Page 1 of 8
Server hacked
Posted: Wed Mar 04, 2009 11:45 pm
by adum
as you probably noticed, hacker.org was hacked last weekend. oh, the irony!
truth to be told, we hadn't spent much effort in securing the site. which was a little foolish.
as well as defacing the site, somebody dumped the user table with names and passwords. we use the phpbb2 reg system here, and i guess they don't salt their passwords, which is unfortunate. any password that is short or based on a dictionary word has probably been reversed at this time. therefore, it's very important to change your password to something robust, and if you used the same password on any other site or email account to change that too. sorry for any trouble.
i've spent some time closing out all the SQL injection points i could think of, but in case i missed something, if you happen to notice it please drop me a PM.
Posted: Thu Mar 05, 2009 1:04 am
by PaRaDoX
lol yea, we'd just "notice an un-sterilized form: :3
Posted: Thu Mar 05, 2009 1:24 am
by plope0726
Posted: Thu Mar 05, 2009 6:36 am
by S3th
Eh, My password was made up of Lower and uppercase, with numbers. sorta like
LiK3sH1HwN <Example.
And even if someone wanted to crack my account...Woopdie do, I created a new email address upon signing up here, so it wouldn't get far.
Posted: Thu Mar 05, 2009 6:53 am
by theStack
Well, I'm glad the site is back again, my apprehensions were that the bad guy destroyed the database and there were never made any backups of hacker.org.
Anyway, I noticed the system for the HVM challenges seems to be broken since the evil 0wnage:
Parse error: syntax error, unexpected T_STRING, expecting T_OLD_FUNCTION or T_FUNCTION or T_VAR or '}' in /home/.mazie/hacker_apache/html/hacker/html/hvm/hvmchallenge.php on line 3
adum, could you fix that please?

Posted: Thu Mar 05, 2009 8:21 am
by DanielG
Also, the SVG version of the map isn't working.
Warning: domdocument() expects at least 1 parameter, 0 given in /home/.mazie/hacker_apache/html/hacker/html/challenge/svg/mapsvg.php on line 31
Fatal error: Call to undefined function: loadxml() in /home/.mazie/hacker_apache/html/hacker/html/challenge/svg/mapsvg.php on line 34
Posted: Thu Mar 05, 2009 8:32 am
by teebee
Moreover, the system for the SuperHack challenges is broken:
Parse error: syntax error, unexpected T_STRING, expecting T_OLD_FUNCTION or T_FUNCTION or T_VAR or '}' in /home/.mazie/hacker_apache/html/hacker/html/sh/shack.php on line 3
and the php source of the SuperHack vm is not available at
http://www.hacker.org/sh/shphp.phps.
Posted: Thu Mar 05, 2009 9:25 am
by adum
i'll fix all that stuff soon... thanks
Posted: Thu Mar 05, 2009 10:56 am
by Codux
Just a notice: Since the incident (i. e. since the hashes (and email) list is online) users might get bulk mail on the used mail address (I do). Only because of that I noticed that somthing is not ok (I was quite inactive the last time

).
I hope you haven't lost the fun on running the site!
Sup
Posted: Thu Mar 05, 2009 10:58 pm
by Defil3d
Hello, I'm new to this site and since I saw that a hacking site just got hacked...All I can say is lol
Re: Sup
Posted: Fri Mar 06, 2009 1:57 am
by PaRaDoX
Defil3d wrote:Hello, I'm new to this site and since I saw that a hacking site just got hacked...All I can say is lol
I wouldn't laugh, go start up a site of your own and watch what happens in like the first 2 days. (shitty free sites don't count, I mean one where you have to do the security, smartass)
Posted: Fri Mar 06, 2009 3:38 am
by Mr_K_13
Quite unfortunate, I hope all is fixed soon. =)
Posted: Fri Mar 06, 2009 4:11 am
by the_impaler
Please let us know when it's safe to change password back to 6 stars.
The stickies are not holding for long
On the other positive side - the only email I got so far was that I just inherited $13,000,000. I didn't know that adum was so rich.
cheers,
Posted: Fri Mar 06, 2009 9:44 am
by m!nus
58.4% of the passwords got cracked
the news is even on heise.de:
http://www.heise.de/security/Nutzerpass ... ung/134052 (german)
maybe it's time for a new era on hacker.org, make it open source, so everyone can find vulnerabilities and let you fix them.
btw, how exactly did they get in the system, vulnerabilities in the challenge system or in the forum?
Posted: Fri Mar 06, 2009 10:09 am
by S3th
"About the circumstances of the burglary, the operator is almost no information."
What happened adum. ;3