{"id":8219,"date":"2012-01-03T13:17:02","date_gmt":"2012-01-03T20:17:02","guid":{"rendered":"http:\/\/www.dreamdawn.com\/sh\/post_view.php?index=8219"},"modified":"2012-01-03T13:17:02","modified_gmt":"2012-01-03T20:17:02","slug":"from-russia-with-love","status":"publish","type":"post","link":"https:\/\/horror.dreamdawn.com\/?p=8219","title":{"rendered":"From Russia With Love"},"content":{"rendered":"<p>On December 28th, 2011, somebody exploited a vulnerability in this site&#8217;s forum software (the popular phpBB system) to install a hacker control panel that gave them wide access to this server and its files.  Actually, code was injected back in October, but the individual waited until the 28th to do anything with it.  On the 28th, he (I&#8217;m guessing it was a he) used the code he had installed to do two things: he set up a malware redirect and inserted a front page for some Russian porn site (more likely another vector for malware, I suspect) in an obscure location.  I am lucky that his actions were not destructive; he was careful not to make any visible changes to this site or any of the page content.  Instead, the malware redirect only affected mobile browsers; if you visited this site on your iPhone or Android device at the end of last year, you might have been surprised to see a fake Opera update page that tried to force some Java code to download.  The porn front page was also hidden (albeit poorly) so as not to attract attention by regular visitors.<\/p>\n<p>I noticed the redirect while traveling in Japan.  I reached out to my ISP, but like everybody else they were on vacation.  Today they wrote back with some suggestions, and I&#8217;ve gone through and performed a little bit of investigation and cleanup.  The malware is gone, the porn is gone, and the hole is closed.  So far, nothing else seems damaged.<\/p>\n<p>It is inaccurate to call the person (or persons; there are actually three separate IPs that accessed the inserted content over the last week) who installed rogue code &#8220;hackers.&#8221;  Hackers are people who have skills, and use those skills to poke around systems, looking for ways in.  Hackers may be malicious or benign, but they are defined by curiosity; they are a breed who figures things out on their own in situations where the interface is as obfuscated as possible.  The folks who attacked this site are barely script kiddies.  They are using software authored by somebody else (complete with Russian comments containing spelling errors), they know little about actual security (the control panel they installed was protected by a password: &#8220;root&#8221;), and their goals have nothing to do with exploration or curiosity; they are inserting code specifically for monetary gain.  Malware runs botnets, botnets make money.  These people might feel proud of themselves for exploiting a hole that somebody else found in a popular piece of software and then using it to install code that somebody else wrote, but there&#8217;s no glory in their work.  They are just following directions written on some forum, without understanding what the steps mean.  If real hackers are topographers, mapping territory that has never been mapped before, the guys who broke into this site are little more than assembly line workers, following the same instructions over and over by route.  They could be replaced with a machine.  In fact, they are quickly being replaced by machines.  This is the extent of their skills.<\/p>\n<p>I have removed the forum from this site.  Over its 9 year history, this site has been hacked two times, both of which stem from vulnerabilities in the forum software.  I&#8217;m good about keeping my software up-to-date, but phpBB and its ilk are simply too complicated to reliably secure.  Maybe I will come up with a replacement; I have all of the forum posts backed up and might one day restore them.  But for now, I&#8217;m sad to say that the forum has to come down.  If script kiddies from Russia (who, by the way, left their ip addresses all over the place for me to find) can crack it, it&#8217;s too vulnerable to allow on the site.  Perhaps we can set up a third-party solution, like a Google Group, or maybe a G+ page.  If you have suggestions, please let me know.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On December 28th, 2011, somebody exploited a vulnerability in this site&#8217;s forum software (the popular phpBB system) to install a hacker control panel that gave them wide access to this server and its files. Actually, code was injected back in October, but the individual waited until the 28th to do anything with it. On the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-8219","post","type-post","status-publish","format-standard","hentry","category-site"],"_links":{"self":[{"href":"https:\/\/horror.dreamdawn.com\/index.php?rest_route=\/wp\/v2\/posts\/8219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/horror.dreamdawn.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/horror.dreamdawn.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/horror.dreamdawn.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/horror.dreamdawn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8219"}],"version-history":[{"count":0,"href":"https:\/\/horror.dreamdawn.com\/index.php?rest_route=\/wp\/v2\/posts\/8219\/revisions"}],"wp:attachment":[{"href":"https:\/\/horror.dreamdawn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/horror.dreamdawn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/horror.dreamdawn.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}