Here I am

Darn Hackers... I've been violated..

Attention: TDR Forum Junkies
To the point: Click this link and check out the Front Page News story(ies) where we are tracking the introduction of the 2025 Ram HD trucks.

Thanks, TDR Staff

Good reading

Jeepers, offroaders and rockcrawlers?

Well, My quiet life in Vermont is forever violated...

Some SOB from the University of Miami hacked my web server and my ISP's web mail.

Replaced web page content with 'F&&K the USA Government', etc etc.

Very crafty hack, been fighting it all day long!

Oh for those nice boring days of yesterday... .
 
Interesting!

Our work site got hit with that same hack. He must have been busy the last day or so.



------------------
Mark Wardell
1996 Dodge 3500, 4x4, Duel, Green and silver, Shocked farm pin hitch, Goose Neck hitch.
 
Hate to say it but it's probably Chinese hackers. Our Gov't Dept-o-Defense system has been on Infocon Alpha for two weeks because of this threat. Hackers are attempting to break into US systems to celibrate some Chinese student day/week B. S. , as well as the US recon. plane incident.
This is the reason that we must turn off our workstations when leaving for the day.
 
UPDATE: http://www.cert.org/advisories/CA-2001-11.html

Well, we got the work site (read that ISP) systems recovered. They are using the 'parent path' weakness to back out of the web page 'up' to the operating system, then are executing stuff to create the webpages.

We closed the 'parent path' door. (don't forget to reboot or the changes do nothing)
We deleted all the unneeded virtual directories.

A sure sign of this attack is finding 'root. exe' in your website's script directory.

I replaced it with a copy of notepad. exe, renamed to root. exe and locked the file down to prevent it from being replaced.

=
My home server only had the 'parent path' fix in place, and I can tell you that it is not enough to prevent the hackers.

I was lucky enough to catch the website logfile before it was deleted (it is not just a diesel that one can 'BOMB' #ad
). A very crafty string is being sent to the webserver as a web page URL. That contains the entire attack!

If you are in the industry, send me an email and I will send you the logfile thread.

My first attack was from a computer at the University of Miami. I talked to some real red-faced folks there!

Tonight I was attacked again from a university in Japan. I just finished that email message to the Director of information services.

Ah, the joy of computers.

Remember, it is considered impossible to hack a computer that is really turned off.

[This message has been edited by David_VT (edited 05-09-2001). ]
 
I ran across a site that must have been hit last weekend. I was looking for information on digital cameras and I was surpised by the page that came up for what I thought was a reputable company. I figured they got caught marketing someones patented product or something. Now I know what it's all about. Someone hacked their site.

Doc
 
Back
Top