I am not...I am not the damsel in distress. I am not some case. I have to work this. I've lived in a cave for 5 years in a world where they killed my kind like cattle. I am not going to be cut down by some monster flu. I am better than that. What a wonder...how very scared I am.

Fred ,'A Hole in the World'


Buffistas Building a Better Board ++

Do you have problems, concerns, or recommendations about the technical side of the Phoenix? Air them here. Compliments also welcome.


Tom Scola - Mar 05, 2012 4:05:57 am PST #3149 of 4673
Remember that the frontier of the Rebellion is everywhere. And even the smallest act of insurrection pushes our lines forward.

The site is slow because we have been hacked.

I logged in and found the following script running: /var/www/vhosts/buffistas.org/cgi-bin/footgear.pl. Modification time of Feb 24.

The script is some kind of DDOS program. I think we have been using a shit-ton of bandwidth the past week or so.

I killed any footgear.pl processes that were running, moved the script out of the way, and made the cgi-bin directory unwritable. It will take me a while to go through the logs to see if I can figure out how they got in.


Jesse - Mar 05, 2012 4:42:32 am PST #3150 of 4673
Sometimes I trip on how happy we could be.

Yikes!


§ ita § - Mar 05, 2012 4:54:21 am PST #3151 of 4673
Well not canonically, no, but this is transformative fiction.

Good god, Tom. Thanks for catching that.

I am curious about how they got in, too. Our admin password is decently strong--do you think it should be changed?

A cursory google doesn't show me any scriptkiddy sites with that application name or anything, but I don't know all the l33t places to go.

eta: and do you think it's something we should report to iStrata in case that's how they got in, or other customers are compromised?


Consuela - Mar 05, 2012 6:12:32 am PST #3152 of 4673
We are Buffistas. This isn't our first apocalypse. -- Pix

Wow! Thanks for catching that, Tom.


Tom Scola - Mar 05, 2012 7:29:56 am PST #3153 of 4673
Remember that the frontier of the Rebellion is everywhere. And even the smallest act of insurrection pushes our lines forward.

Looks like they got in through plesk.


§ ita § - Mar 05, 2012 7:36:35 am PST #3154 of 4673
Well not canonically, no, but this is transformative fiction.

Is there a security loophole or exploit that they used? Is our password compromised? Was it our plesk install, or one at a higher level (like iStrata admin, or something?)


Tom Scola - Mar 05, 2012 7:39:36 am PST #3155 of 4673
Remember that the frontier of the Rebellion is everywhere. And even the smallest act of insurrection pushes our lines forward.

And, in fact, I see you, ita, logging into Plesk on Thursday, the 23rd, and then the hacker is able to log in on Friday, the 24th with no failed login attempts. I'm worried that there might be a keylogger on one of your systems, ita.

Edit: Or there could be a security hole in Plesk, and the fact that you logged in the day before was just a coincidence. I'm still looking.


§ ita § - Mar 05, 2012 7:47:58 am PST #3156 of 4673
Well not canonically, no, but this is transformative fiction.

23rd of Feb? Can you email me the IP address that was from? I'm trying to think why I would have logged in. That seems too recent for the vote, and that was the last time I went in, to change the email address for the vote.


Tom Scola - Mar 05, 2012 8:00:52 am PST #3157 of 4673
Remember that the frontier of the Rebellion is everywhere. And even the smallest act of insurrection pushes our lines forward.

Insent.


§ ita § - Mar 05, 2012 8:34:24 am PST #3158 of 4673
Well not canonically, no, but this is transformative fiction.

Thanks. V. confusing. Obviously I can't keep track of when I go in, but keylogged on my Mac? Say it ain't so, Joe. Say it ain't so.