Khakain Forum Index

WE CAN'T STOP HERE. THIS IS BAT COUNTRY.
 

Board Utilities
Khakain Photo Gallery | Timeline | cheeEZboard | Oekaki
Khakain Encyclopedia | Khakain Chan | Plastic Grass Face | PGF Stats
April Fools Board
Board Member Sites
Board City | Ubergaming.net | Tim Hates People | HTLOZ II | ZRPG
IMM SORY1!1!! i almost skullfucked a moose



 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Khakain Forum Index -> Hall of Fame

Author Message
Guest







PostPosted: Thu Dec 16, 2004 1:45 am    Post subject: IMM SORY1!1!! i almost skullfucked a moose Reply with quote

OK you can stop trying to ban me now. My proxies switch out after every connection.

I'm posting to say that I'm sorry for the panic and you people are far less fun than I had assumed.

I would like to object to the expressions of horror at the mere addition of a forum and the de-adminning of someone who tried to end my fun.

...

What should REALLY be horrifying you is, wtf is this doing here:
http://www.khakain.com/theboard/phpbb2/some dude.txt

But seriously folks, I kid.

My username has apparently been deleted, but due to [GAPING SECURITY HOLE OMITTED HAHAHAHA], I still have access to [GAPING SECURITY HOLE OMITTED HAHAHAHA].

I could have sealed this gaping security hole, of course, but as my server's IP has been banned from khakain.com, I cannot use the tools I've made to correct it.

Oh well, someone will point it out eventually. No one will notice until someone gets curious. And that's when you have problems.

I'll let you know in a week. And I'm sorry for the trouble I caused you, Zman. I'll tell Jesus to forgive the ban, too.
Author Message
Efreit
didgeridoo original
man with the dream



Joined: 02 Oct 1999
Posts: 4083
Location: Perth, Australia

PostPosted: Thu Dec 16, 2004 1:47 am    Post subject: Reply with quote

Meh, people suck, some dude. Don't let the man get you down.
_________________
i got soul but im not a soldier
View user's profile Send private message AIM Address
Author Message
Krono
hates you




Joined: 11 Jan 2000
Posts: 3463
Location: Al'alyn, United Arab Emerates

PostPosted: Thu Dec 16, 2004 1:53 am    Post subject: Reply with quote

Yeah, seriously. Most people here think you're awesome. No one would mind if you stuck around.
View user's profile Send private message AIM Address
Author Message
drewnb
cochinillo




Joined: 21 Nov 1999
Posts: 1640

PostPosted: Thu Dec 16, 2004 1:58 am    Post subject: Reply with quote

Why would the some dude be banned from here? He should be admin.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Thu Dec 16, 2004 2:11 am    Post subject: Reply with quote

I'm guessing HOAX.

Edit: And that file seems to be 404.
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
drewnb
cochinillo




Joined: 21 Nov 1999
Posts: 1640

PostPosted: Thu Dec 16, 2004 2:22 am    Post subject: Reply with quote

Actually it did read 'some dude was here'.
_________________
[B][78][F5][FF][K]
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Thu Dec 16, 2004 2:25 am    Post subject: Reply with quote

Looks like it's ShadowLynk's fault.
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
Archdeco
Bored as hell.
Mmm...Nutella



Joined: 16 Apr 2000
Posts: 5279
Location: Kansas City

PostPosted: Thu Dec 16, 2004 2:28 am    Post subject: Reply with quote

All the more reason to keep some dude around.
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Author Message
Who Cares
Groove
Member since 1999



Joined: 30 Dec 1999
Posts: 3888
Location: ...

PostPosted: Thu Dec 16, 2004 2:34 am    Post subject: Reply with quote

I've been a some dude fan since his tour with Whitesnake in '85.
View user's profile Send private message AIM Address
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Thu Dec 16, 2004 2:47 am    Post subject: Reply with quote

Security hole fixed....hopefully.
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
Archdeco
Bored as hell.
Mmm...Nutella



Joined: 16 Apr 2000
Posts: 5279
Location: Kansas City

PostPosted: Thu Dec 16, 2004 2:50 am    Post subject: Reply with quote

But oh, the damage that has been done. Like me, Krono and Kal being admins.

Any chance it could stay that way?
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Author Message
drewnb
cochinillo




Joined: 21 Nov 1999
Posts: 1640

PostPosted: Thu Dec 16, 2004 2:51 am    Post subject: Reply with quote

Yes it should.

Especially for Kal.
_________________
[B][78][F5][FF][K]
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Author Message
Krono
hates you




Joined: 11 Jan 2000
Posts: 3463
Location: Al'alyn, United Arab Emerates

PostPosted: Thu Dec 16, 2004 2:52 am    Post subject: Reply with quote

We very obviously deserve it.

Especially, yeah, Kal.

(And me and Deco, too, that is)
View user's profile Send private message AIM Address
Author Message
Archdeco
Bored as hell.
Mmm...Nutella



Joined: 16 Apr 2000
Posts: 5279
Location: Kansas City

PostPosted: Thu Dec 16, 2004 2:55 am    Post subject: Reply with quote

Even if you de-admin the both of us, keep Kal on. He's long overdue.
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Author Message
Archdeco
Bored as hell.
Mmm...Nutella



Joined: 16 Apr 2000
Posts: 5279
Location: Kansas City

PostPosted: Thu Dec 16, 2004 3:01 am    Post subject: Reply with quote

Vaginas, every last one of you.
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Thu Dec 16, 2004 3:01 am    Post subject: Reply with quote

I'm not touching anything. I'm too damn tired. Copying and pasting the change log from 2.0.10 to 2.0.11 is a pain in the ass.
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
Assassin
Member since 1999



Joined: 03 Feb 2004
Posts: 361
Location: Riverhead, New York

PostPosted: Thu Dec 16, 2004 3:56 am    Post subject: Reply with quote

I'm a big some dude fan, he should be an administrator. Seriously.
View user's profile Send private message AIM Address MSN Messenger
Author Message
Flea
Puta Traidora



Joined: 17 Oct 1999
Posts: 1376
Location: SD

PostPosted: Thu Dec 16, 2004 4:07 am    Post subject: Reply with quote

Jesus. Who cares if you're an admin for a message board? Whoopdeeshit, you have the ability to screw everything up. Whee.
View user's profile Send private message Send e-mail Visit poster's website AIM Address
Author Message
Assassin
Member since 1999



Joined: 03 Feb 2004
Posts: 361
Location: Riverhead, New York

PostPosted: Thu Dec 16, 2004 4:11 am    Post subject: Reply with quote

I don't really care if he's an administrator, he should just be allowed to stick around at least. Obviously he didn't do too much, I fell asleep around 6 P.M. EST and woke up around 11 and apparently between 11 and now everything's been fixed.
View user's profile Send private message AIM Address MSN Messenger
Author Message
Flea
Puta Traidora



Joined: 17 Oct 1999
Posts: 1376
Location: SD

PostPosted: Thu Dec 16, 2004 4:13 am    Post subject: Reply with quote

Fucking around with the board very much now is kind of like being an Arab shortly after 9/11. Generally not a good idea, as tempers are still short.
View user's profile Send private message Send e-mail Visit poster's website AIM Address
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Thu Dec 16, 2004 4:16 am    Post subject: Reply with quote

Someone deleted his account (not me) and someone banned his IP's (me). I'm waiting for him to reply so I can unban him because the IP logs are gone.
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
Reitz
Big Boss
Supreme Dictator-For-Life



Joined: 09 Sep 1999
Posts: 7220
Location: Sheppard AFB

PostPosted: Thu Dec 16, 2004 8:42 am    Post subject: Reply with quote

If the gaping security hole is Snip's back door, we all know about it and it's kind of an inside joke around here. Thanks to work I totally missed everything, but eh.
_________________
"Colonel! I've located a ration... but it's trapped behind some sort of metal forcefield! I... I can't get through it!"
"...Raiden, it's just a can, there's a tab..."
"This wasn't in VR training!"
View user's profile Send private message Visit poster's website AIM Address MSN Messenger
Author Message
KALIMDEL
Random Hero




Joined: 07 Feb 2004
Posts: 987
Location: Manitoba, CANADA

PostPosted: Thu Dec 16, 2004 10:30 am    Post subject: Reply with quote

HEY WTF WAS I AN ADMIN OR SOMETHING?? FUCK I MISSED IT.
View user's profile Send private message Send e-mail AIM Address Yahoo Messenger MSN Messenger
Author Message
Efreit
didgeridoo original
man with the dream



Joined: 02 Oct 1999
Posts: 4083
Location: Perth, Australia

PostPosted: Thu Dec 16, 2004 12:25 pm    Post subject: Reply with quote

Reitz wrote:
If the gaping security hole is Snip's back door, we all know about it and it's kind of an inside joke around here. Thanks to work I totally missed everything, but eh.

It wasn't Snip's back door, and it's been patched now. But it was a pretty freakin' hilarious breach, I must say =P
_________________
i got soul but im not a soldier
View user's profile Send private message AIM Address
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Thu Dec 16, 2004 2:00 pm    Post subject: Reply with quote

It was though the fuckin word highlight code.
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
The Cabbage
Member since 1999



Joined: 09 Oct 1999
Posts: 3698

PostPosted: Thu Dec 16, 2004 3:47 pm    Post subject: Reply with quote

O_o
_________________
I got ants in my pants and I need to dance.
View user's profile Send private message Send e-mail AIM Address
Author Message
DAVE
Pwner of a lonley heart
Mmm...Nutella



Joined: 20 Feb 2001
Posts: 3383

PostPosted: Thu Dec 16, 2004 4:02 pm    Post subject: Reply with quote

Too awesome.

I think he should be an admin because, hell, if he wanted to, are you going to stop him?
View user's profile Send private message MSN Messenger
Author Message
Guest







PostPosted: Thu Dec 16, 2004 4:03 pm    Post subject: Reply with quote

The exploit words on all phpbb boards at version 2.0.10 or lower, and works best on 2.0.10.

Basically all you need is the address of the board and a working topic ID number, and you can execute any command on the system with the permissions of the webserver.

I could give you all the address of the tools I made being that they no longer work here, but I don't want to incite mayhem across the internet again.


The GAPING SECURITY HOLE I was referring to earlier was the fact that I had removed authentication checking from the "admin" folder. Between the hours of 11PM and 1AM last night it was possible to log out and access the administration panel from anywhere.



Being that I could have just erased the entire home directory (rm -rf ~/), which includes the board, I think I did relatively minimal damage.

Now aren't you all glad I found this before some trickster did?
Author Message
Krono
hates you




Joined: 11 Jan 2000
Posts: 3463
Location: Al'alyn, United Arab Emerates

PostPosted: Thu Dec 16, 2004 4:15 pm    Post subject: Reply with quote

See? He's like our very dangerous, slightly offsetting, but overall pretty cool guardian angel.
View user's profile Send private message AIM Address
Author Message
Who Cares
Groove
Member since 1999



Joined: 30 Dec 1999
Posts: 3888
Location: ...

PostPosted: Thu Dec 16, 2004 4:18 pm    Post subject: Reply with quote

Aww, thanks, sweetie.
View user's profile Send private message AIM Address
Author Message
The Letter E




Joined: 17 Mar 2005
Posts: 0

PostPosted: Thu Dec 16, 2004 5:26 pm    Post subject: Reply with quote

Weeee unbanned....

I kinda miss my "Taker of Childrens Candy" custom rank, though...
View user's profile Send private message
Author Message
Krono
hates you




Joined: 11 Jan 2000
Posts: 3463
Location: Al'alyn, United Arab Emerates

PostPosted: Thu Dec 16, 2004 6:18 pm    Post subject: Reply with quote

So what kind of stuff can't you hack? I'm curious. What are some successful security measures that have (or could possibly have) kept you out in the past?
View user's profile Send private message AIM Address
Author Message
Archdeco
Bored as hell.
Mmm...Nutella



Joined: 16 Apr 2000
Posts: 5279
Location: Kansas City

PostPosted: Thu Dec 16, 2004 6:22 pm    Post subject: Reply with quote

Are things like, say, Gamefaqs accounts out of your reach?
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Author Message
Rocketlex
Member since 1999



Joined: 31 Jan 2004
Posts: 5283
Location: Arpegania

PostPosted: Thu Dec 16, 2004 6:23 pm    Post subject: Reply with quote

Oh, God, not this again...
_________________
Board City
(A fantastic comic of words!)
View user's profile Send private message AIM Address
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Thu Dec 16, 2004 8:28 pm    Post subject: Reply with quote

I'm sure SL isn't the smartest person when it comes to making good passwords.
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
Efreit
didgeridoo original
man with the dream



Joined: 02 Oct 1999
Posts: 4083
Location: Perth, Australia

PostPosted: Thu Dec 16, 2004 10:00 pm    Post subject: Reply with quote

Archdeco wrote:
Are things like, say, Gamefaqs accounts out of your reach?

Ahahaha. That would be the ultimate revenge... I love it.
_________________
i got soul but im not a soldier
View user's profile Send private message AIM Address
Author Message
The Letter E




Joined: 17 Mar 2005
Posts: 0

PostPosted: Thu Dec 16, 2004 11:30 pm    Post subject: Reply with quote

BlanKrono wrote:
So what kind of stuff can't you hack? I'm curious. What are some successful security measures that have (or could possibly have) kept you out in the past?


For this specific hack, the only insecurity I could manage to exploit was the webserver's permissions.

It's a good idea (though not necessary) to have your webserver run as "nobody" and give it only read access to the files it needs to access. Since it's being run as the user "khakain," it has write access to all of khakain's files, include the one I modified to grant access to the admin section.

Things that keep hackers out (khakain has almost all these, good job guys):
- Disabling remote connections for MySQL
- Setting up proper linux permissions
- Not making all your passwords the same, and not using "password" or a series of consecutive numbers as your password
- Disabling default login usernames

Things that you think keep hackers out but don't:
- Excessively strong password. Pretty much any mangled english word with some numbers will work fine, you don't have to have a 20-character completely random password, the security difference is minimal considering they would both take several billion years to brute force.
- Firewall. Just give it up. If we want in, we get in.
- Secret questions that only you (supposedly) know the answer to. I've called several people to ask them the answer to their secret question in a roundabout way, and it fucking works more often than anyone wants to admit.
- Advertising the fact that you have some kind of anti-hacker protection installed. We view this as a challenge, not a deterrant.

The golden rule is pretty much thus: If you believe it's error-free, chances are good one will be found, and you will find out about it only after it has been exploited.

I've never tried GameFAQs but I believe it must be possible.
View user's profile Send private message
Author Message
Rocketlex
Member since 1999



Joined: 31 Jan 2004
Posts: 5283
Location: Arpegania

PostPosted: Thu Dec 16, 2004 11:37 pm    Post subject: Reply with quote

I wonder, would it be possible to set some sort of trap program? Something which looks like an exploit but, when used, actually sends out a virus or something?
_________________
Board City
(A fantastic comic of words!)
View user's profile Send private message AIM Address
Author Message
Dunkinbean
Handsome



Joined: 28 Oct 1999
Posts: 4577
Location: Naperville, Illinois

PostPosted: Thu Dec 16, 2004 11:38 pm    Post subject: Reply with quote

Quote:
- Firewall. Just give it up. If we want in, we get in.


Thank you. I'm tried of fixing people's computers and having the problem turn out to be Zone Alarm blocking a port.
View user's profile Send private message Send e-mail Visit poster's website AIM Address
Author Message
The Fonz
Member since 1999



Joined: 11 Oct 1999
Posts: 2610
Location: Ottawa

PostPosted: Thu Dec 16, 2004 11:39 pm    Post subject: Reply with quote

Heh, same with the new windows firewall. I turned that shit off the second it DL'd SP2.
View user's profile Send private message MSN Messenger
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Thu Dec 16, 2004 11:57 pm    Post subject: Reply with quote

Gamefaqs accounts would probably be pretty easy for Brutus to crack, especially since the username is already known.
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Thu Dec 16, 2004 11:59 pm    Post subject: Reply with quote

You guys know the email address, right?
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
Tinister
Sterdonian Superwarrior




Joined: 13 Nov 1999
Posts: 2728

PostPosted: Fri Dec 17, 2004 12:24 am    Post subject: Reply with quote

Actually, GameFAQs now has it where to log in you need an email address and a password, they don't ask for your username anymore. Shadowlynk posted on his topic that he was gonna use a private email address.
_________________
Doug Flutie. Part Cyborg. Part Jesus. Most likely your biological father.
View user's profile Send private message Send e-mail AIM Address Yahoo Messenger MSN Messenger ICQ Number
Author Message
Zman
Administrator/1999



Joined: 25 Nov 1999
Posts: 1958
Location: Seattle, WA

PostPosted: Fri Dec 17, 2004 12:47 am    Post subject: Reply with quote

Brutus is having a hard time figuring out what the correct response for a login is. I might have to switch to Access Driver.
View user's profile Send private message Send e-mail AIM Address MSN Messenger ICQ Number
Author Message
drewnb
cochinillo




Joined: 21 Nov 1999
Posts: 1640

PostPosted: Fri Dec 17, 2004 1:35 am    Post subject: Reply with quote

Off topic, but I hate it that gamefaqs boards are gonna merge with gamespot. It was bad enough as it was.
_________________
[B][78][F5][FF][K]
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Display posts from previous:   
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Khakain Forum Index -> Hall of Fame All times are GMT - 4 Hours
Page 1 of 1

 

 
Jump to:  

You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2002 phpBB Group
A phpbb template by SkaidonDesigns