Bad news - downtime / security breach

This is the main shmups forum. Chat about shmups in here - keep it on-topic please!
User avatar
system11
Posts: 6290
Joined: Tue Jan 25, 2005 10:17 pm
Location: UK
Contact:

Bad news - downtime / security breach

Post by system11 »

Well, there's no nice way to say this.

The server got rooted, some time between mid December and today (perhaps indeed multiple times, it was being script attacked). I only noticed because today they kicked off a spam script which resulted in thousands of bounces in my mail. They compromised the exim mail daemon to gain root access. This is why the forum was down today for a couple of hours - I simply shut everything down until I could work out what state it was in. The original point of entry (exim) has been fixed.

There is no evidence files (database backups) were taken or tampered with, but at the same time I cannot prove that they didn't do this. Unfortunately this means some hassle for everyone and definitely some downtime.

What needs to happen to the server:
Find replacement
Migrate forum to temporary home
Review forum data for anything suspicious - mostly dodgy links that might have been inserted.
Bring forum back up
Ship old server back to my place, total crash & burn reinstall
Ship old server back to hosting co, replace web files, verifying integrity against pre-December backups
Migrate forum back to server

What this means to users:
A couple of episodes of downtime
Some users may lose their avatars
Passwords cannot be considered secure

What you need to do:
1) If you use your shmups forum password here at other sites, change it at those sites to something different
2) After the initial relocation, change your password here.

This fucking sucks. More news as soon as it happens.
System11's random blog, with things - and stuff!
http://blog.system11.org
User avatar
emphatic
Posts: 7988
Joined: Mon Aug 18, 2008 3:47 pm
Location: Alingsås, Sweden
Contact:

Re: Bad news - downtime / security breach

Post by emphatic »

Damn those hacker scumbags to hell, I say.
Image | My games - http://www.emphatic.se
RegalSin wrote:Street Fighters. We need to aviod them when we activate time accellerator.
User avatar
Sumez
Posts: 8819
Joined: Fri Feb 18, 2011 10:11 am
Location: Denmarku
Contact:

Re: Bad news - downtime / security breach

Post by Sumez »

Aren't password always encrypted on PHPBB?
Of course, getting access to the encrypted pass is still a security breach, but brute forcing the password would be a pretty complicated process.
User avatar
system11
Posts: 6290
Joined: Tue Jan 25, 2005 10:17 pm
Location: UK
Contact:

Re: Bad news - downtime / security breach

Post by system11 »

Sumez wrote:Aren't password always encrypted on PHPBB?
Of course, getting access to the encrypted pass is still a security breach, but brute forcing the password would be a pretty complicated process.
Yes, they are encrypted, the danger is brute force as you suggest. It seems they were really just interested in using the machine to spam people, but it seems sensible to change passwords elsewhere. Since the current host cannot be considered trustworthy, it is not worth changing passwords here yet.
System11's random blog, with things - and stuff!
http://blog.system11.org
User avatar
StarCreator
Posts: 1943
Joined: Mon Jan 12, 2009 2:44 am
Location: Maryland, USA
Contact:

Re: Bad news - downtime / security breach

Post by StarCreator »

I'm probably not the best candidate since I only have a shared hosting account, but if you need someone to temporarily host the forums while you work on the server let me know.
dieKatze88
Posts: 613
Joined: Sat Sep 12, 2009 1:27 am

Re: Bad news - downtime / security breach

Post by dieKatze88 »

StarCreator wrote:I'm probably not the best candidate since I only have a shared hosting account, but if you need someone to temporarily host the forums while you work on the server let me know.
Ditto. I'm on Dreamhost, It's not the greatest, but it does PHPbb pretty decently.
User avatar
Krimzon Kitzune
Posts: 331
Joined: Wed Jun 15, 2005 8:31 pm

Re: Bad news - downtime / security breach

Post by Krimzon Kitzune »

Well, damn.

Anyways, thanks for letting us know, man. Much appreciated. :)
".... that would be rubbish."
User avatar
Sumez
Posts: 8819
Joined: Fri Feb 18, 2011 10:11 am
Location: Denmarku
Contact:

Re: Bad news - downtime / security breach

Post by Sumez »

If all you need is a phpBB with a moderate activity level like this, most webhotels should be sufficient - I know I've done much more advanced stuff on mine, what are your requirements for a potential new server?
Of course, it's understandable if you want more control over the server (ie. not being run by an external company)
User avatar
system11
Posts: 6290
Joined: Tue Jan 25, 2005 10:17 pm
Location: UK
Contact:

Re: Bad news - downtime / security breach

Post by system11 »

The new server is already installed - I'm just working on apache/exim/php/etc, then it's time to start auditing and migrating the sites. A friend of mine with a very hefty ESX server in the same datacenter as this server kindly created me a virtual machine we can use until I can clean this one down completely and then reformat it.
System11's random blog, with things - and stuff!
http://blog.system11.org
User avatar
Blackbird
Posts: 1563
Joined: Fri Dec 10, 2010 3:27 am
Location: East Coast USA

Re: Bad news - downtime / security breach

Post by Blackbird »

Bummer. Fortunately, I don't think that I use this password for anything important, only other forum-related stuff like this. I'll keep it in mind, though.
User avatar
spadgy
Posts: 6675
Joined: Tue Nov 06, 2007 5:26 pm
Location: Casino Arcade (RIP), UK.

Re: Bad news - downtime / security breach

Post by spadgy »

Gonads! And I only changed all my passwords a couple of weeks back!

If I can help at all with any of the legwork System11, let me know mate.

I'm not a techy really, so I'll ask - is it worth backing up things like high score threads (something I do once a month with the ones I maintain anyway) just in case?
User avatar
system11
Posts: 6290
Joined: Tue Jan 25, 2005 10:17 pm
Location: UK
Contact:

Re: Bad news - downtime / security breach

Post by system11 »

Right - everything has been migrated to our new (temporary) host.

If anything isn't working, please let me know - it SEEMS to be ok. If small bugs are discovered the server may restart at any time.

All users should reset their passwords now
System11's random blog, with things - and stuff!
http://blog.system11.org
User avatar
Edwards80
Posts: 48
Joined: Mon Sep 20, 2010 10:50 am
Location: Stockport, Manchester UK

Re: Bad news - downtime / security breach

Post by Edwards80 »

No biggie, but auto login does not seem to be working. You're required to manually log in after returning to the site.

Aside from that, thanks for the heads up and I hope this isn't causing you too much of a headache :D
User avatar
S20-TBL
Posts: 440
Joined: Mon Jan 18, 2010 6:48 am
Location: Frying over a jungle and saving the nature
Contact:

Re: Bad news - downtime / security breach

Post by S20-TBL »

Edwards80 wrote:No biggie, but auto login does not seem to be working. You're required to manually log in after returning to the site.
Probably disabled for the meantime in case any keyloggers are still wandering around.
--Papilio v0.9 Beta now on itch.io! (development thread)--
Xyga wrote:Blondest eyelashes ever.
User avatar
system11
Posts: 6290
Joined: Tue Jan 25, 2005 10:17 pm
Location: UK
Contact:

Re: Bad news - downtime / security breach

Post by system11 »

Edwards80 wrote:No biggie, but auto login does not seem to be working. You're required to manually log in after returning to the site.

Aside from that, thanks for the heads up and I hope this isn't causing you too much of a headache :D
It'll be cookie settings somewhere, I'll look into it - might require force logging everyone out.
System11's random blog, with things - and stuff!
http://blog.system11.org
User avatar
TrevHead (TVR)
Posts: 2781
Joined: Sat Jul 11, 2009 11:36 pm
Location: UK (west yorks)

Re: Bad news - downtime / security breach

Post by TrevHead (TVR) »

I just posted to say thanks Bloodflowers for putting in your time over the years keeping this place running and for fixing this current problem, also thx to the mods and anybody else providing support :)
User avatar
system11
Posts: 6290
Joined: Tue Jan 25, 2005 10:17 pm
Location: UK
Contact:

Re: Bad news - downtime / security breach

Post by system11 »

S20-TBL wrote:
Edwards80 wrote:No biggie, but auto login does not seem to be working. You're required to manually log in after returning to the site.
Probably disabled for the meantime in case any keyloggers are still wandering around.
It's not on the compromised host anymore - I moved every single service off onto a temporary host kindly provided by a friend.
System11's random blog, with things - and stuff!
http://blog.system11.org
User avatar
mjclark
Banned User
Posts: 1384
Joined: Fri Aug 22, 2008 10:04 pm
Location: UK Torquay

Re: Bad news - downtime / security breach

Post by mjclark »

Yeah- just to second the appreciation.
Thanks for getting us back on track.
I can't imagine what a massive pain in the arse it must be to sort this stuff out.
Image
User avatar
sven666
Posts: 4544
Joined: Wed Feb 02, 2005 2:04 am
Location: sweden
Contact:

Re: Bad news - downtime / security breach

Post by sven666 »

TrevHead (TVR) wrote:I just posted to say thanks Bloodflowers for putting in your time over the years keeping this place running and for fixing this current problem, also thx to the mods and anybody else providing support :)
Image

I approve of this message.
the destruction of everything, is the beginning of something new. your whole world is on fire, and soon, you'll be too..
moozooh
Posts: 3722
Joined: Fri Jul 27, 2007 11:23 pm
Location: moscow/russia
Contact:

Re: Bad news - downtime / security breach

Post by moozooh »

bloodf is the man. :)
Image
Matskat wrote:This neighborhood USED to be nice...until that family of emulators moved in across the street....
User avatar
njiska
Posts: 2412
Joined: Sun Jan 10, 2010 8:36 am
Location: Waterloo, On, Canada

Re: Bad news - downtime / security breach

Post by njiska »

Ouch, sounds like you've got a ton of work ahead of you Bloodflowers, er system11. Good to know you were able to get everything moved over so quickly.

Fortunately the password I use with shmups forum is different from the one i use for anything that has my credit card tied to it, so I'm not worded about that kind of theft. I think a lot of us probably learned that lesson with the Gawker hack.

Good luck getting it all sorted out.
Look at our friendly members:
MX7 wrote:I'm not a fan of a racist, gun nut brony puking his odious and uninformed arguments over every thread that comes up.
Drum wrote:He's also a pederast. Presumably.
User avatar
Vexorg
Posts: 3090
Joined: Wed Jan 26, 2005 1:33 am
Location: Greensboro NC

Re: Bad news - downtime / security breach

Post by Vexorg »

Seems to be working fine here. Fortunately I was just using the auto-generated password on this board, so it doesn't affect anything else. Changed it anyway, just to be sure.
We want you, save our planet!
Xbox Live: Vexorg | The Sledgehammer - Version 2.0
User avatar
Aquas
Posts: 1575
Joined: Thu Jan 11, 2007 1:37 am
Location: Minnesota, USA
Contact:

Re: Bad news - downtime / security breach

Post by Aquas »

Thanks for the work getting things back in order. Props.
STG Weekly!, 1cc's, twitch, XBL: DJ Aquazition
The in-game papers prove that being the paperboy is actually a position of the greatest importance,
ranking alongside top elected officials for notoriety. -Ed Oscuro
User avatar
Daigohji
Posts: 1292
Joined: Thu Jul 06, 2006 2:09 pm
Location: England

Re: Bad news - downtime / security breach

Post by Daigohji »

Thanks for the hard work and updates.
Image
User avatar
louisg
Posts: 2897
Joined: Wed Jul 20, 2005 7:27 pm
Location: outer richmond
Contact:

Re: Bad news - downtime / security breach

Post by louisg »

Hey bloodf, were the passwords salted?
Humans, think about what you have done
User avatar
system11
Posts: 6290
Joined: Tue Jan 25, 2005 10:17 pm
Location: UK
Contact:

Re: Bad news - downtime / security breach

Post by system11 »

louisg wrote:Hey bloodf, were the passwords salted?
You'll have to look up what PHP does by default.

I think I've fixed the session handling problem now, it's a change in PHP which is now the newest version, I've had to put a workaround in for now but the correct fix is going to take a little longer.
System11's random blog, with things - and stuff!
http://blog.system11.org
User avatar
emphatic
Posts: 7988
Joined: Mon Aug 18, 2008 3:47 pm
Location: Alingsås, Sweden
Contact:

Re: Bad news - downtime / security breach

Post by emphatic »

Yeah, thanks a lot for the great work!
Image | My games - http://www.emphatic.se
RegalSin wrote:Street Fighters. We need to aviod them when we activate time accellerator.
User avatar
tinotormed
Posts: 1069
Joined: Mon May 24, 2010 10:08 pm
Location: Philippines
Contact:

Re: Bad news - downtime / security breach

Post by tinotormed »

:x :evil: :evil: GRRRRRRR :evil: :x

Those hackers are not only do they become a pain in the a**, but also they can easily impale themselves through the localhost of the sql server of every single website!
Image
YT|2nd YT|1ccs|
Good, bad, I'm the guy with the keyboard! Note:Please PM me if you need scores to be updated!
User avatar
system11
Posts: 6290
Joined: Tue Jan 25, 2005 10:17 pm
Location: UK
Contact:

Re: Bad news - downtime / security breach

Post by system11 »

Someone noted to me that it's probably worth explaining something I took for granted.

I can't prove they didn't take a copy of the database. It seems unlikely given that they wanted to use the box as a spamhost, but it's impossible to prove. Members who regularly use the trading forum might want to check through their saved messages to see if they've sent anything sensitive. I would hope they haven't, it should mostly be ways for other people to give you money, after all.
System11's random blog, with things - and stuff!
http://blog.system11.org
User avatar
drauch
Posts: 5638
Joined: Thu Oct 30, 2008 6:14 am

Re: Bad news - downtime / security breach

Post by drauch »

Good job on getting it back up! I almost didn't know what I was gonna do with myself last night. Shmups forum is my facebook.
BIL wrote: "Small sack, LOTS OF CUM" - Nikola Tesla
Post Reply