You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 56 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Hacked by EmpEror SeCUriTy Team [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
StaticBeats
Nuke Cadet
Nuke Cadet


Joined: Aug 18, 2003
Posts: 5


PostPosted: Fri Mar 05, 2004 4:51 pm Reply with quoteBack to top

I added all the patches I found in the downloads section here.

I deleted webmail folder and journal folder as well.

Next iteration of my site will NOT be php-nuke. Im sick of patching the software over and over each time I get hacked.

I was hacked 2 weeks ago and applied every patch I could find. Then I get hacked today again and find that I somehow missed the other half of patches.

More than anything it's a huge waste of my time, a headache, and a nuisance.

_________________
StaticBeats
http://www.staticbeats.com
Electronic Music > Digital Culture
Find all posts by StaticBeatsView user's profileSend private messageVisit poster's website
southernwolf
Corporal
Corporal


Joined: Dec 14, 2003
Posts: 56

Location: Texas

PostPosted: Fri Mar 05, 2004 5:17 pm Reply with quoteBack to top

StaticBeats wrote:
I added all the patches I found in the downloads section here.
I deleted webmail folder and journal folder as well.
Next iteration of my site will NOT be php-nuke. Im sick of patching the software over and over each time I get hacked.
I was hacked 2 weeks ago and applied every patch I could find. Then I get hacked today again and find that I somehow missed the other half of patches.
More than anything it's a huge waste of my time, a headache, and a nuisance.


Sorry for your problems but forgive me if I opine that you give up too easy. Pioneers, whether of the frontier variety or the Internet development sort, never have it as easy as those who prefer the comforts and reassurances of known routine. So you've been hacked? So you back off, knees trembling. You'd never make it on the western frontier, either. Wink
Find all posts by southernwolfView user's profileSend private messageVisit poster's website
reikimaster
Sergeant
Sergeant


Joined: Jan 31, 2004
Posts: 148


PostPosted: Fri Mar 05, 2004 5:19 pm Reply with quoteBack to top

I understand your frustration. However as someone who has been making web sites since before there were even any PICTURES on the web... I can tell you without hesitation that if they want to deface your site, they will hack away at it until they find a way.

Sad but true, I'm afraid. Some folks are just idiots and get pleasure in destroying stuff. Like kids shaving a cat.....
Find all posts by reikimasterView user's profileSend private message
StaticBeats
Nuke Cadet
Nuke Cadet


Joined: Aug 18, 2003
Posts: 5


PostPosted: Fri Mar 05, 2004 5:23 pm Reply with quoteBack to top

Well I dont know that I agree in this context. I've been a web developer for 7 years now and the *only* sites of mine that have gotten hacked are PHP-Nuke sites.

Having a nuke site is like throwing out a welcome mat for these guys.

"Welcome. I have holes. Please Hack Me. Enjoy!"

Shocked

_________________
StaticBeats
http://www.staticbeats.com
Electronic Music > Digital Culture
Find all posts by StaticBeatsView user's profileSend private messageVisit poster's website
reikimaster
Sergeant
Sergeant


Joined: Jan 31, 2004
Posts: 148


PostPosted: Fri Mar 05, 2004 5:32 pm Reply with quoteBack to top

maybe it's the name.... it IS kinda hacker-ish sounding.

Say it to yourself....

P H P - N U K E

Kinda makes ya wanna shave a cat, don't it?

Maybe the name should be changed to Php-CMS
or take the Php out and call it..... The-CMS

yeah.... I think that's kinda catchy
and I think the cats are safe...

Cool
Find all posts by reikimasterView user's profileSend private message
StaticBeats
Nuke Cadet
Nuke Cadet


Joined: Aug 18, 2003
Posts: 5


PostPosted: Fri Mar 05, 2004 5:35 pm Reply with quoteBack to top

Razz

PhP got NUKED (again)

_________________
StaticBeats
http://www.staticbeats.com
Electronic Music > Digital Culture
Find all posts by StaticBeatsView user's profileSend private messageVisit poster's website
southernwolf
Corporal
Corporal


Joined: Dec 14, 2003
Posts: 56

Location: Texas

PostPosted: Fri Mar 05, 2004 9:10 pm Reply with quoteBack to top

StaticBeats wrote:

Having a nuke site is like throwing out a welcome mat for these guys.
"Welcome. I have holes. Please Hack Me. Enjoy!"
Shocked


Please do hack me, if you have enough hair on your chest. Or is that big red S Neet rash? Mr. Green

Well, it was fun for a while but after getting a bunch of emails I decided to turn off the link above. It breaks my heart to have to put a couple of prankish peeps in my deny file, but the wages of sin is death. Smile


Last edited by southernwolf on Sun Mar 07, 2004 7:26 am; edited 1 time in total
Find all posts by southernwolfView user's profileSend private messageVisit poster's website
djmaze
Captain
Captain


Joined: Nov 29, 2003
Posts: 566

Location: Netherlands

PostPosted: Sat Mar 06, 2004 1:43 am Reply with quoteBack to top

StaticBeats wrote:
Well I dont know that I agree in this context. I've been a web developer for 7 years now and the *only* sites of mine that have gotten hacked are PHP-Nuke sites.


Time to make your own CMS then, then we can hack that 2 Very Happy

Get real, you are using a system without waranty if you want security then buy one, and when your hacked sue them Rolling Eyes

_________________
Famous people never give their signature Rolling Eyes
http://www.cpgnuke.com <- back online thanks to dedicatednow.com
Don't ask me to be admin on your site please Exclamation
Find all posts by djmazeView user's profileSend private messageVisit poster's website
southernwolf
Corporal
Corporal


Joined: Dec 14, 2003
Posts: 56

Location: Texas

PostPosted: Sat Mar 06, 2004 6:31 am Reply with quoteBack to top

It's not just nuke that gets hacked, heck even the US State Department and FBI websites have been hacked and other non-nuke sites. You're entitled to your pessimistic view of nuke, StaticBeats, but every web technology from html to .asp is hack-able. Are we just supposed to retreat from hackers and cede control of the Internet to 'em? And, btw, don't thank me for the hack alert script- thank Raven. Smile
Find all posts by southernwolfView user's profileSend private messageVisit poster's website
Def
Sergeant
Sergeant


Joined: Feb 08, 2004
Posts: 105


PostPosted: Sat Mar 06, 2004 8:43 am Reply with quoteBack to top

I do security for a job. There is only 1 way to have a secure website, and that's to provide flat html only on a server that doesn't allow connections to anything other than port80. If they can't hack the site, they'll try and hack the sql db, or the ftp used to let you upload. Simple fact is, there is no such thing as a 100% secure computer - website, desktop, server or otherwise. For public hosting, it only needs a hole in someone else's website to allow access to every site on the server.

To reduce the risk of a nuke hack, stop allowing lots of options for ppl to post or modify your site's content. Every time someone can provide input that is then displayed (comments, avatar uploads, web links, whatever), you have a potential hole. Reduce this to the bare minimum. Of course people then start complaining they lose functionality - that's your choice. Functionality, or easily hacked.
Find all posts by DefView user's profileSend private message
reikimaster
Sergeant
Sergeant


Joined: Jan 31, 2004
Posts: 148


PostPosted: Sat Mar 06, 2004 12:05 pm Reply with quoteBack to top

Def-

True. We walk a fine line when we try to make our sites more interesting. I think Php-Nuke is still the best CMS out there for what I do. And that "for what I do" part is a big qualifier.

I recently discovered nuke. I'm hangin with it. It does everything I need and then some. It's customizable. It's interesting.

If I get hacked I get hacked. I been hacked before and it's always a new twist. Once through someone else's security problem on the same server. Once actually from a disgruntled employee where my site was hosted. It takes all kinds. I'm not gonna blame nuke for the actions of a hacker. You do the best you can to secure your belongings. You make adjustments if someone finds a way to break into your house and spray grafitti on the walls. You clean up and you change the locks.

There ARE and always have been IDIOTS in this world. *shrug*
Find all posts by reikimasterView user's profileSend private message
Chinese_Power
Private
Private


Joined: Feb 16, 2004
Posts: 38


PostPosted: Sat Mar 06, 2004 7:39 pm Reply with quoteBack to top

cheezzzz.... there are just a crackers-script kiddies... just find a bug and exploit it en every phpnuke sites....

look at this....

http://www.google.com.ni/search?q=emperor+security+team&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=0&sa=N

_________________
Image
Find all posts by Chinese_PowerView user's profileSend private message
djmaze
Captain
Captain


Joined: Nov 29, 2003
Posts: 566

Location: Netherlands

PostPosted: Sat Mar 06, 2004 10:11 pm Reply with quoteBack to top

Don't browse to their website using IE it will auto download obscure files.

Check their site with Mozilla http://www.iman0nline.com/

And this is what they use: http://www.iman0nline.com/sql.htm
Find all posts by djmazeView user's profileSend private messageVisit poster's website
maciekp
Sergeant
Sergeant


Joined: Sep 09, 2003
Posts: 94

Location: Perth, WA

PostPosted: Sun Mar 07, 2004 11:27 am Reply with quoteBack to top

It seems phpnuke-service.de was also recently attacked by the emperor team: http://www.zone-h.org/defacements/mirror/id=990237/

_________________
ElectricDice 0.8 - password & MD5, sitekey generator tool

Use SHA1 in Nuke
Find all posts by maciekpView user's profileSend private messageVisit poster's website
disgruntledtech
Site Admin
Site Admin


Joined: Apr 14, 2003
Posts: 991

Location: Tulsa, OK

PostPosted: Sun Mar 07, 2004 5:09 pm Reply with quoteBack to top

all these hacks can be stopped easily with this simple hack

http://nukecops.com/uploads/disgruntledtech/mysql.zip

its just a simple 1 line code hack

db/mysql.php line 103

change
Code:
      if($query != "")

to
Code:
      if($query != "" AND !stristr($query, "UNION"))


this will prevent somone from tacking on additional queries to existing unsecured queries. its the nuke equivilant to writing that line you write on a check that prevents someone from writing "and a million dollars" after the amount
Find all posts by disgruntledtechView user's profileSend private messageSend e-mailVisit poster's website
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.507 Seconds - 361 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::