PDA

View Full Version : Hacked By MDHr : MaD Hacker - MDHr BEATS YOU ALL



darkcurves
September 3rd, 2004, 08:22
http://www.keretapi.com/guestbook/index.php

WTF? This idiot hacked one of sites.

Nick
September 3rd, 2004, 15:39
Some 13 year old kid thinks he's ------.

trenzterra
September 4th, 2004, 06:43
Pretending to be elitist.

Ignite
September 4th, 2004, 06:51
They seem to enjoy hacking WebWiz Forums & guest books..

Decker
September 4th, 2004, 08:17
And left the link to his site in the source

http://madoz.jeeran.com/hack.gif

twit

Corazu
September 4th, 2004, 11:00
Someone want to report him to his host ;) ? Sure, it's practically harmless. But I'd like to ssee this idiot get busted ^^

Regards,

Robert
September 4th, 2004, 11:18
I've already sent a letter to the upstream provider located in the U.S. Asked them if they wonder if the FBI would be interested in knowing that one of the clients that is hosted within their network performs illegal activities.

Decker
September 4th, 2004, 11:19
One of those - 'We don't care' and it's not in our terms and conditions places.

I spend a load of time reporting attempts to hack into servers and get nothing back or really lame 'thank you' responses.

I recon that anyone who hosts should ban the IP

Techrad
September 4th, 2004, 11:25
What a SFI. :-)

Decker
September 4th, 2004, 11:51
SFI - where are you seeing that SFI Techrad

stabme
September 4th, 2004, 12:45
LOL. that's not a hack. not even close. it's called.. your guestbook script is a pos that allows html in it :p

trenzterra
September 4th, 2004, 21:04
LOL. that's not a hack. not even close. it's called.. your guestbook script is a pos that allows html in it :p
In that case, one poor bloke is getting reported for performing illegal activities when what he did was to post HTML.

jmiller
September 5th, 2004, 01:18
The kid exploited a well-known hole in a script, what's the big deal ?

Happens all the time.

Just check OSVDB for vulnerabilities, then Google for instances of the script -- I guarantee you will find the same thing.

Decker
September 5th, 2004, 05:33
Who know's what they'll try next though, if they get away with it it can become clumsy and damaging. Even if it's just having their connection pulled it shows them they've been caught.

darkcurves
September 5th, 2004, 06:03
The kid exploited a well-known hole in a script, what's the big deal ?

Happens all the time.

Just check OSVDB for vulnerabilities, then Google for instances of the script -- I guarantee you will find the same thing.

That's doesn't mean everything will be ok.

Btw, does anyone know how to remove that. I think that ---- is in my MYSQL database. Please, somebody.........

Decker
September 5th, 2004, 06:12
Check the source of the page for his stuff and search your db for it, I doubt it'll be hard to find as it's a pretty amature attempt, if you really hit a prob finding it mail me an sql dump and I'll see if I can find it :)

darkcurves
September 6th, 2004, 12:10
Thanks man, i will PM you.

stabme
September 6th, 2004, 14:59
In that case, one poor bloke is getting reported for performing illegal activities when what he did was to post HTML. it's not hacking. hacking is illegal access to a machine. (actually, that's cracking; hacking are programming shortcuts).

all he did was exploit a bad-written script that allowed html... that's not hacking, as he didnt intrude or abuse a machine. all it is is showing off, and also it is other people's stupidity.

it doesnt actually break something. it's not even as severe as other xss things, just a simple html code that doesn't affect anything or pose any security risks or alter any hard coding or data.

Decker
September 7th, 2004, 12:09
What he did was 'deface' a site, we know everyone normally get's the terms the wrong way round and that's not the real problem. It can more clearly be referred to as 'malicious damage' which is an ilegal activity. So showing off or not as you can see it's caused the site owner problems invloving clean up work which at least would normally allow a civil case to reclaim expenses for that and a punative amount for other reasons.

There's no reason to try and justify this type of thing, it should be actively discouraged, lets face it at least half of the costs of any webhosting resource is due to costs involved in protecting infrastructure & systems - if it stopped they wouldn't be necessary. In my book a good reason to discourage it and report any offenders.

FTWebD
September 9th, 2004, 16:51
I googled to find information on this "attack" after a client of mine had his website defaced via this "attack". We've reported all the information we have gathered and sent a report to the FBI. Regardless of whether it is "hacking", which it could be becuase you are still changing and editing data on a remote machine without permissions.

Anyways, just floating around the Internet.

Nick

stabme
September 9th, 2004, 17:19
it is NOT "changing and editing data on a remote machine without permissions." .. its adding HTML which affects the output of a website. nothing has been changed. nothing has been edited. NOTHING. just because you're ignorant and don't understand how it works doesn't make it HACKING. do some god damned research before reporting people and wasting the FBI's time.

second of all, you can't do anything without an IP and timestamp. third of all, the first step is to go to the ISP, NOT the fbi. but since it's not hacking, it doesn't matter anyway!

trenzterra
September 9th, 2004, 21:18
it's not hacking. hacking is illegal access to a machine. (actually, that's cracking; hacking are programming shortcuts).

all he did was exploit a bad-written script that allowed html... that's not hacking, as he didnt intrude or abuse a machine. all it is is showing off, and also it is other people's stupidity.

it doesnt actually break something. it's not even as severe as other xss things, just a simple html code that doesn't affect anything or pose any security risks or alter any hard coding or data.
Er, did I mention anything about hacking in that post?

CAWUnited.com
September 9th, 2004, 22:34
Btw, does anyone know how to remove that. I think that ---- is in my MYSQL database. Please, somebody.........

I'm not sure how exactly that guestbook works, but if you can search the posts, look for layer1 or <div in the posts. If that doesn't work, e-mail me at admin@cawunited.com and i'll help you some more.

edit: didn't see the second page.. but if you still need help, let me know
: Just incase you didn't find out which one posted it, it was entry number 51 by joe. his hostname is dyn-83-155-175-153.ppp.tiscali.fr It was on Sunday, 13. June 2004 04:39 AM