. No. I have his logs here and he didn't even try to read the (hashed) password data. Salted and such makes it difficult to attack.
Figured as much, but thanks for the confirmation.

Computers: Amiga 1200, DEC VAXStation 4000/60, DEC MicroPDP-11/73
Synthesizers: Roland JX-10/SH-09/MT-32/D-50, Yamaha DX7-II/V50/TX7/TG33/FB-01, Korg MS-20 Mini/ARP Odyssey/DW-8000/X5DR, Ensoniq SQ-80, E-mu Proteus/2, Nord Lead 2, Behringer Model D
commodorejohn
PDP-X

Trade Count: (0)
Posts: 367
Threads: 7
Joined: May 2018
Find Reply
12-19-2021, 02:15 AM
#9
RE: Site Sabotaged. Post Mortem in progress
Raion: It sounds like you have things well under control, but let me know if you need any assistance on this. I wish I could have responded to this sooner, but I was off on a security engagement for my job.

Personaliris Indigo Indigo2 Indy Onyx2 Origin 200 Origin Vault O2 Octane2 (VW 320) (VW 540) (VW 550) Fuel Tezro Tezro Rack Origin 350 Onyx4 Altix 350 (Prism Rackmount)
kaigan
Site Admin and SGI Tinkerer

Trade Count: (2)
Posts: 262
Threads: 31
Joined: May 2019
Location: Omaha, NE
Find Reply
12-20-2021, 01:54 PM
#10
RE: Site Sabotaged. Post Mortem in progress
Good lad. It's hard to express how much your time means or costs without sounding like a total narcissist so we won't go there. However, the time and cost you lost putting whatever was f00k3d back into service was more than nothing and that's appreciated!

Hopefully Santa will bring you something nice...or naughty if you wish hard enough.

"My answer in answering the question: "What does the red spectrum tell us about quasars",There are various words that need to be defined: what is a spectrum, what is a red one, why is it red, and why is it so frequently linked with quasars?"..."What the hell is a quasar?


Onyx2 Octane2 O2 O2 Origin 200 Indigo2 R10000/IMPACT Indy
defaultrouteuk
Sponsor

Trade Count: (0)
Posts: 111
Threads: 28
Joined: Jul 2020
Location: Dubai
Website Find Reply
12-20-2021, 02:48 PM


Forum Jump:


Users browsing this thread: 1 Guest(s)