Author Topic: Short story: Security on evilzone  (Read 886 times)

0 Members and 1 Guest are viewing this topic.

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Short story: Security on evilzone
« on: April 16, 2013, 09:56:20 am »
One day Factionwars implemented a Google custom search function into the forum software as a experiment.


A few days later, at a stunning time of 6 in the morning, 2 administrators called ande and bluechill found out about the feature and thought we were compromised. They thought someone implemented a malicious google custom search in our site 8) .


So the 2 admins started crawling trough every log the linux system possess and go trough every file to see where a possible hacker got trough (Which is in the first place very unlikely). They went on for hours. And when the admin Factionwars comes online after a good night of sleep the admin ande asked him if he implemented the google custom search. Yep, he did. Ande is happy, so is the security.


And they lived happily ever after.
« Last Edit: April 16, 2013, 11:17:15 pm by ande »
~Factionwars

Offline WirelessDesert

  • Knight
  • **
  • Posts: 356
  • Cookies: 10
  • I think...
    • View Profile
Re: Short story: Security on evilzone
« Reply #1 on: April 16, 2013, 10:33:35 am »
Nice. Good job Factionwars, good job.
Check out my arduino project: Moving car - School project!
"I'm like current, I always take the easiest route."

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Short story: Security on evilzone
« Reply #2 on: April 16, 2013, 01:33:37 pm »
It would have been the first hacker to implement a "google search" maliciously.
Fuck sweet.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline bluechill

  • Cybermancer
  • Royal Highness
  • ****
  • Posts: 682
  • Cookies: 344
  • I am the existence in these walls
    • View Profile
Re: Short story: Security on evilzone
« Reply #3 on: April 16, 2013, 03:24:00 pm »
No so the problem is EvilZone gets enough views a month that it might be worth it to do because of ad revenue you would get hence why we were concerned because it looked like the person who did this, Factionwars, had touched *other* files as well and his login times weren't quite consistent with the modification because of an error in how the server was keeping file times vs ssh login times...

Basically we didn't have the protections we needed to truly figure out whether it was an admin or not who did this but now we do after this scare :P

Also it was only 12am my time when I messaged you so nbd on my part.
« Last Edit: April 16, 2013, 03:27:17 pm by bluechill »
I have dreamed a dream, but now that dream has gone from me.  In its place now exists my own reality, a reality which I have created for myself by myself.

Offline ande

  • Owner
  • Titan
  • *
  • Posts: 2664
  • Cookies: 256
    • View Profile
Re: Short story: Security on evilzone
« Reply #4 on: April 16, 2013, 08:13:43 pm »
Funny story bro
if($statement) { unless(!$statement) { // Very sure } }
https://evilzone.org/?hack=true

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: Short story: Security on evilzone
« Reply #5 on: April 16, 2013, 10:04:00 pm »
Nice. Good job Factionwars, good job.
NO, thanks to the admins who are always alert. We have faith in you guys.
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]

Offline ande

  • Owner
  • Titan
  • *
  • Posts: 2664
  • Cookies: 256
    • View Profile
Re: Short story: Security on evilzone
« Reply #6 on: April 16, 2013, 11:18:05 pm »
I always enjoy an all-nighter digging through insane amounts of logs :)  ...
« Last Edit: April 16, 2013, 11:18:13 pm by ande »
if($statement) { unless(!$statement) { // Very sure } }
https://evilzone.org/?hack=true