logo

Member
Member
Offline Offline
avatar
Posts: 10
Oh noes we've been haxored by Obama.

Look at the news, it wasn't me this time.:D

http://files.mschat.net/mschat_member.png

MSChat.Net
eoCMS Designer
eoCMS Designer
Offline Offline
avatar
Posts: 1290
tbarkass_willamson@hotmail.com
Re: Oh noes we've been haxored by Obama.

How can you see it if it's only visible to admins? That's a bug in itself...

Seen a bug? Report it!
eoCMS Developer
eoCMS Developer
Offline Offline
avatar
Posts: 1528
Re: Oh noes we've been haxored by Obama.

Oh poop, im going to email that person and ask how he/she did it. Only strange thing is that only Admins can use HTML/JS so im guessing he got into manicgames' account aka 'admin'

EDIT: TGPEG it was set to Guests only! He/She obviously made a mistake lol

Removed it i dont want it updating my sig with that

Please do not PM me requesting support or anything, use the forums, thats what they are here for
eoCMS Designer
eoCMS Designer
Offline Offline
avatar
Posts: 1290
tbarkass_willamson@hotmail.com
Re: Oh noes we've been haxored by Obama.

Well I suppose we should thank them in a way...

at least they've shown a bug.

EDIT: And why Obama? Is that some U.S joke I've missed?

Seen a bug? Report it!
eoCMS Developer
eoCMS Developer
Offline Offline
avatar
Posts: 1528
Re: Oh noes we've been haxored by Obama.

Dam he also used a proxy, 66.55.143.198. He used manicgames' account to login so the ip of this proxy was inserted into the database

Please do not PM me requesting support or anything, use the forums, thats what they are here for
eoCMS Developer
eoCMS Developer
Offline Offline
avatar
Posts: 1528
Re: Oh noes we've been haxored by Obama.

Ok something does not seem right as all Superglobals are Sanitized meaning all < and > and ' and " are converted so they would not be interpreted. Also the hacker said the following in the email
"I could of done alot worse than that (even access to your server) " He cant access the server with JS injection so im going to assume he is lieing and that he just got hold of manicgames' password for his account on eocms.com

Please do not PM me requesting support or anything, use the forums, thats what they are here for
eoCMS Developer
eoCMS Developer
Offline Offline
avatar
Posts: 1528
Re: Oh noes we've been haxored by Obama.

Ok it looks like he/she did guess the password

Please do not PM me requesting support or anything, use the forums, thats what they are here for
Member
Member
Offline Offline
Posts: 221
Re: Oh noes we've been haxored by Obama.

Guessed it? Do you have preventions against brute force?
eoCMS Developer
eoCMS Developer
Offline Offline
avatar
Posts: 1528
Re: Oh noes we've been haxored by Obama.

I guess i should add something to limit the login attempts and also log what was entered

Please do not PM me requesting support or anything, use the forums, thats what they are here for
Member
Member
Offline Offline
Posts: 221
Re: Oh noes we've been haxored by Obama.

That would make it a lot more secure.
eoCMS Designer
eoCMS Designer
Offline Offline
avatar
Posts: 1290
tbarkass_willamson@hotmail.com
Re: Oh noes we've been haxored by Obama.

Unfortunatley our search for this guy just got a little bit harder...

Seen a bug? Report it!
Member
Member
Offline Offline
Posts: 221
Re: Oh noes we've been haxored by Obama.

What happened?
eoCMS Developer
eoCMS Developer
Offline Offline
avatar
Posts: 1528
Re: Oh noes we've been haxored by Obama.

Got into manicgames' account and added a news article about Obama, said hacked through JS (Which we know is not true) and left an email.

The email however is now deleted so cant contact him/her anymore

Please do not PM me requesting support or anything, use the forums, thats what they are here for
Member
Member
Offline Offline
Posts: 221
Re: Oh noes we've been haxored by Obama.

Could it be that SecurePimp guy again? I never found out how that ended...
eoCMS Developer
eoCMS Developer
Offline Offline
avatar
Posts: 1528
Re: Oh noes we've been haxored by Obama.

It ended in the sig being removed. It might be him actually. Theres no way to find out though

Please do not PM me requesting support or anything, use the forums, thats what they are here for
eoCMS Designer
eoCMS Designer
Offline Offline
avatar
Posts: 1290
tbarkass_willamson@hotmail.com
Re: Oh noes we've been haxored by Obama.

We could assume it was jscript and make extra sure there are not weaknesses.

Seen a bug? Report it!
Member
Member
Offline Offline
Posts: 221
Re: Oh noes we've been haxored by Obama.

We could.... And he could have seen the entire CMS from the SVN, and if you went through the code you could probably find a weakness (eventually).
Global Moderator
Global Moderator
Offline Offline
Posts: 122
Re: Oh noes we've been haxored by Obama.

When I read about people who waste their lives hacking websites and online games, and bothering people on the internet (that they don't even know), I can't help chuckling to myself.  XD  What's the point?  o_o

Arwym's Domain  ||  SBM: A PHP Bookmarks Script (coming soon)
eoCMS Developer
eoCMS Developer
Offline Offline
avatar
Posts: 1528
Re: Oh noes we've been haxored by Obama.

lol i totally agree with that Arwym

Please do not PM me requesting support or anything, use the forums, thats what they are here for
Global Moderator
Global Moderator
Offline Offline
Posts: 122
Re: Oh noes we've been haxored by Obama.

Yeah.  Honestly, it just tells you how low on self-esteem these people really are.  Sad
Yet they think that the ability to hack into a system only makes them 'cooler'.  It's sad and funny at the same time.

And no, not saying that hacking is entirely bad.  The ability to hack can be a good thing, depending on how it's used.  To be honest, I'd like to know some more about hacking.  It'd help me test my own programs and make sure that they're at least secure enough.

Arwym's Domain  ||  SBM: A PHP Bookmarks Script (coming soon)

Jump to:


0.04 seconds Queries: 13