Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

People For Change website hacked - being abandoned

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (01/01/06 through 01/22/2007) Donate to DU
 
TahitiNut Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 12:35 AM
Original message
People For Change website hacked - being abandoned
Other DUers may have had their email addys 'harvested' and received the hackers' notice, to whit ...
Dear dear dearTahitiNut,

-------------------------------------
Hacked By KMKM Statistics:
-------------------------------------
Registered Users: 1146
Total Posts: 261016
Busiest Time: 130 users were online on 11/2/05 - 11:11 PM
Board Address: http://www.peopleforchange.net/forums/index.php

~~~~~~~~~~~HACKED BY KMKM~~~~~~~~~~~


Ahh! I will release it, but only if u pursuade me by pming me in ICB.

Links to visit :-

www.h4ckme.org
www.indianschatboard.com

Thanx to a lot of people who helped me become what I am

Buff, Priya, Sid, Humbe, etc..


Anyways ... see ya around!

Kudos!
~KMKM


The website owner's notice that they're hanging it up - not enough time and money to bother dealing with the mess - is on the home page.
http://www.peopleforchange.net/
Printer Friendly | Permalink |  | Top
MADem Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 12:39 AM
Response to Original message
1. Oh, well, far be it from me to judge...but that's unfortunate.
Pity some progressive whiz kid with expertise in these here internets couldn't step up and give them folks a hand...

Seems like a prosecution might be in order. But hey, what do I know?
Printer Friendly | Permalink |  | Top
 
TahitiNut Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 03:33 PM
Response to Original message
2. Kicking a harbinger of "things to come".
:shrug: What happens if DU gets rooted?
Printer Friendly | Permalink |  | Top
 
Cleita Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 03:56 PM
Response to Reply #2
3. I guess we are all going to have to bone up on hacking 101.
not only for defense but maybe retaliation.

Knowledge is power.
Printer Friendly | Permalink |  | Top
 
SensibleAmerican Donating Member (460 posts) Send PM | Profile | Ignore Sat Jul-15-06 05:21 PM
Response to Reply #3
6. Hacking is illegal, even as retaliation
Don't think about doing it unless you're prepared to go to jail for a long time.
Printer Friendly | Permalink |  | Top
 
Cleita Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 05:22 PM
Response to Reply #6
7. But wouldn't there be an advantage in knowing how it's done
even if you don't do it yourself?
Printer Friendly | Permalink |  | Top
 
bobbolink Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 04:07 PM
Response to Original message
4. Why don't they do something *useful* -- like hack elections?
Oh wait...

Too bad they won't consider announcing a hacking -- in favor of the blues.

sigh...

Sorry about that, TahitiNut. That really stinks.
Printer Friendly | Permalink |  | Top
 
Cerridwen Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 05:18 PM
Response to Original message
5. I think I found the puke...
I googled his "signature" and found other sites he's hacked.

---------------------


People For Change Forums
~~~~~~~~HACKED BY KMKM~~~~~~~~~~ Ahh! I will release it, but only if u pursuade me by pming me in ICB. Links to visit :- www.h4ckme.org ...
www.peopleforchange.net/forums/index.php - 28k - Cached - Similar pages

(OFFLINE) Board Offline
HACKED BY KMKM!!! Special Thanx to Buff Humbe h4ckyou h4ckme 3l3ctr1c & Demmo for their help and support. Places to visit:- www.h4ckme.org ...
www.icyhell.net/forums/index.php?showforum=32 - 35k - Cached - Similar pages

(OFFLINE) Board Offline
FORUM HACKED BY KMKM ~~~~~~ I CAME , I SAW , I PWNED!!!!!!!!!!! Thanx to, Buff and Choozy Humbe and "3l3ctr1c" Anyways.. if you are a bit smart the forum ...
forums.plakias.co.uk/index.php?act=calendar - 26k - Cached - Similar pages

(OFFLINE) Board Offline
Forum Hacked~~~~~! Special Thanx to ... www.indianschatboard.com and oh! about myself, I live in NY in USA... come beat me up someday :P Kudos! ~KMKM ...
map.planetmedalofhonor.gamespy.com/callofduty/forums/index.php?s=1f73ecbdbc57460051f3f78c93bd2974&act... - 27k - Cached - Similar pages

-----------------

I also found some other things which led me to what is apparently his bulletin board (which he lists in his hack note) which appears to be hosted at http://www.indiachatboard.frih.net/ and a link to his blog http://kmkm.indiachatboard.frih.net/ entitled "Kritesh's Life Book." His hosting service is frih.net.

Perhaps you'd care to let folks know. He should also be reported to frih.net aka http://www.frihost.com/.

Just my 0.02.

Printer Friendly | Permalink |  | Top
 
TahitiNut Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 06:07 PM
Response to Reply #5
8. Probably just a skript kiddie using a canned hack of Invision ...
... forum software. PFP was using an old trial version and Invision has had several 'security' fixes and upgrades to the version they were using. It doesn't take much to exploit a scurity hole after finding out about it from the software publisher ... and then finding sites using unpatched software. All the 'hacks' you list are forums.

:shrug:

Printer Friendly | Permalink |  | Top
 
Cerridwen Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jul-16-06 08:19 AM
Response to Reply #8
17. Exactly.
I found some of his posts at a forum software site asking for help in setting up his own forum software. It appears it's a new "skill" he's learned and is out playing with it at other people's expense. Sort of like when an infant first discovers their feet will fit in their mouth and they spend hours enamored of their own toes.



Printer Friendly | Permalink |  | Top
 
Eric J in MN Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 09:07 PM
Response to Reply #5
13. Could he hack DU that way?
NT
Printer Friendly | Permalink |  | Top
 
TahitiNut Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 09:55 PM
Response to Reply #13
16. It depends on whether the DCForum software DU uses ...
... and the software platform on which it runs have been kept up-to-date and all known security holes have been plugged. I get the impression elad does a pretty decent job, though. A bit depends on the intrusion detection mechanisms and practices used by the ISP, too.

I think PFC's site was probably "low-hanging fruit."
Printer Friendly | Permalink |  | Top
 
blogslut Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 06:10 PM
Response to Original message
9. Is it a PHP nuke site?
I have a friend that got hacked through a vulnerability in the PHP code. The hacker's IP was supposedly in Turkey in the ranges of: 85.97.**.** 85.98**.**, 85.99**.**, and 85.100**.**.

Can't they just pack it all up and switch to a new server/host?
Printer Friendly | Permalink |  | Top
 
TahitiNut Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 06:17 PM
Response to Reply #9
10. Yep. It's implemented in PHP.
That's a popular implementation 'language.' :shrug:
Printer Friendly | Permalink |  | Top
 
blogslut Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 06:28 PM
Response to Reply #10
11. yeah, i know
All the cool kids use it. Personally, I shy away from keeping any kind of database on my server but I'm funny like that. My blog software is semi low-tech. The database is on my machine and I upload when I post. I have a neglected message board but it's a WYSIWYG app that I lease and it's on someone else's server. It's UBB. My boss uses PHP for static pages but his message board is vBulletin.

I never liked the sound of name PHP nuke. That's like begging for a hack.

Sorry about the site. I am wondering if this is all the same gang o hackers. If it is, I'll let you know. I may not be an expert but we adult webmasters are pretty good at sussing out who is behind crap like this cause we get hit with it all the time.
Printer Friendly | Permalink |  | Top
 
Sapphocrat Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 09:15 PM
Response to Reply #10
14. My condolences & empathy, TN.
Edited on Sat Jul-15-06 09:17 PM by Sapphocrat
I grew a certain (fairly well-known) site into a huge PostNuke site -- very, very bad idea. Russian hacker nailed me three times in as many days (also killing a promising LGBT message forum), and took all the fight out of me. It's been a ghost site for over a year now, and I've only recently been motivated to start picking at it again.

I detest PHP, and use it only for the creation of dynamic pages whose headers and footers may need a quick change. I will NEVER again rely on it for programming.

Your apparent ease over the situation is admirable, TN, but still, I'm so sorry! :(
Printer Friendly | Permalink |  | Top
 
TahitiNut Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 09:50 PM
Response to Reply #14
15. Perhaps I gave a mis-impression?
It's not my site ... it's merely one to which I subscribed. As a subscriber, my email was in it's database, so the skript kiddy taunted me as well, I assume, as other subscribers.
Printer Friendly | Permalink |  | Top
 
KoKo Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jul-16-06 09:41 AM
Response to Reply #15
19. So what happens if your e-mail was in their database...
and the hacker has it. I'm not tech literate so I have no idea how the hacker could harrass a person who was in PFC's database. :shrug:
Printer Friendly | Permalink |  | Top
 
lonestarnot Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jul-16-06 09:47 AM
Response to Reply #10
20. ewwwww you smart little TahitiNut!
Printer Friendly | Permalink |  | Top
 
Blue_Tires Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jul-15-06 09:01 PM
Response to Original message
12. well that's a shame
does he/she not have anything better to do?!?!? i'll never understand the appeal of hacking (unless there was a huge financial payoff after blowing up the site)
Printer Friendly | Permalink |  | Top
 
NoPasaran Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jul-16-06 08:33 AM
Response to Original message
18. R. I. P. People For Change
:cry:
The original Site Which Cannot Be Named.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Tue Apr 23rd 2024, 11:31 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (01/01/06 through 01/22/2007) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC