6502.org Forum  Projects  Code  Documents  Tools  Forum
It is currently Sat Nov 23, 2024 4:51 am

All times are UTC




Post new topic Reply to topic  [ 49 posts ]  Go to page 1, 2, 3, 4  Next
Author Message
 Post subject: Forums back up
PostPosted: Thu May 24, 2012 11:20 pm 
Offline

Joined: Sun Nov 08, 2009 1:56 am
Posts: 411
Location: Minnesota
Yay it's back! I missed this!


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Thu May 24, 2012 11:44 pm 
Offline
User avatar

Joined: Fri Dec 11, 2009 3:50 pm
Posts: 3367
Location: Ontario, Canada
Thank goodness! I was in withdrawal!

Jeff

_________________
In 1988 my 65C02 got six new registers and 44 new full-speed instructions!
https://laughtonelectronics.com/Arcana/ ... mmary.html


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Thu May 24, 2012 11:53 pm 
Offline

Joined: Mon Mar 02, 2009 7:27 pm
Posts: 3258
Location: NC, USA
I was in withdrawal too... :x :x :evil:

Do we still need to change passwords to the forum? I've changed them everywhere else, anyone that was similar anyway...

I actually read the title forum's back-up, as in back-up storage. Heh.

Anyway, thanks to Mike Naberezny for the work at getting the site back up and running. Not sure how much work was involved, but thanks!

_________________
65Org16:https://github.com/ElEctric-EyE/verilog-6502


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 1:25 am 
Offline
User avatar

Joined: Fri Aug 30, 2002 1:09 am
Posts: 8544
Location: Southern California
Three cheers! (or maybe a hundred!)

_________________
http://WilsonMinesCo.com/ lots of 6502 resources
The "second front page" is http://wilsonminesco.com/links.html .
What's an additional VIA among friends, anyhow?


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 4:24 am 
Offline

Joined: Sat Dec 13, 2003 3:37 pm
Posts: 1004
Yes, hurray.

Imagine - I post a "Introduction" message and next thing I know the site is dead.

"What have I done!!?"

But it's nice that it's back.


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 6:58 am 
Offline
User avatar

Joined: Thu Dec 11, 2008 1:28 pm
Posts: 10986
Location: England
Hooray! Many thanks to Mike, not just for restoring but for keeping solid backups!


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 9:41 am 
Offline

Joined: Tue Jul 05, 2005 7:08 pm
Posts: 1043
Location: near Heidelberg, Germany
Thanks Mike for bringing the forum back up!

_________________
Author of the GeckOS multitasking operating system, the usb65 stack, designer of the Micro-PET and many more 6502 content: http://6502.org/users/andre/


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 3:04 pm 
Offline
User avatar

Joined: Mon Aug 08, 2011 2:48 pm
Posts: 808
Location: Croatia
Did you find out who the hacker was, and why he did it(what can be so tempting for hackers on this forum?)?


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 4:35 pm 
Offline

Joined: Fri Jun 27, 2003 8:12 am
Posts: 618
Location: Meadowbrook
Withdrawals here as well, bigtime.

So if it is of any help, here is a picture of my Pinball Mind partially stuffed.

Image

_________________
"My biggest dream in life? Building black plywood Habitrails"


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 6:24 pm 
Offline

Joined: Wed May 20, 2009 1:06 pm
Posts: 491
Dajgoro wrote:
Did you find out who the hacker was, and why he did it(what can be so tempting for hackers on this forum?)?


It is estimated that half of computer users are hackers. I'm guessing the hacker saw this board from Hackaday.

A motive could be identity theft. They could be interested in stealing email addresses to spam us or setting up a bot net.

Your browsing habits are worth thousands of dollars to advertising agencies which is why Facebook and Google use cookies.

They could be interested in finding out who someone here is for political reasons.

Most hackers look for naked pictures if they break into your home computer.

Should the policy be changed on most boards to not store identifiable information like our email address and real name if the user database is not encrypted?


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 6:41 pm 
Offline
User avatar

Joined: Sun Feb 13, 2005 9:58 am
Posts: 85
thank you for be back online and, in general, for supporting all of us!

i like this forum very much, reading it on daily and miss it a lot in these days.

if there is something that i can do for supporting this effort, please let me know.

grazie. (thanks)


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 7:44 pm 
Offline
Site Admin
User avatar

Joined: Fri Aug 30, 2002 1:08 am
Posts: 281
Location: Northern California
The attacker somehow gained access to the phpBB admin panel. The admin panel allows the forum's templates to be customized. This feature was used to inject malicious PHP code to gain access to the server.

The attacker installed a large number of hidden web pages onto the server. Many of them advertised software for sale. They were probably intended to be used with spam to distribute malware.

Here are some of the things I have done about it:

    - I completely wiped the server and reinstalled from the operating system up. Most of the files for 6502.org are stored in a Subversion repository and I used those files to rebuild the site. For files that were not in the repository, I inspected them manually before putting the online.

    - I have tightened up the Apache and PHP configuration on the server. For PHP, I've set options to restrict filesystem access and running system commands.

    - I've installed mod_security, a web application firewall. It will try to block known attacks and suspicious activity from reaching phpBB.

    - phpBB stores its configuration in a MySQL database. I wrote a MySQL trigger that will not allow the "allow PHP code in templates" option to be enabled. If you try to enable this option in phpBB, the database will not allow it to be enabled.

    - I've blocked an IP range in Russia containing the attacker's IP.

    - The users with access to the admin panel now have much stronger passwords.

    - I've modified the Apache configuration to only allow access to the admin panel from certain trusted IP addresses.

Regarding Chuck's question about encrypting the user data in the forum... phpBB does not store passwords in plain text. It does not offer encryption of real names or email addresses. However, it may not have helped in this case. Having them encrypted would mean that the forum would have to decrypt them on demand. An attacker with access to the server would have access to the decryption routines.

Some of the steps above could have helped prevent the attack and I'm sorry they were not already in place. Please understand that 6502.org is an old site and is a hobby project. This forum has been online in different versions for ten years.

I hope that it will now be significantly more difficult for another attack to succeed and that we can get back to discussing our projects. Thanks for your support and using the forum.

_________________
- Mike Naberezny (mike@naberezny.com) http://6502.org


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 8:14 pm 
Offline
User avatar

Joined: Thu May 28, 2009 9:46 pm
Posts: 8507
Location: Midwestern USA
Dajgoro wrote:
Did you find out who the hacker was, and why he did it(what can be so tempting for hackers on this forum?)?

You mean the "cracker?" We are hackers. A**holes who break into systems are crackers. :lol:

_________________
x86?  We ain't got no x86.  We don't NEED no stinking x86!


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 8:17 pm 
Offline
User avatar

Joined: Thu May 28, 2009 9:46 pm
Posts: 8507
Location: Midwestern USA
Dr Jefyll wrote:
Thank goodness! I was in withdrawal!

Jeff

I had developed quite the case of DTs while 6502.org was belly-up. My wife was tempted to dial 911 until she realized it was only due to a lack of "bare metal" computer activity. Instead, she consulted with a shrink, who told her to be patient. It would pass. :P

Good work Mike in rebuilding the site and getting it back on its feet.

_________________
x86?  We ain't got no x86.  We don't NEED no stinking x86!


Top
 Profile  
Reply with quote  
 Post subject: Re: Forums back up
PostPosted: Fri May 25, 2012 8:22 pm 
Offline
User avatar

Joined: Thu May 28, 2009 9:46 pm
Posts: 8507
Location: Midwestern USA
Nightmaretony wrote:
Withdrawals here as well, bigtime.

So if it is of any help, here is a picture of my Pinball Mind partially stuffed.

Lookin' gooood, as Freddie Prinze used to say.

I am a bit surprised that you are using the DIP40 version of the 65C816 instead of the PLCC44 package. The latter, in my humble opinion, is easier to work with—definitely takes less real estate. However, what will matter is when you put the juice to it and it works. :D Here's to hoping for a smoke-free launch.

_________________
x86?  We ain't got no x86.  We don't NEED no stinking x86!


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 49 posts ]  Go to page 1, 2, 3, 4  Next

All times are UTC


Who is online

Users browsing this forum: No registered users and 24 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to: