Check Out Our Shop
Page 1 of 2 1 2 LastLast
Results 1 to 25 of 43

Thread: Telemark Talk hacked

  1. #1
    Join Date
    Oct 2003
    Posts
    1,037

    Telemark Talk hacked

    Go try it:

    http://www.telemarktalk.com/

    what it the motivation behind hacking a tele site?

  2. #2
    Join Date
    Jul 2004
    Location
    not far from snowbird
    Posts
    2,244
    sounds like someone got kicked off the board and didn't take it too well.

  3. #3
    Join Date
    Oct 2003
    Posts
    8,881
    just some script kiddies

  4. #4
    Join Date
    Jun 2004
    Location
    SLC
    Posts
    916
    They probably think they're the shit right now too. Interesting what makes people tick.

  5. #5
    Join Date
    Oct 2003
    Location
    Was UT, AK, now MT
    Posts
    14,579
    How does that shizz happen?

  6. #6
    Join Date
    Nov 2003
    Location
    London : the L is for Value!
    Posts
    4,574
    According to a post on TT it's due to a bug in the PHP. Basically, if the script isn't written securely enough - especially with freely distributed products written in a populat language like PHP - somebody with too much time and a poor sense of morality just sorts through it untill they can find a way to make a small crack... and then those usually gradually get bigger.

    The classic on for PHP (from a security prespective) is when simplistic user input -> database linking is used. A usualy one in user/password database connection is to submit the user name and password straight into and SQL statement. However, you can type a password which just returns the SQL statement as true, giving you a small amount of extra access (say, an admin account), which allows you to put in your own backdoors to create further, more damaging access...

    Sad stuff Hope the losers realise it isn't big, amusing, intelligent or in anyway constructive an give it up - especially before they can do too much damage (nobody likes backups )

    Here's a link to a modified file (apparently there's more than one)

    edg
    Last edited by edg; 12-02-2004 at 08:42 AM.
    Do you realize that you've just posted an admission of ignorance so breathtaking that it disqualifies you from commenting on any political or economic threads from here on out?

  7. #7
    Join Date
    Oct 2003
    Location
    back of my truck
    Posts
    316
    Quote Originally Posted by edg
    According to a post on TT it's due to a bug in PHP. Basically, if the script isn't written securely enough - especially with freely distributed products written in a populat language like PHP - somebody with too much time and a poor sense of morality just sorts through it untill they can find a way to make a small crack... and then those usually gradually get bigger.

    The classic on for PHP (from a security prespective) is when simplistic user input -> database linking is used. A usualy one in user/password database connection is to submit the user name and password straight into and SQL statement. However, you can type a password which just returns the SQL statement as true, giving you a small amount of extra access (say, an admin account), which allows you to put in your own backdoors to create further, more damaging access...

    Sad stuff Hope the losers realise it isn't big, amusing, intelligent or in anyway constructive an give it up - especially before they can do too much damage (nobody likes backups )

    edg
    How the hell do people learn to do all of that? Do they just have a bunch of time on their hands? I don't understand computers.......

  8. #8
    Join Date
    Oct 2003
    Location
    The Ranch
    Posts
    3,792
    Quote Originally Posted by The General
    How the hell do people learn to do all of that? Do they just have a bunch of time on their hands? I don't understand computers.......
    That thing that you are typing on is called a 'keyboard', the clicky thing to your right is called a 'mouse'. That's all you need to know. As far as security goes I'm sure the creators of telemarktalk.com weren't concerned with it so they left some open holes and didn't think that people would try to hack their site.

  9. #9
    Join Date
    Oct 2004
    Location
    Boulder, CO
    Posts
    2,270
    Quote Originally Posted by The General
    How the hell do people learn to do all of that?

    Easy he is most likely btw 13 - 18 and has no chance of getting laid so he spends all of his life in front of his computer trying to convince people that don't know him that he is "133t"

  10. #10
    Join Date
    May 2002
    Location
    River City
    Posts
    2,400
    Quote Originally Posted by edg
    According to a post on TT it's due to a bug in the PHP. Basically, if the script isn't written securely enough - especially with freely distributed products written in a populat language like PHP - somebody with too much time and a poor sense of morality just sorts through it untill they can find a way to make a small crack... and then those usually gradually get bigger.

    The classic on for PHP (from a security prespective) is when simplistic user input -> database linking is used. A usualy one in user/password database connection is to submit the user name and password straight into and SQL statement. However, you can type a password which just returns the SQL statement as true, giving you a small amount of extra access (say, an admin account), which allows you to put in your own backdoors to create further, more damaging access...

    Sad stuff Hope the losers realise it isn't big, amusing, intelligent or in anyway constructive an give it up - especially before they can do too much damage (nobody likes backups )

    Here's a link to a modified file (apparently there's more than one)

    edg
    Holy shit edg, I have no idea what you just said, you lost me at "according to..." Glad you tech monkey's are around to help us computer idiots out.

  11. #11
    Join Date
    Nov 2004
    Location
    down south
    Posts
    629
    The way most script kiddies work is to pick a vulnerability and then scan for sites that have it. Completely indescriminate.

    The problem is, that type of hacking is super simple- anybody could be taught how to do it in a day- but stupid kids pretend like they are some sort of computer genious for doing it.

  12. #12
    Join Date
    Nov 2002
    Location
    Kootenays
    Posts
    466
    Quote Originally Posted by cmor
    what it the motivation behind hacking a tele site?
    I think they got confused. I'm guessing that they were really doing god's work and trying to attack telemarketers and got a little ahead of themselves. Gifted geeks but really poor spellers.
    Last edited by JR; 12-03-2004 at 01:50 AM.

  13. #13
    Join Date
    Jun 2004
    Location
    On my way
    Posts
    912
    That stuff can make you some money in the long run. Just get good at it, then point out all the flaws a company has and fix it for them.

  14. #14
    Join Date
    Mar 2004
    Posts
    12
    Quote Originally Posted by JR
    I think they got confused. I'm guessing that they were really doing god's work and trying to attack telemarketers and got a little ahead of themselves. Gifted geeks but really poor spellers.
    Hmm. God's work? Heh. Maybe, baby.

    All's I can say is, much of the "private" info on the internet is hackable, for a price. Sixty bucks, wired to a Vietnamese address, buys lots of info, including email passwords.

  15. #15
    Join Date
    Jul 2004
    Location
    Norway
    Posts
    333
    I can't log on to telemarktalk today... anyone else have this problem??

  16. #16
    Join Date
    Jun 2004
    Location
    in a frozen jungle
    Posts
    2,374
    yea, I think those computer dorks killed it! hopefully this place is safe?
    I think Mitch is trying to plug the holes before he comes back on line! maybe Big Tim or somebody can keep us up to speed1
    Scientists now have decisive molecular evidence that humans and chimpanzees once had a common momma and that this lineage had previously split from monkeys.

  17. #17
    Join Date
    Oct 2003
    Location
    Emulating the ocean's sound
    Posts
    7,008

  18. #18
    Join Date
    Jun 2004
    Location
    in a frozen jungle
    Posts
    2,374
    Hey Basom! one pair is more than enough for me!
    Scientists now have decisive molecular evidence that humans and chimpanzees once had a common momma and that this lineage had previously split from monkeys.

  19. #19
    Join Date
    Jan 2004
    Location
    NNE
    Posts
    2
    [news flash]North American productivity hits all time highs today![/news flash]

    I want my Ttips!!!

  20. #20
    Join Date
    Feb 2004
    Location
    on the pointy end, calling the line, swearing my fucking ass off
    Posts
    4,682
    Quote Originally Posted by Droopy
    That stuff can make you some money in the long run. Just get good at it, then point out all the flaws a company has and fix it for them.
    Its not as worthwhile as it was a few years ago, with the patriot act, homeland security and all that bullshit, doing that can get you sued into oblivion with barely any evidence whatsoever. Bugtraq and NTbugtraq are nothing in comparison to what they used to be anymore. People actually have to be careful what they point out and how.

  21. #21
    Join Date
    Oct 2004
    Location
    Boulder, CO
    Posts
    2,270
    Quote Originally Posted by nealric
    The way most script kiddies work is to pick a vulnerability and then scan for sites that have it. Completely indescriminate.

    The problem is, that type of hacking is super simple- anybody could be taught how to do it in a day- but stupid kids pretend like they are some sort of computer genious for doing it.

    I did a Google search on the hackers name and saw that he has hacked a stencil website in the past. He is definitely a script kiddie trying to stroke his ego in any way he can.

  22. #22
    Join Date
    Feb 2004
    Location
    on the pointy end, calling the line, swearing my fucking ass off
    Posts
    4,682
    Quote Originally Posted by Lurch
    I did a Google search on the hackers name and saw that he has hacked a stencil website in the past. He is definitely a script kiddie trying to stroke his ego in any way he can.
    pretty typical

    probably just searched for "phpbb v2.whatever" in google to find sites that haven't upgraded the core version then tries the script on every single one until he finds one it works on.

    gaygaygay

  23. #23
    Join Date
    Dec 2001
    Location
    Øøøtahhh
    Posts
    2,780

    Talking

    Quote Originally Posted by JR
    I think they got confused. I'm guessing that they were really doing god's work and trying to attack telemarketers and got a little ahead of themselves. Gifted geeks but really poor spellers.
    Bwahahahahahaaazahhaahaaaa!!!!!

  24. #24
    Join Date
    Dec 2001
    Location
    Øøøtahhh
    Posts
    2,780

    Cool

    Thank you, bosom.



    ...er, basom.

  25. #25
    Join Date
    Nov 2003
    Location
    London : the L is for Value!
    Posts
    4,574
    Quote Originally Posted by likwid
    pretty typical

    probably just searched for "phpbb v2.whatever" in google to find sites that haven't upgraded the core version then tries the script on every single one until he finds one it works on.

    gaygaygay
    According to Mitch on TT it wasn't the PHP vulnerability that was exploited, but I can imagine the pandemonium resulting for this little slip - think how many PHPBB sites you can find on google

    edg
    Do you realize that you've just posted an admission of ignorance so breathtaking that it disqualifies you from commenting on any political or economic threads from here on out?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •