Donate!
Welcome, Guest. Please Login or Register :: View Members
Pages: 1 2 
Send Topic Print
susuzkisavage.com related - possibly important (Read 283 times)
BurnPgh
Serious Thumper
*****
Offline

SuzukiSavage.com
Rocks!

Posts: 1732

susuzkisavage.com related - possibly important
05/25/10 at 20:46:58
 
http://www.suzukisavage.com/cart/index.php

Go there. What Im seeing is some very strange things and a lot of what appears to be an eastern european language. I dont know much about computers but I know something isnt right on that page.

".Cheesyata System:.
Disable Function:NONE
Op.System:Linux||Ip.server:173.244.96.23
Safe ModeShockedFF
Temp:
Uname:Linux olyweb1 2.6.32-3-amd64 #1 SMP Wed Feb 24 18:07:42 UTC 2010 x86_64
PhpVersi:5.2.13

Greetz::netheroes crews>>fitri,lyly^,Hellhag,gunX,black,quintin,ckarh,mzloveme,h_ganteng,ncezz,ben
ny,wendy,napicatra,dyvilz & all (scrolling)

total 288
630262392   4 drwxr-x--- 14 www www   4096 May 25 03:32 .
95700155   4 drwxr-x--- 14 www www   4096 Apr 12 15:43 ..
918966067   8 drwxr-x---  5 www www   4096 Sep  4  2008 admin
568287914 164 -rw-r--r--  1 www www 166031 May 25 03:31 c99.php
918966076  16 drwxr-x---  2 www www  12288 May 24 07:47 cache
568287919   4 -rw-r--r--  1 www www   2404 May 25 03:32 db_scaner.php
95700166   4 drwxr-x---  2 www www   4096 May  1  2008 docs
401260575   0 drwxr-x---  2 www www    133 May  1  2008 download
630262869   0 drwxr-x---  3 www www     54 May  1  2008 editors
918977282   4 drwxr-x---  2 www www   4096 May  1  2008 email
95700172   4 drwxr-x---  2 www www   4096 May  1  2008 extras
401260581  16 drwxr-x--- 14 www www  12288 May 25 19:31 images
95700177   4 drwxr-x--- 13 www www   4096 May 13 14:39 includes
630400080   8 -rw-r-----  1 www www   4666 Feb  1  2006 index.php
630400081  20 -rw-r-----  1 www www  16672 Nov 27  2007 ipn_main_handler.php
630400082  16 -rw-r-----  1 www www  15039 Jan 21  2006 license.txt
401296754   0 drwxr-x---  2 www www     43 May  1  2008 media
630400083   4 -rw-r-----  1 www www   2154 Mar 27  2006 nddbc.html
630400084   4 -rw-r-----  1 www www   4076 Aug 19  2007 nochex_apc_handler.php
630400085   4 -rw-r-----  1 www www    675 Dec 30  2005 page_not_found.php
630263549   0 drwxr-x---  2 www www     39 May  1  2008 pub
918978145   0 drwxr-x---  3 www www     64 May  1  2008 tmp"

Perintah: (next to a text bar)

Eksekusi / Berishi (bottons)

/mnt/raid/webserver/virtual/suzukisavage.com/html/cart (in a text bar)


ndelok (another button)

Susep file:

kirim (another button)"

Anyone know wtf this means? My immediate assumption is the sites cart section has be hacked/hijacked. Doesnt matter much since no one's bought anything directly from the site for as long as Ive been around and thats about 2 years, but personal info may be in danger. I dont really know. Just thought Id give a heads up and maybe someone else knows whats going on. In any case, I think this is a good time to suggest making the backup forum a sticky if possible or as widely known as possible.
Back to top
 
 
  IP Logged
Serowbot
YaBB Moderator
ModSquad
*****
Offline

OK.... so what's the
speed of dark?

Posts: 28387
Tucson Az
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #1 - 05/25/10 at 22:41:57
 
That is some major weirdness!...

If all else fails,... go here..
Created by Bouletard...
It;s not a full back-up but a place to meet up if we get lost...
http://suzukisavage.forumotion.net/
bookmark it now!... Huh...

Wish we could at least back up the tech section...
Back to top
 
 

Ludicrous Speed !... ... Huh...
  IP Logged
dasch
Serious Thumper
*****
Offline

SuzukiSavage.com
Rocks!

Posts: 1137

Re: susuzkisavage.com related - possibly important
Reply #2 - 05/26/10 at 00:16:18
 
Know what? I think this is in Albanian.
Back to top
 
 
  IP Logged
Stimpy - FSO
Serious Thumper
*****
Offline

SuzukisSavage Int'l
Division

Posts: 1203
Germany - formerly SD, SoCal
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #3 - 05/26/10 at 01:05:29
 
We've been hacked.

We could have been targeted (or our host server)
or it could have been random, who knows, but till
now it looks pretty harmless to me, kinda like
wall graffiti. Easy fix. No virus risk nor re-direction
(cause they usually redirect traffic to weird pr0n
sites or worse) no harm done.   Wink

This is what they changed in the HTML page source file:



<marquee behavior=alternate>
<B>n37 by:<font color=#33FF4B face='courier new' size=3>vires
</font>vires Greetz::netheroes
crews>>fitri,lyly^,Hellhag,gunX,black,quintin,ckarh,mzloveme,
h_ganteng,ncezz,benny,wendy,napicatra,dyvilz & all
</b></marquee>
</center></font></td>

<form method='POST' enctype='multipart/form-data' action=/cart/index.php><br>
Perintahe :<input type='text' name='vires' size='42'>
<input type='submit' value='Eksekusi' name='v1'>
<input type='reset' value='Bersihi' name='v2'><br>
Direktoryne : <input type='text'  value= "/mnt/raid/webserver/virtual
/suzukisavage.com/html/cart" name='girls' size='50' >
<input type='submit' value='ndelok' name='v3'><br>
Susup file:<input size='44' type='file' name='filele'>
<input type='submit' name='fitrix' value='kirim'></form>
</center></font></td>
</tr>
</table><br>

Perintah Terlaksana boz>><font color='yellow'></font>::
<center>o--+[coded by vires/nETh 2009]+--o</center><br>
</font></body></div>
Back to top
 
« Last Edit: 05/26/10 at 03:14:42 by Stimpy - FSO »  

Recently sold 97'savage (change of residence) - looking to buy another - just bought a temp, a great SR125 called 'methadone'
WWW Stimpy - FSO   IP Logged
dasch
Serious Thumper
*****
Offline

SuzukiSavage.com
Rocks!

Posts: 1137

Re: susuzkisavage.com related - possibly important
Reply #4 - 05/26/10 at 02:26:13
 
dasch wrote on 05/26/10 at 00:16:18:
Know what? I think this is in Albanian.


Mistyped, it's not Albanian. Don't want to falsly accuse my neighbors...
Back to top
 
 
  IP Logged
mick
Serious Thumper
Alliance Member
*****
Offline

Hell-bound

Posts: 7323
Dayton Oregon
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #5 - 05/26/10 at 02:57:44
 
dasch wrote on 05/26/10 at 02:26:13:
dasch wrote on 05/26/10 at 00:16:18:
Know what? I think this is in Albanian.


Mistyped, it's not Albanian. Don't want to falsly accuse my neighbors...

it's in Swahely
Back to top
 
 

Science and Logic fly you to the moon,
Religion makes you fly into skyscrapers
mickrowe37   IP Logged
jef.savage
Serious Thumper
*****
Offline

ridin' n slidin'

Posts: 638
Boston, MA
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #6 - 05/26/10 at 05:49:21
 
I did order a SS.com decal a month ago and never got it.  I recently wrote to "contact us" about and got no answer.  Looks like I'm out $3.
Back to top
 
 
  IP Logged
babyhog
Serious Thumper
*****
Offline

Find a Cure for
Breast Cancer!
 NOW!!

Posts: 3802
WV
Gender: female
Re: susuzkisavage.com related - possibly important
Reply #7 - 05/26/10 at 05:59:10
 
I noticed it 2 or 3 days ago, at least.
Back to top
 
 

~ 2006 Black, Big Crank battery, HD Softail muffler, engine guard/o-ring pegs, Spitfite windshield, custom mounted Saddlemen bags, Mustang seat! ~ oh, and Hairdo by Helmet! ~
  IP Logged
Boule’tard
Serious Thumper
ModSquad
*****
Offline

Master of the
Obvious

Posts: 1620
Austin TX
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #8 - 05/26/10 at 06:55:46
 
It does look like the home page was hacked, but apparently they did not touch the forum.  If I was concerned about catching something I'd just set the "noscript" extension on Firefox to not allow javascripts from the site, which BTW needs to be pruned down to just the part that is used, and the forum software updated.

Thanks prechermike for the heads up.
Back to top
 
 

That which can be destroyed by the truth should be. - P.C. Hodgell
  IP Logged
Moofed
Full Member
Alliance Member
***
Offline

...and the engine
just gleams...

Posts: 148
Bloomington, Indiana
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #9 - 05/26/10 at 09:02:07
 
Actually, it's quite serious.  Anyone who came across that page, which is anyone who went to suzukisavage.com, could have wiped out the entire site very easily.  Shocked  The "graffiti" was really a command prompt straight into the server.  Anyone with some Linux experience would have instantly recognized the directory listing.

Since the admin around here hasn't shown his face in forever, I took it upon myself to prevent a catastrophe.  I redirected the home page to the forum and moved the cracked page.  I didn't want to mess with stuff too much, but something had to be done.  I'd say the only reason the forum has been unaffected is that it is an uncommon forum software and so the scripts the crackers run generally don't look for it.
Back to top
 
 

WWW Moofed MoofedOne   IP Logged
verslagen1
YaBB Moderator
ModSquad
*****
Offline

Where there's a
will, I want to be
in it.

Posts: 28787
L.A. California
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #10 - 05/26/10 at 09:20:39
 
Thanks moof.   Smiley

Is this the backdoor that the bigX has gotten thru?

And or left open?
Back to top
 
 
WWW   IP Logged
Moofed
Full Member
Alliance Member
***
Offline

...and the engine
just gleams...

Posts: 148
Bloomington, Indiana
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #11 - 05/26/10 at 09:28:06
 
I'm not sure who/what bigX is, but maybe.
Back to top
 
 

WWW Moofed MoofedOne   IP Logged
prechermike
Serious Thumper
Alliance Member
*****
Offline

Kalashna Kitty, from
Skat

Posts: 1190
Ponzer, NC
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #12 - 05/26/10 at 09:34:24
 
WHOOO HOOO! Moofed to the rescue!

Thanks!
Back to top
 
 

2006, HD pipe, Tkat fork brace, elkhide handgrips, gel seat w/riser, silverblue, Ed L's forward controls, Wristwatch, biblethumper650@gmail.com
prechermike   IP Logged
RidgeRunner13
Serious Thumper
*****
Offline

haulin' the
groceries!

Posts: 649
Mustang Island, Texas
Gender: male
Re: susuzkisavage.com related - possibly important
Reply #13 - 05/26/10 at 09:35:06
 
Is that why I got an Error 404: File Not Found when I was trying to access this site earlier? Huh

I posted this on the alternate site. Cool
Back to top
 
 

Wind me up & watch me run, I ain't never had too much fun!
  IP Logged
Gort
Ex Member




Re: susuzkisavage.com related - possibly important
Reply #14 - 05/26/10 at 09:56:39
 
Moofed wrote on 05/26/10 at 09:28:06:
I'm not sure who/what bigX is, but maybe.



"Big X" is Verslagen's name for the coward anonymous poster who has posted a variety of sexually obscene attack posts under a variety of "member/ex member" names.  As every member who has been here for a few years well knows, he has been on this site for at least 2+ years and is one of the original early members who is now using  additional fake names to hide from the disgust of other members. He is friends with some of the early members, and they know who is he but play stupid.  He works with the cooperation of the moderators because they have been on site and logged in, while he attacks members with sexually descriptive, obscene scenarios.  They do nothing about it, and he is the first to ever become so sexually descriptive and obscene in his attacks.
It does not take a hacker to do this.  Anyone can log in as a member, say anything they want, and then log out as an ex member.  Feel free to do so, as absolutely nothing will happen to anyone who wants to do it.
Back to top
 
 
  IP Logged
Pages: 1 2 
Send Topic Print


« Home

 
« Home
SuzukiSavage.com
05/19/24 at 01:33:03



General CategoryThe Cafe › susuzkisavage.com related - possibly important


SuzukiSavage.com » Powered by YaBB 2.2!
YaBB © 2000-2007. All Rights Reserved.