![]() |
|
Security Breach - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: General (https://sinister.ly/Forum-General) +--- Forum: Announcements (https://sinister.ly/Forum-Announcements) +---- Forum: Announcements (Archived) (https://sinister.ly/Forum-Announcements-Archived) +---- Thread: Security Breach (/Thread-Security-Breach) |
Security Breach - Oni - 12-30-2014 Security Breach
TL;DR: The site was hacked. Data may have been taken. @phyrrus9 is staff. You will be required to change your password. As Sinisterly is a security forum, it will always remain a prime target for security breaches. On the 27th, it was discovered that someone had obtained access to the ACP and generated a shell. It isn't certain, but it is possible that a copy of the database was taken. Security breaches have happened before and will inevitably happen again in the distant future. I have taken measures to make things much more difficult and it is extremely unlikely we will have a repeat. @Reiko, @phyrrus9, and I spent a decent amount of time ascertaining what was done and how. Currently, we have no evidence that a copy of the database was taken, or that they even obtained root. After consulting with multiple experts, it was determined that it is safe to bring Sinisterly back online. There is, however, no guarantee we will not face issues. We must remain vigilant in moving forward, despite recent obstacles [ Moving Forward ] Sinisterly hasn't been in a great position and morale reached a critical low over the past few weeks. No doubt, a lot of you will be very disappointed with what's happened. I can't change the past, but I can shape the future. I have already made plans to implement several new features and large modifications to the site's theme. Expect great things, very soon. In addition to the scheduled changes, I have added a new staff member and forced a password change for everyone. @phyrrus9 is now a staff member, as he has shown great dedication to the forum. While the forced password change is not exactly necessary, it is a smart move. Everyone should change their passwords frequently. Do not reuse your Sinisterly password. Have a great day! If you have any questions or concerns, message me or post below. RE: Security Breach - Alex - 12-30-2014 0/10 security breach didn't use a sweg deface page highly disappointed in this haxz0r. RE: Security Breach - Dyme - 12-30-2014 Is it safe to say that this was not due to a MyBB vulnerability? The fact that the httpd logs don't show any signs of attempted exploitation of MyBB makes me skeptical. Is there a guess to how access to the ACP was obtained? RE: Security Breach - Oni - 12-30-2014 (12-30-2014, 10:59 PM)Dyme Wrote: Is it safe to say that this was not due to a MyBB vulnerability? The fact that the httpd logs don't show any signs of attempted exploitation of MyBB makes me skeptical. Is there a guess to how access to the ACP was obtained? Nope. There were no recent announcements of MyBB core or plugin vulnerabilities. However, the ACP is now inaccessible, so that's not an issue. Extensive logs will be taken and I will be keeping a very close eye. None of us feel like rediscovering a 0day, if there is one. RE: Security Breach - Dyme - 12-30-2014 (12-30-2014, 11:00 PM)Oni Wrote: None of us feel like rediscovering a 0day, if there is one. Lol so none of you want free bank? I'll take your logs and get myself $2K if you don't mind... RE: Security Breach - Ominous - 12-30-2014 Could it have been possible that Sinisterly was breached through your hosting provider? I previously had my forum hacked because of poor security on the host I was on. Otherwise, it might be a vulnerability in a plugin that is in use, or even in MyBB itself, since the team isn't working on 1.6 anymore, unfortunately. (12-30-2014, 11:11 PM)Dyme Wrote: Lol so none of you want free bank? I'll take your logs and get myself $2K if you don't mind... Someone has the right idea. If you're able to find a critical exploit in 1.6.16 now, practically every other MyBB forum is at your mercy since 1.6 isn't going to be updated, and people are too lazy to switch to 1.8 because themes and many plugins will be incompatible. RE: Security Breach - Eclipse - 12-30-2014 Well this is pretty interesting... I'll just sit back and see how this plays out. RE: Security Breach - Master - 12-31-2014 Is this why some recent posts and updated signature are missing? And I agree with @Ominous about the possibility of Sinisterly being breached through the hosting provider. RE: Security Breach - phyrrus9 - 12-31-2014 (12-31-2014, 01:27 AM)The-Master Wrote: Is this why some recent posts and updated signature are missing? And I agree with @Ominous about the possibility of Sinisterly being breached through the host provider. A backup from 12/26 was restored, so anything made after that is now nonexistent. It does not look as though any breach was done via the hosting company as the injection vector was identified to be the ACP. How they got in there, we don't yet know. RE: Security Breach - Losi - 12-31-2014 Shout outs to @phyrrus9 for becoming a mod. Nice going brotha. So that's why SL was down for a few days. I'm glad you figured out what was going on and came up with a solution. I was wondering what was up with the mandatory password reset. But it's better to be safe than sorry. |