No problem at all. MateDog Pants wrote:Thanks awfully for reposting that. Bastard.
5punk /downloads & /uploads
Moderator: Forum Moderators
-
Woo Elephant Yeah
- Heavy

- Posts: 5433
- Joined: October 10th, 2004, 17:36
- Location: Bristol, UK
- Contact:
-
northwesten
- Shambler In Drag

- Posts: 784
- Joined: September 3rd, 2006, 12:43
-
Dr. kitteny berk
- Morbo

- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
You don't any more (the upload function was removed due to having some unknown and evil hole in it)
Perhaps http://docs.google.com/ would be a good way to go (as it avoids the need for excel and uploading etc)
otherwise, rapidshare and such are easy
Perhaps http://docs.google.com/ would be a good way to go (as it avoids the need for excel and uploading etc)
otherwise, rapidshare and such are easy
-
Woo Elephant Yeah
- Heavy

- Posts: 5433
- Joined: October 10th, 2004, 17:36
- Location: Bristol, UK
- Contact:
/uploads is back up, however the actual ability to upload anything isn't.
This means any dead links to stuff should be restored, but until I find a better more secure way of allowing you to upload/host files, the upload service will stay down.
I'll put the download button back later on, and have a fiddle with the header/footer, so if you notice any weirdness it might be me
This means any dead links to stuff should be restored, but until I find a better more secure way of allowing you to upload/host files, the upload service will stay down.
I'll put the download button back later on, and have a fiddle with the header/footer, so if you notice any weirdness it might be me
-
Dr. kitteny berk
- Morbo

- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
-
Dr. kitteny berk
- Morbo

- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
Just to make this clear
Even then it won't be 100% safe, but what you've just done is Really concerning.
Seriously wey. unless you have downloaded EVERY SINGLE FILE from /uploads and checked they're not evil. you're risking 5punk getting he-haxed.Woo Elephant Yeah wrote:This means any dead links to stuff should be restored, Also there's quite a significant risk that whatever was used to hack 5punk is still there
Even then it won't be 100% safe, but what you've just done is Really concerning.
-
FatherJack
- Site Owner

- Posts: 9597
- Joined: May 16th, 2005, 15:31
- Location: Coventry, UK
- Contact:
This one in particular looks a bit dodgy:
http://www.5punk.co.uk/uploads/Thomas_E ... ummary.jpg
http://www.5punk.co.uk/uploads/Thomas_E ... ummary.jpg
-
Woo Elephant Yeah
- Heavy

- Posts: 5433
- Joined: October 10th, 2004, 17:36
- Location: Bristol, UK
- Contact:
-
Dr. kitteny berk
- Morbo

- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
Have you actually *looked* at every single file, checking every image is really an image, and the word docs etc are word docs.
or have you just had a poke at something that might look iffy?
as much as i'd like to give you more credit, I don't think anyone can afford to assume/hope you've done the job right. these things have to be checked on.
or have you just had a poke at something that might look iffy?
as much as i'd like to give you more credit, I don't think anyone can afford to assume/hope you've done the job right. these things have to be checked on.
-
Woo Elephant Yeah
- Heavy

- Posts: 5433
- Joined: October 10th, 2004, 17:36
- Location: Bristol, UK
- Contact:
I have downloaded the entire folder, virus checked it, previewed every single image, and opened all the documents.
I have also identified the 3 files used to hack into the site and gain shell access and have been spending considerable time here at work googling for information on how it works.
Several entries on the net also suggest that there are only 3 files needed, which also helps back up my thinking that everything is okay.
I have also identified the 3 files used to hack into the site and gain shell access and have been spending considerable time here at work googling for information on how it works.
Several entries on the net also suggest that there are only 3 files needed, which also helps back up my thinking that everything is okay.
-
Dr. kitteny berk
- Morbo

- Posts: 19676
- Joined: December 10th, 2004, 21:53
- Contact:
-
Woo Elephant Yeah
- Heavy

- Posts: 5433
- Joined: October 10th, 2004, 17:36
- Location: Bristol, UK
- Contact:
From what I've seen I don't think our attacker was too clever, otherwise they might have done something better than just deleting the site. But then it could all be a ruse. 
-
FatherJack
- Site Owner

- Posts: 9597
- Joined: May 16th, 2005, 15:31
- Location: Coventry, UK
- Contact:
They deleted everything to disguise the fact that they'd stolen passwords, which they then tried on PayPal, so not utterly stupid.spoodie wrote:From what I've seen I don't think our attacker was too clever, otherwise they might have done something better than just deleting the site. But then it could all be a ruse.




