Notices
ScoobyNet General General Subaru Discussion

HACKED??

Thread Tools
 
Search this Thread
 
Old Jul 19, 2001 | 07:16 PM
  #1  
Avi's Avatar
Avi
Thread Starter
Scooby Regular
 
Joined: Apr 2001
Posts: 5,084
Likes: 0
From: Manchester
Red face

Did anyone else notice Scoobynet was

<B>Hacked by Chinese!!</B>

?? Or was it me ??

Andy A
Reply
Old Jul 19, 2001 | 07:22 PM
  #2  
ex-webby's Avatar
ex-webby
Orange Club
 
Joined: Oct 1998
Posts: 13,763
Likes: 1
Post

Hi All

I didn't actually see this, but something was definitely done.

All appears to be running normally for now..

Maybe whoever it was would be good enough to contact me on webmaster@scoobynet.co.uk to discuss why, etc? I would be very interested.

If it was just sport, then fair play, I hope that will be the last of it. If not, it would be good to find out what the motive is / was.

All the best

webmaster
Reply
Old Jul 19, 2001 | 07:24 PM
  #3  
SimonH's Avatar
SimonH
Scooby Regular
 
Joined: Jul 2000
Posts: 1,743
Likes: 1
From: Nr Bath, Wilts
Red face

Hmmm yes I noticed that too. Bizarre.
Reply
Old Jul 19, 2001 | 07:25 PM
  #4  
Dream Weaver's Avatar
Dream Weaver
Scooby Regular
25 Year Member
Liked
 
Joined: Feb 2000
Posts: 9,846
Likes: 4
From: Lancashire
Exclamation

Avi

Yes, I just logged on to be presented with:

"Hello, welcome to
Reply
Old Jul 19, 2001 | 07:26 PM
  #5  
Avi's Avatar
Avi
Thread Starter
Scooby Regular
 
Joined: Apr 2001
Posts: 5,084
Likes: 0
From: Manchester
Post

I think the original message was

<B>Hacked by Chinese</B>

Reply
Old Jul 19, 2001 | 07:26 PM
  #6  
Andy W's Avatar
Andy W
Scooby Regular
 
Joined: Jul 2001
Posts: 1,887
Likes: 0
Post

I just couldn't access for about ten mins
Reply
Old Jul 19, 2001 | 07:27 PM
  #7  
Avi's Avatar
Avi
Thread Starter
Scooby Regular
 
Joined: Apr 2001
Posts: 5,084
Likes: 0
From: Manchester
Post

Beat me to it DW
Reply
Old Jul 19, 2001 | 07:28 PM
  #8  
SDB's Avatar
SDB
Scooby Regular
 
Joined: Feb 1999
Posts: 1,727
Likes: 0
Post

Avi

when you say it was mentioned on EVO.. do you mean that the scoobynet attack was mentioned on evo, or
Reply
Old Jul 19, 2001 | 07:30 PM
  #9  
Avi's Avatar
Avi
Thread Starter
Scooby Regular
 
Joined: Apr 2001
Posts: 5,084
Likes: 0
From: Manchester
Post

Sorry SDB, just meant that someone had mentioned this attack on EVO before I posted here.

Andy
Reply
Old Jul 19, 2001 | 07:31 PM
  #10  
babber's Avatar
babber
Scooby Regular
 
Joined: Feb 2001
Posts: 4,370
Likes: 0
Thumbs down

Yes same here, whilst it was going on I was able to look at older threads from earlier today. Cleared my cache so I was connecting

So looks like someone changed the front page, the properties showed a page of around 25 bytes, nowhere near this size it should be and the file type was different. Not the usual HTML document.

Didn't have time to screen capture the information. Damn

Cheers Phill C
Reply
Old Jul 19, 2001 | 07:32 PM
  #11  
adyhicut's Avatar
adyhicut
Scooby Senior
 
Joined: Nov 1999
Posts: 2,316
Likes: 0
From: Devon
Wink

Yep i saw it too!

Well done Si for getting it back online

Ady
Reply
Old Jul 19, 2001 | 07:33 PM
  #12  
Dream Weaver's Avatar
Dream Weaver
Scooby Regular
25 Year Member
Liked
 
Joined: Feb 2000
Posts: 9,846
Likes: 4
From: Lancashire
Thumbs up

SDB

I still have it in memory so will upload a screen capture for you.

Should be up soon.

Si
Reply
Old Jul 19, 2001 | 07:35 PM
  #13  
EvilBevel's Avatar
EvilBevel
Scooby Regular
 
Joined: Oct 1999
Posts: 3,491
Likes: 0
Post

Hmmm ...

[This message has been edited by EvilBevel (edited 19 July 2001).]
Reply
Old Jul 19, 2001 | 07:38 PM
  #14  
Dream Weaver's Avatar
Dream Weaver
Scooby Regular
25 Year Member
Liked
 
Joined: Feb 2000
Posts: 9,846
Likes: 4
From: Lancashire
Red face

And I dont have the page anymore - re-cached itself

DW
Reply
Old Jul 19, 2001 | 07:39 PM
  #15  
Shark's Avatar
Shark
Scooby Regular
 
Joined: Aug 1999
Posts: 3,539
Likes: 0
Post

I went on at about 18.50, looked at two topics at the top of General, but couldn't reply with quote, see profile etc. I just got the normal unable to display page screen. Didnt try normal reply tho. Came off, then unable to get back in.

David
Reply
Old Jul 19, 2001 | 07:44 PM
  #16  
Andy W's Avatar
Andy W
Scooby Regular
 
Joined: Jul 2001
Posts: 1,887
Likes: 0
Post

did it just happen again?
Andy
Reply
Old Jul 19, 2001 | 07:50 PM
  #17  
Avi's Avatar
Avi
Thread Starter
Scooby Regular
 
Joined: Apr 2001
Posts: 5,084
Likes: 0
From: Manchester
Post

Andy W - Didn't notice anything.

<B><I>Andy A</I></B>


[This message has been edited by Avi (edited 19 July 2001).]
Reply
Old Jul 19, 2001 | 07:53 PM
  #18  
Shark's Avatar
Shark
Scooby Regular
 
Joined: Aug 1999
Posts: 3,539
Likes: 0
Post

Seems fine now, well quick to, tho I do have ADSL

David
Reply
Old Jul 19, 2001 | 07:57 PM
  #19  
boomer's Avatar
boomer
Scooby Senior
 
Joined: Feb 2000
Posts: 5,763
Likes: 0
From: West Midlands
Exclamation

Is anyone else with a firewall getting intrusion logs?

I currently have 21 attempts (in batches of 3), the latest from node-d8e95045.powerinter.net [216.233.80.69] - so someone could be using other PCs as a springboard. Could Scoobynets IP log be compromised?

mb (forever paranoid!)
Reply
Old Jul 19, 2001 | 08:01 PM
  #20  
SDB's Avatar
SDB
Scooby Regular
 
Joined: Feb 1999
Posts: 1,727
Likes: 0
Post

It appears that it's a very common problem being experienced by lots of web servers around the world..

A big thank you to everyone who let me know that it was happening, especially Ronnie (who was the first)..

and a HUGE thank you to Theo (EvilBevel) for his efforts in helping to get us back on track.

Thank you also to rsquire (Microsoft) for his support and information.

There is a patch which MS advises, but we are already running it.

I think it's unlikely to happen again, as whoever it is has made their point, and in fairness they appear to have done no damage at all, so we should be grateful for that.

All the best

Simon
Reply
Old Jul 19, 2001 | 08:05 PM
  #21  
SDB's Avatar
SDB
Scooby Regular
 
Joined: Feb 1999
Posts: 1,727
Likes: 0
Post

In answer to the questions about data being compromised.

I very much doubt it.

It seems that it is a Denial of Service type of worm. Which either defaces the attacked page (by placing the "hacked by chinese" message on it) or creating a traffic based DoS as a by-product of the way it is distributed.

In addition it looks like the way sites are chosen is completely random (which is a relief), so it is unlikely that there is any specific intention toward scoobynet.

Best regards

Simon
Reply
Old Jul 19, 2001 | 08:05 PM
  #22  
logiclee's Avatar
logiclee
Scooby Regular
 
Joined: Sep 2000
Posts: 4,935
Likes: 0
From: Notts, UK
Post

Boomer,

I'm not getting any intrusion attemtps my firewall.

Lee
Reply
Old Jul 19, 2001 | 08:06 PM
  #23  
Andy W's Avatar
Andy W
Scooby Regular
 
Joined: Jul 2001
Posts: 1,887
Likes: 0
Post

I cant access the SWRT store either!
Reply
Old Jul 19, 2001 | 08:07 PM
  #24  
Avi's Avatar
Avi
Thread Starter
Scooby Regular
 
Joined: Apr 2001
Posts: 5,084
Likes: 0
From: Manchester
Talking

Nothing from my Firewall either
Reply
Old Jul 19, 2001 | 08:12 PM
  #25  
babber's Avatar
babber
Scooby Regular
 
Joined: Feb 2001
Posts: 4,370
Likes: 0
Post

boomer,

Firewall hasn't had an attempt to probe ports since 3:40pm this afternoon. I am currently running anti virus software, but I guess it won't pick anything up.

Everyone on here should at least have Zonealarm 2.1 on thier PCs, dial up people as well. You never know what someone has uploaded to your PC, so please download it now!!!
Reply
Old Jul 19, 2001 | 08:18 PM
  #26  
Scoobychick's Avatar
Scoobychick
Scooby Regular
iTrader: (1)
 
Joined: Feb 2001
Posts: 16,067
Likes: 1
From: Nobbering about...
Smile

Well at least that's explained it, I was on here when it went down, can't say I understand what you're all talking about as I'm computer illiterate but I'm just glad scoobynet is back up and running ok

I've not had anything from my firewall either

Sal
Reply
Old Jul 19, 2001 | 08:19 PM
  #27  
Chris L's Avatar
Chris L
Scooby Regular
 
Joined: May 2000
Posts: 10,371
Likes: 0
From: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Unhappy

Didn't see it - but it doesn't sound good Word of warning if you intending to visit worm.com or any other dodgy hacker type websites, make sure your PC is protected (ZoneAlarm is the absolute minimum). These places are not for the inexperienced user. I would steer clear unless you know what you are doing.

Chris
Reply
Old Jul 19, 2001 | 08:21 PM
  #28  
JackClark's Avatar
JackClark
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Post

It's 'Code Red'
Reply
Old Jul 19, 2001 | 08:26 PM
  #29  
JackClark's Avatar
JackClark
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Post

Reply
Old Jul 19, 2001 | 08:29 PM
  #30  
boomer's Avatar
boomer
Scooby Senior
 
Joined: Feb 2000
Posts: 5,763
Likes: 0
From: West Midlands
Lightbulb

JackClark,

thanks for the pointer (er, pointers) - very interesting!

mb
Reply



All times are GMT +1. The time now is 11:24 PM.