Page 2 of 7 FirstFirst 12346 ... LastLast
Results 11 to 20 of 64

Thread: Sega-16 Taken Down

  1. #11
    Quote Originally Posted by Frogacuda View Post
    I blame Nintendo.
    This involved use of the internet. Nintendo's alibi is air tight.

  2. Quote Originally Posted by Melf View Post
    I'm already in talks with someone about new hosting, so hopefully we'll be up soon.

    What I want to know is if this was an exploit from the first hack or came later. I don't know where else it could come from, since the exploit used before was fixed and the forums upgraded. I do wish I had a bit more time to find out what it was and what exactly needed to be done to have the site stable. We never had this issue in 7 years, and to suddenly see everything full of holes is more than a bit disconcerting.
    for what it's worth, when I checked out the files in question they all had the same april 22nd date (presumably from when you restored your data the first time) so it likely happened beforehand and has been sitting dormant/unnoticed

  3. Yeah, that's week after the hack and when it was restored, so things were there before I guess. I just don't understand how it never got exploited in 6 years and now it's gotten you guys reported. Why would someone do this now?

  4. #14
    Quote Originally Posted by Yoshi View Post
    Nintendo's alibi is air tight.
    I want to make a mom joke

  5. #15
    Don't do that, or all the nut hangers are going to start making the same post.

  6. What I still don't understand is why there would be java script code for eBay in our pages. We have never had anything to do with eBay, and the site's design code has been unchanged since it was implemented in 2005. How could it get there? Was it placed there during the hack as a means to further screw the site later on?

  7. Quote Originally Posted by Melf View Post
    What I still don't understand is why there would be java script code for eBay in our pages. We have never had anything to do with eBay, and the site's design code has been unchanged since it was implemented in 2005. How could it get there? Was it placed there during the hack as a means to further screw the site later on?
    It was probably injected at the same time. The issue is that the site engine must be revised to check if it wasn't. Someone simply wanted to use Sega 16 resources and that phishing page is an example. They used a vulnerability somewhere in the forums or the page code in order to write those files and folders, including the javascript code. There might be several other files in there.

    The best course of action is to restore everything on a private server, and then comb all the files and folders. Figure out which ones are from sega 16 and which ones are not, someone with expertise in unix would be useful.

    I am sure all people can be sourced form the community, we all love the site and forums.
    Last edited by Artemio; 22 May 2011 at 06:01 PM.

  8. Quote Originally Posted by Melf View Post
    What I still don't understand is why there would be java script code for eBay in our pages. We have never had anything to do with eBay, and the site's design code has been unchanged since it was implemented in 2005. How could it get there? Was it placed there during the hack as a means to further screw the site later on?
    I don't think so. Not everything can be blamed on hackers. I might be wrong, and I apologize if that is the case, but that page was pretty much just an auction that staff saved from eBay and uploaded whole onto Sega-16. That was a bad decision made sometime in the past that has repercussions now.

    Whoever hacked Sega-16 last time wrote a note saying, in effect, the site is full of holes; patch them up so I don't have to do this again. Whether that page was reported or not, the lesson to be learned here is that the site needs to be updated. If not, you will put it up on some other Web space and if another hijack takes place, you may find yourself out on the street with no access to your files and blacklisted as a risky site. It is simply irresponsible to ask anyone to host the site at this time. If that wasn't so, Sega-16 would still be "on the air" right now.

    You have FTP access to your files, so you won't have to re-upload everything from your PC. If you find a designer, just give him an FTP account and let him work on everything there. No one needs to go in and write malicious code if the site is vulnerable to begin with. Check not only your database but also your content. Make sure there is no external script or even a hotlinked image that can be taken advantage of.

  9. If you want to host something now, host only the forums and open them to the public, since that is patched and up to date. The site will have to wait until it is revised thoroughly.

  10. You are asking a lot. Remember, TNL's server was put in the line of fire three times now in the span of a month, I had to pay handsomely to resolve the problem, and the antagonists are persistent.

    My suggestion was to get a WordPress template going, make sure WordPress is kept up to date, and handle the main site that way. But even then . . . both WordPress and vBulletin need to update frequently because there are so many people trying to hack them. Who's to say that a vBulletin or WordPress exploit won't be found tomorrow and whoever it is that hates Sega-16 won't jump on it right away - before the developers even have a chance to roll out a fix?

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Games.com logo