We Got Hacked

Log in

SmokingPipes.com Updates

Watch for Updates Twice a Week

PipesMagazine Approved Sponsor

PipesMagazine Approved Sponsor

PipesMagazine Approved Sponsor

PipesMagazine Approved Sponsor

PipesMagazine Approved Sponsor

Status
Not open for further replies.

admin

Smoking a Pipe Right Now
Staff member
Nov 16, 2008
8,873
5,656
St. Petersburg, FL
pipesmagazine.com
As alluded to and discussed in my BURP!!! post, we did in fact get hacked and it was several more files than I thought.
As of this writing all of the infected files have been restored.
If you have anti-virus and firewall software installed on your machine, you are most likely ok.
I'm the closest to all of these files as I surf all parts of the site all day. I scanned my machine and it's fine.
You may want to scan your machines just to be safe, and if you don't have anti-virus and firewall software, you have no business being online, and you better get some right away.
This is a brand new exploit that just cropped up last month. I haven't found the holes and closed them yet. I still have pages and pages of reading to do.
Please do me a favor. If your anti-virus software throws a warning when you come to the site, please let me know by EMAIL, not by PM.
email.gif


 

admin

Smoking a Pipe Right Now
Staff member
Nov 16, 2008
8,873
5,656
St. Petersburg, FL
pipesmagazine.com
If you've recently changed your avatar and used the same file name as the old one, it may have got replaced, like mine did. It was easier to just restore all files than pick and choose.

 

francois1

Might Stick Around
Jul 21, 2011
92
0
KEVIN in the last 2 days my computer has been blocking the site it does not happen all the time

david

 

admin

Smoking a Pipe Right Now
Staff member
Nov 16, 2008
8,873
5,656
St. Petersburg, FL
pipesmagazine.com
This is a pain in the butt. I just killed two hours on this crap.
I found a love.php file in the root that looks like the culprit. Oddly, when searching for info on it, there is nothing to be found.
There's also some weird binary file "Atomic Archive configuration script".
Any geeks out there know anything about this stuff?

 

morlader

Can't Leave
Mar 2, 2011
483
1
Cornwall UK
When I logged in this morning my avitar had changed to an old one.I,ve changed it.Yesterday my anti-virus AVG warned me that it had blocked an intruder.All OK here now.

 

admin

Smoking a Pipe Right Now
Staff member
Nov 16, 2008
8,873
5,656
St. Petersburg, FL
pipesmagazine.com
@coalsmoke - thanks for that. The server tech informed me it was something he was messing with and told me I could delete it. It raised suspicion since it was a binary file and it wasn't on my local drive.
As to the hack - it should be fixed now, but I am still working on closing the hole. So, it could come back if he beats me to the punch. Please let me know if you still have this issue after today, but you don't have to email about virus / trojan warnings today.
It's not what I planned on working on today, but I am enjoying an amazing pipe full of Stokkebye Proper English.

 

nemrod

Can't Leave
Apr 28, 2011
337
1
Sweden
if you don't have anti-virus and firewall software, you have no business being online, and you better get some right away.
I have no AV. Then again I use Linux. ;)
If that love.php wasn't there originally the real problem is that someone was able to put an arbitrary file on the server.

 

admin

Smoking a Pipe Right Now
Staff member
Nov 16, 2008
8,873
5,656
St. Petersburg, FL
pipesmagazine.com
@nemrod - ha! I guess you are fine using Linux. You're a "Super Geek". :wink:
It seems it is an issue with timthumb.php, which generates the little thumbnails on the "Most Popular Posts" plugin.
I do not like the way the new version of the plugin functions, so I am trying to just update timthumb.php without installing the new version of the plugin.
The love.php file is at least polite enough to tell you what it is right in the header comments -
/**

* WSO 2

* Web Shell by oRb

*/
It's pretty interesting looking at the code. Lmk if you want me to email it to you Nemrod.

 

marmal4de

Lifer
Feb 20, 2011
2,315
4
Richmond, BC
If you don't use antivirus software, you're probably using a Mac, and belong on the Internet just as much, if not more than anyone. Super bummer in the hacked bullshit.

 

classicgeek

Part of the Furniture Now
Apr 8, 2010
710
1
What I'd like to know is how you keep the forums so spam-free. Whatever you're doing, keep it up!
Simon

 

collindow

Part of the Furniture Now
Jul 15, 2010
738
4
Portland, OR
Yeah, my computer popped up a warning the other day. The site was loading super-slowly, too, so I just closed to page. I figured it was either an error (Norton is a tad retarded,) or that the site had gotten hacked. Too bad it wasn't just norton being a dunce.

 

scotrob

Starting to Get Obsessed
Jul 24, 2011
178
0
Even though Avast supposedly blocked a Trojan which tried to install itself when I was on forums page, the Trojan (Trojan.Gen for anyone interested) still installed- had to remove it with Spyware Doctor...all is well again now I think :)

 
Status
Not open for further replies.