Login Register


Security Breach filter_list
Author
Message
RE: Security Breach #11
Somebody claims that the DB was taken, so the password reset is simply to prevent anybody from being "hacked" with a password.

Did you know that mybb uses the following to generate the hash stored in the table?
Code:
$hash = md5(md5($salt) . md5($password));

Like really, what the fuck


RE: Security Breach #12
Seems like no information was stolen or perhaps they removed their traces? Did you figure out how they got ACP access?
[Image: F4Z9Dqw.png]


RE: Security Breach #13
(12-31-2014, 02:45 AM)BreShiE Wrote: Seems like no information was stolen or perhaps they removed their traces? Did you figure out how they got ACP access?

That was @Oni who came to that solution, they planted a remote shell from there. We intercepted it before anything serious was done (the filename was hilarious), and then took the remainder of the 2 days to implement countermeasures and do damage control.


RE: Security Breach #14
inb4 merge directory
Spoiler:
I kid, Onigger couldn't be that silly.
Spoiler:
Could he? :S



RE: Security Breach #15
(12-31-2014, 02:47 AM)phyrrus9 Wrote: That was @Oni who came to that solution, they planted a remote shell from there. We intercepted it before anything serious was done (the filename was hilarious), and then took the remainder of the 2 days to implement countermeasures and do damage control.

How did the logs seem? Had they been wiped or was there anything juicy at all?
[Image: F4Z9Dqw.png]


RE: Security Breach #16
(12-31-2014, 03:00 AM)BreShiE Wrote: How did the logs seem? Had they been wiped or was there anything juicy at all?

The logs I went through had some indications of attacks. I don't know what is being said or not so I will keep that information to myself and let somebody else reveal it. Nothing extremely juicy was present though, and the logs were not wiped, I suspect that the attacker did not have enough time.


RE: Security Breach #17
(12-31-2014, 01:36 AM)phyrrus9 Wrote: A backup from 12/26 was restored, so anything made after that is now nonexistent. It does not look as though any breach was done via the hosting company as the injection vector was identified to be the ACP. How they got in there, we don't yet know.

Yeah, the MyBB ACP has a ton of vulnerabilities, and the coders are too lazy to fix them.

Oni, shouldn't it still display in the logs which user accessed the ACP to plant the shell? It could give us a clue to whether any staff/admin accounts were compromised. if no user is shown, then it is possible there is a 0day outside of the ACP that allowed the attacker to gain access to it and plant the shell using a second vulnerability in the ACP itself.

Also, if you guys think there is a unpublished vulnerability, let me know so I can dig through the MyBB source and try and find it.

Anyways, I hope to be more active on Sinisterly. Oni runs a great forum.


RE: Security Breach #18
(12-31-2014, 03:05 AM)phyrrus9 Wrote: The logs I went through had some indications of attacks. I don't know what is being said or not so I will keep that information to myself and let somebody else reveal it. Nothing extremely juicy was present though, and the logs were not wiped, I suspect that the attacker did not have enough time.

Ah I see. Guess it was just some kid who got lucky then.

(12-31-2014, 03:59 AM)Ominous Wrote: Yeah, the MyBB ACP has a ton of vulnerabilities, and the coders are too lazy to fix them.

Oni, shouldn't it still display in the logs which user accessed the ACP to plant the shell? It could give us a clue to whether any staff/admin accounts were compromised. if no user is shown, then it is possible there is a 0day outside of the ACP that allowed the attacker to gain access to it and plant the shell using a second vulnerability in the ACP itself.

Also, if you guys think there is a unpublished vulnerability, let me know so I can dig through the MyBB source and try and find it.

Anyways, I hope to be more active on Sinisterly. Oni runs a great forum.

I'm 100% sure this would have been the first thing Oni would have done. A comment like this is pretty useless to say Reiko and phyrrus have both analysed the attack, but I do like the fact you're trying to help. Smile - BTW your user title is offensive to the real hackers of SL.
[Image: F4Z9Dqw.png]


RE: Security Breach #19
(12-31-2014, 03:59 AM)Ominous Wrote: Yeah, the MyBB ACP has a ton of vulnerabilities, and the coders are too lazy to fix them.

Oni, shouldn't it still display in the logs which user accessed the ACP to plant the shell? It could give us a clue to whether any staff/admin accounts were compromised. if no user is shown, then it is possible there is a 0day outside of the ACP that allowed the attacker to gain access to it and plant the shell using a second vulnerability in the ACP itself.

Also, if you guys think there is a unpublished vulnerability, let me know so I can dig through the MyBB source and try and find it.

Anyways, I hope to be more active on Sinisterly. Oni runs a great forum.


Only one account had access to that, it is likely somebody just found a way in without logging in correctly.


RE: Security Breach #20
Finally! I'm glad nothing serious happened. Also goodluck to phyrrus9 for being a new staff. I'm glad we have some dedicated staff members. Smile
[Image: dHJ4Beo.gif]
Hidden Lesson: Reactions are always instinctive whereas responses are always well thought of.








Users browsing this thread: 1 Guest(s)