News Focus
News Focus
icon url

kodiak149

02/18/05 8:54 PM

#49504 RE: Mattu #49503

Thanks Matt
icon url

Churak

02/18/05 8:55 PM

#49505 RE: Mattu #49503

thanks
icon url

Bob Zumbrunnen

02/18/05 9:32 PM

#49507 RE: Mattu #49503

All 3 of us (Matt, Dave, and I) are leaving no stone unturned on this one. I'm so glad most people savvy enough to use a site like this know a phish when they see it.

Here's what we do and don't know so far.

1. We know the originating address of the phish email hasn't been located in our log files yet. Neither has the IP address of the site that links in the email take you to.

2. It seems pretty apparent that we did get hit/hacked or something. Most evidence says so. However, not *all* accounts got these emails. I didn't get one at an email address I've used for two accounts here. Meaning: It's possible they didn't grab email addresses from all accounts but instead grabbed some range we haven't determined yet.

3. Interesting, the source code of the site linked to in the email contains Javascript variables with names starting with "vuln", which I'm sure is short for "vulnerable". I don't know Javascript, so can't tell if simply going to the site exposes you to malicious Javascript, but it's a good assumption to go with. No, I didn't go to the site. There's a way to grab html from a site and store it for inspection without actually going to the site.

4. These kinds of things are often done using a technique called "SQL Insertion". I've tried to be very careful to make sure this trick isn't possible anywhere. The only place I know of where it's even close to possible (a requirement is that you have a form field into which you can input something and get results -- including a SQL query) would be Search, but it's not possible there. If multiple words are submitted to Search, I parse them and insert "AND" between each word after stripping out words that're too short or are "noise" words.

So, an input of "select * from member" ends up being "select AND member" before being submitted to the db. The asterisk is removed because it's too short, and "from" is removed because it's a noise word.

5. We're throwing ALL of our energies into finding out what happened, how to prevent it happening again, and, if possible, make the perpetrator wish they hadn't done this. Which will likely be difficult. The IP addy of the email goes to Russia and the site the email links to was registered via what's almost certain a bogus name and address in the Marshall Islands.

6. We were one of who knows how many sites got targeted. We know for certain we're not the only one.

7. The site that the email links to was registered only 2 days ago.

The company that hosts the website the emails links go to doesn't seem to give a damn. I'm going to get more insistent Monday that they shut down the linked-to site if they haven't by then. If they'd simply shut down that site, which they've been informed is doing something illegal, they can prevent anyone falling victim.


icon url

Churak

02/19/05 6:16 AM

#49534 RE: Mattu #49503

So what is it going to take for you to step in re the MACH board or do they have something on you?

Posted by: Mach1cobra
In reply to: None Date:2/19/2005 2:01:08 AM
Post #31529 of 31534

JANICE SHELL, how many times does the words stay off have to be said. I am sick and tired of this and you will be erased every time you come here. It seems you are up 24/7 and people know they can find you on the CMKX board. If you notice you have a little button up there that says PRIVATE REPLY, so if you have something to say use that little tiny button. You can't be that blind!!!!!

As for everyone else please if you have something to say to Janice and her little buddies please go to the cmkx board where they are hanging from the ceiling just waiting to attack and prove you wrong no matter what you say about cmkx.

I have said this many times, and listen or turn your hearing aid on if need to, so ok listen I AM YELLING, START YOUR OWN BOARD SO PEOPLE CAN COME TO YOU AND BE ABUSED, WOW HOW HARD IS THIS ANYWAY.

Please all we have a good board and if you feel the need to talk to these people that are so kind as to save us, do it in a PM or go to CMKX or to the board they should start..
Mach Cobra


This is bullshit. They are a SHADOW CMKX board in the FREE ZONE that only allows pumper clowns & this jerk acts like he owns iHub. So either (a) remove all the MODS or (b) move it into the PREMIUM ZONE where it belongs as a PRIVATE CLUB BOARD (which we all know doesn't exist on iHub). IMHO of course.



icon url

Churak

02/19/05 6:36 AM

#49535 RE: Mattu #49503

While this is allowed...sheesh:

Posted by: kenjhavery
In reply to: A deleted message Date:2/18/2005 10:40:43 PM
Post #31512 of 31534

You represent the scum of humanity. Gutter trash.




icon url

The Original dpb5!

02/19/05 10:11 AM

#49536 RE: Mattu #49503

Matt,

Please change the ticker symbol on the WebSky Board from WBSK to WKYN.

TIA

http://www.knobias.com/individual/public/news.htm?eid=3.1.9be62e159d1eb968a663bbe50f0e8f9f6e621622b2...
icon url

Jaybeaux

02/20/05 11:42 AM

#49939 RE: Mattu #49503

Matt, are you saying that I-Hub was hacked and email addresses were taken?