17b's Hacking |
14/03/2017 - 09:29:56 |
Post
#1
|
|
Group: 17 Buddies Posts: 18 535 Joined: 27/12/2003 Team: Dev. 17b |
17b a une nouvelle fois été hacké avec mise en place de fichiers frauduleux sur notre serveur. Google m'en a averti par mail.
Pour l'instant j'ai supprimé une partie des fichiers incriminés et rechargé ma dernière sauvegarde "propre". Cela fait 2 fois en 2 mois qu'un pirate s'introduit sur notre site. Il installe des fichiers permettant d'envoyer du spam. Cela doit l'amuser. (IMG:http://forum.17buddies.rocks/style_emoticons/default/icon_nul.gif) Je n'ai malheureusement pas les compétences ni le temps pour résoudre ce problème et les fondateurs historiques de 17b qui avaient ces compétences ne sont plus disponibles pour ça non plus. J'en appelle donc aux bonnes volontés qui souhaiteraient d'une façon ou d'une autre aider EatingPizza à résoudre ce problème. Je reste bien évidemment à la disposition d'EatingPizza pour lui donner tous les codes d'accès nécessaire au réglement du problème. Pour moi s'en est fini et je vous confie mon bébé. Je vous demande juste d'en prendre soin. (IMG:http://forum.17buddies.rocks/style_emoticons/default/bye.gif) Nous avons passé de bons moments ensemble. Il est maintenant temps pour moi de tourner la page. (IMG:http://forum.17buddies.rocks/style_emoticons/default/wub.gif) (IMG:http://forum.17buddies.rocks/style_emoticons/default/wub.gif) ======================================================================== Once again 17b has been hacked with setting up fraudulent files on our server. Google notified me by e-mail. For now I deleted some of the offending files and reloaded my last "clean" backup. It is 2 times in 2 months that a pirate is introduced on our site. It installs files to send spam. That must amuse him. (IMG:http://forum.17buddies.rocks/style_emoticons/default/icon_nul.gif) Unfortunately, I do not have the skills or the time to solve this problem and the historic founders of 17b who had these skills are no longer available for it either. So I appeal to the good will who would somehow help EatingPizza to solve this problem. I remain of course at the disposal of EatingPizza to give him all the access codes necessary to solve the problem. For me it is finished and I entrust my "baby" to you. I just ask you to take care of it. (IMG:http://forum.17buddies.rocks/style_emoticons/default/bye.gif) We had a great time together. It is now time for me to turn the page. (IMG:http://forum.17buddies.rocks/style_emoticons/default/wub.gif) (IMG:http://forum.17buddies.rocks/style_emoticons/default/wub.gif) |
|
|
16/03/2017 - 19:21:47 |
Post
#2
|
|
Group: Advanced Posts: 20 Joined: 27/07/2012 |
Chapo I have a lot of respect for you, but even you haven't been able to eliminate the hacks and you know the 17B site better than anyone. I've always said that I was just here to help fund the site. Now I have OVH accusing me of repeatedly sending spam because nobody is stopping the hacks, just restoring the the same code that gets hacked again and again and again.
|
|
|
16/03/2017 - 23:18:27 |
Post
#3
|
|
Group: 17 Buddies Posts: 18 535 Joined: 27/12/2003 Team: Dev. 17b |
Chapo I have a lot of respect for you, but even you haven't been able to eliminate the hacks and you know the 17B site better than anyone. I've always said that I was just here to help fund the site. Now I have OVH accusing me of repeatedly sending spam because nobody is stopping the hacks, just restoring the the same code that gets hacked again and again and again. I don't think that vulnerability comes from code. Instead I think that The problem is a server problem. I can code hundred and hundred of php lines, but I have no idea how to secure a server. For ten years, when security was supervised by Nosferatu we were never hacked. Since we changed of provider, security features we had before have not been reinstalled and somebody has seen that. Of course it's not our responsibility. But I think it would be simple to solve problem. (IMG:http://forum.17buddies.rocks/style_emoticons/default/icon_ami.gif) |
|
|
17/03/2017 - 00:37:50 |
Post
#4
|
|
Group: Advanced Posts: 20 Joined: 27/07/2012 |
Since we changed of provider, security features we had before have not been reinstalled and somebody has seen that. The provider has not changed, it is still OVH. The server size was chosen by former 17B member(s) who then setup and configured the new server after I purchased it. It's been a struggle to identify who is responsible for maintaining the server, and I've always tried to remain on the sidelines, but now that you are leaving Chapo who is left to do the admin, fixes, and security? Who remains? |
|
|
17/03/2017 - 20:56:33 |
Post
#5
|
|
Group: 17 Buddies Posts: 179 Joined: 22/10/2008 Team: Les Scarapotes |
The provider has not changed, it is still OVH. The server size was chosen by former 17B member(s) who then setup and configured the new server after I purchased it. It's been a struggle to identify who is responsible for maintaining the server, and I've always tried to remain on the sidelines, but now that you are leaving Chapo who is left to do the admin, fixes, and security? Who remains? Just curious. This guy responsible for maintaining the server, what did he do? Did he installed some things related to security? Or nothing at all? This post has been edited by Arkshine: 17/03/2017 - 20:57:34 |
|
|
Lo-Fi Version |
Skin © Chapo
|