If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.
Read carefully... I said I got the same "hacked" message on the library's computer too and I didn't even log in my screen name nor my MKF site password at the Library. So the library's computer didn't know who I was.
The end run I did was go to gmail, pull up an old email from MFK saying I have a new personal message on MKF. Then I clicked on the www.snaggedline hot link within gmail and that took me to this site OK. But if I try to go to MKF directly from my "Favorite's List" I get the "hacked message".
Well... there are a few obvious hacking methods...
1.) The first is outdated software running this site forum with known exploitable hacks...
2.) Keyword loggers that an administrator has on his computer.
3.) Brute force password attacks.
2.) We will set aside for the time being.
3.) Is easy if the administrators have weak passwords.
1.) Most likely there is a "simple" exploit that is vulnerable in the software running this site.
And uhhh... looks like there is from my quick search. I don't run this software on any of my
sites.... so I can not extrapolate.
1.)
a. From the observations it looks like it is a "Defacing" hack... that is no damage has been done to the SQL
databases.
b. "Defacing" websites is a popular "game" in the hacker's world.. they find an exploit and they search Google
to all the websites that have the vulnerability... and slap their name on the hacked site
A.K.A. "HvCvavcvkvevd vbvy Lvavsvt Tvovuvcvh" Remove the "v" for the name.
Im gonna take the board down temporarily so i can patch it up.
Was it just the front page that got defaced?? Have you checked to make sure that there isn't malicious code or exploits buried somewhere on site? Or that everyone's password or other personal information wasn't compromised?
I am assuming that it was a defacement, since if the hackers goal was to infect other pcs or steal information they wouldn't change anything on the website to help avoid detection. None the less I would thoroughly examine the site and logs to be sure.
Could have also been another site running on the same server as Snaggedline.com that was compromised and the attacker just defaced all sites (mass defacement). Google ""Hacked by LastTouch" and you'll get a lot of hits. Assuming snaggedline runs on a shared server, looks like it does to me.
Either way, Grilled should probably get us on the latest version of vBulletin and see if the database containing the credentials was accessed.
Host gator performed a virus check on the server side and it came back negative. I applied the latest security patches on the site and am planning to upgrade to the latest version tonight. The database was not affected as far as I can tell. He just screwed around with the index file. The hacker actually created an account on the board as an administrator...ha! Yakattack also got hacked!
Just ~ an hour ago on my home computer, when I log on to snaggedline.com I get the message, "Hacked by LastTouch" and the next line says, "LastTouch@hachermail.com". Then I can't get to anywhere in snaggedline.
ALL OTHER WEBSITES WORK GREAT!
So I went to the local library and got the same message without even logging into snaggedline first. Then tried kinda doing an end run to snaggedline and finally got in to post this message.
Anyone else having this problem? Seems to be restricted to snaggedline only. So, who got hacked... my computer or snaggedline????
Comment