You have commented 339 times on Rantburg.

Your Name
Your e-mail (optional)
Website (optional)
My Original Nic        Pic-a-Nic        Sorry. Comments have been closed on this article.
Bold Italic Underline Strike Bullet Blockquote Small Big Link Squish Foto Photo
Hacked...
2005-07-20
As you probably guessed, we got hacked again last night, again from an IP address in Germany. It looks like a pretty determined attack, specifically on Rantburg. We probably have another server swap coming up, since hacker boy's Serv-U daemon looks like it's called from logon.dll.

I've got an important meeting this afternoon. I'll clean up as much mess as I can this morning, then try and finish up this evening. I think I've figured how he got in this time, but since he's determined and seems to know what he's doing, I'm going to have to call a pro to help us out.
Posted by:Fred

#51  Heh, jules 2, you'll have Dr Steve prescribing himself sedatives if you keep that up...
Posted by: .com   2005-07-20 23:49  

#50  To all you Mac lovers out there-

Four years ago I got talked into going Mac because I am an artist/musician, and a trusted friend said Mac would be the best thing for me.

Well Macs are good for graphics and music, but not much else. Now I have a Mac at home and at work and I would love to switch back to Windows. Yeah, Windows may be more susceptible to inflitration, but Macs, unlike what their commercials say, are completely unintuitive and generally a big headache. And in terms of communication functions, they suck big-time.
Posted by: jules 2   2005-07-20 23:41  

#49  bad's not a programmer - he's a hobbyist. And they know everything. Just ask 'em.

The point isn't whose fucking label you wear - it's to get the fucking job done. You use the best tools you can get. Those who think ANY system is perfect or perfectly safe are fools. Connect it and it's vulnerable, period. And, of course, access denial is available against any system.

The pros go to Cert and the other sites which aren't overtly cheerleading their latest stock purchase or own personal xDS problem.
Posted by: .com   2005-07-20 22:23  

#48  Oh goody. A programmer slapfight. Don't go too far yet, guys. I gotta go upstairs and get my mom so she can watch it too.
Posted by: Pappy   2005-07-20 22:12  

#47  You sound like you got caught cold, had your ass handed to you, and are attempting to play it cool like you're not a fool, bad.

How's that raspberry?

Kos, huh?
Posted by: .com   2005-07-20 22:05  

#46  You can post all the bile you want, but the fact is you overplayed your hand on this thread, once with Gromky's post and once with mine.

You sound like a Usenet troll, .com Sounds like you've been dipping your beak youself as well. Want sugar with koolaid?
Posted by: badanov   2005-07-20 22:00  

#45  #43 - Lisp (lost in stupid parentheses)
Posted by: Whiskey Mike   2005-07-20 21:55  

#44  I hear ya, 3dc - and you've got some interesting ideas in the thread.

badass - Smear? Lol, I didn't smear anyone - unless they're suffering as described. Read it again - it's accurate... snared you, didn't it, lol! You must have the official /. pizza-stained T-shirt.

I'm the one who keeps quiet around here while the sufferers spew - regularly. Even Fred has said some things here during his ASP -> PHP changeover that were NOT true or casually implied ASP was at fault, when it was clearly server configuration. I kept my mouth shut. That you don't notice those things which fit your bias, but can't contain yourself over my post, must mean something, eh? You want to equate me with Kos, huh? Really. Hmmm. I hear your pain, which is a personal problem, but I'm not Kos. I'm a old guy who has been programming for over 30 years on one hell of a range of systems and right smack dab in the middle of it all in realtime. You?

I use what works best - and often I have to factor in the money and compatibility with that. Period. So I use a mix of stuff. I don't wear anyone's T-Shirt, don't have anyone's bumper sticker on my car, and don't subscribe to the Open Source Socialism - which is actually boosted in a ploy on the clueless by commercial adversaries, such as Sun's McNealey, Oracle's Ellison, et al. Torvalds? Great. Cool. Socialist Twit. I like capitalism, Comrade Badass. You?

Kos, huh... I'll remember your uber-sensitivity in future posts. Never thought we'd get here, but hey - your call. You're just yet another Asshole With A Cause - in this case swilling the dipshit SlashDot Kool Aid.
Posted by: .com   2005-07-20 21:05  

#43  PD - it's like this. The less users of an OS, the less people who have a clue how to hack it.

Hell add a few protocols onto Multics and you will have an OS with hardly any likely hacker base.

The same would go for VM-370, the P-System, ....
My fantasy involves Plan 9 implemented as SDL machines in Pascal or Ada. It just wouldn't be worth a hacker's effort.

Posted by: 3dc   2005-07-20 20:09  

#42  Great smear, PD. Kos could use you.

I will point out that only one mention in this entire thread was made of Unix products versus Windows products, but I guess you just couldn't help it. And here I was keeping quiet. Guess that old GDS just kicked it for me, huh?
Posted by: badanov   2005-07-20 19:48  

#41  ima need a math slo prosessor for my 486s SpOd, are they cheap?
Posted by: half   2005-07-20 19:44  

#40  I recommend Zoloft for them (The Crackers) and a round of Beers for US. Well, all of us who drink that is PD.

I'll hit the tip jar when I can. This new central conditoning I am going to choke down this weekend is cramping my funds (there goes several new computers).

My computing motto is I use what works. If it's free or nearly free thats great. But that doesn't exclude paying for an OS or aplication if I have to. Hell I even pay for my Linux. PD knows whats up and he has been doing this Computing thing a LONG time.

Yea I have been owned too, on a BSD based system my Host provides. No OS is totally secure, none.
If anyone thinks there is I have some dual core 486s I'll sell them.
Posted by: Sock Puppet 0’ Doom   2005-07-20 18:57  

#39  There are many flavors of Kool Aid, Bush Derangement Syndrome and Gates Derangement Syndrome are two of the loudest examples - and neither of them is the Devil or Hitler or a chimp or any of the other brainless demonization icons currently tossed around by the thoughtless and clueless. Everybody is standing on a huge pyramid of shoulders. All of the xDS sputterings are emotional, not factual. Any system can be swamped / denied, if not hacked, smurfed or spoofed. Anyone who actually understands the OSI model, OSPF / router programming, server OS's, and TCP/IP and other protocols knows the truth is that they all work as well as they do is the marvel, not the infrequent outage.

Thanks, Fred - you and your brainchild, Rantburg, truly rock. Thanks, also, to the PARC team, BBN, et al, lol. For those who would like to know some of the background, search your memory and you'll find a PBS documentary... Triumph of The Nerds. Yeah, that's the show's transcript - which chronicles the birth of personal computing. Enjoy. Webopedia does a decent job of chronicling the birth of the Internet. For the xDS sufferers, get a life - and meds, strong meds. This shit is soooo old and soooo lame.
Posted by: .com   2005-07-20 18:26  

#38  $5 says it was some college hacker type Muslim kid attending school at the university of who the fuck somewhere here in the states using a proxy out in the wild blue yonder to launch attacks. All likelihood just some netnut like the unspun losers.

the Enemy is at the Gates. Cyber guerilla psyops? I'm sure we're all scared to death. Anyway, good luck with the idiots, whomever they are Fred.

EP
Posted by: ElvisHasLeftTheBuilding   2005-07-20 17:29  

#37  You might want to look at SecureIIS

http://eeye.com
Posted by: mojo   2005-07-20 15:55  

#36  Wasn't me or anyone of the family...
Probably a Muslim hacker kid, maybe only using one of those open German proxies.
Posted by: True German Ally   2005-07-20 15:39  

#35  They see that we're having fun here, and it's not their kind of fun.

Besides, they don't like intellect.
Posted by: Bobby   2005-07-20 15:33  

#34  It is queer, Educated. Why do they feel this overwhelming need to bother us when they have so many other sandboxes to play in?
Posted by: trailing wife   2005-07-20 15:28  

#33  This web site seems to be the target of a lot of disgruntled chaps wanting to vent their anger.
Posted by: Educated   2005-07-20 15:15  

#32  I hit it last week for "beauzeaux control" .....little did I know...
Posted by: Frank G   2005-07-20 15:10  

#31  I feel Fred Anger all around the Burg. Ima just go sit quietly somewhere and promise to hit the jug Jar 1st of September.
Posted by: Shipman   2005-07-20 14:39  

#30  Die you ferign evil-doers, die.....
Posted by: Captain America   2005-07-20 13:10  

#29  Thank God, Fred. Last night I awoke in a heavy sweat. I dreamed I was the innocent, well-intended RB server being attacked by evil foreigners from afar. This IS a war on terror.
Posted by: Captain America   2005-07-20 13:08  

#28  Image of WINE running on windows with gnome window manager
Posted by: 3dc   2005-07-20 12:28  

#27  hey! Thanks Fred for all you have done.

And to the 'Crackers' out there. You aren't smarter then everyone else -- its just that you dont have a life unlike everyone else and can thus waste your life being a stinky little turd -- nobody else would want your life....
Posted by: CrazyFool   2005-07-20 12:10  

#26  Also, Fred, if you want... you have my e-mail. Send me a code ZIP or tar ball and I could see if I can get it to run under the WINE windows emulator.
That would let you run multiple copies too.
Restoration us usually just a unzip or
"tar -xjf tarball" away. (quick)

I do the wife's windows that way. She's really running linux but has her confortable windows applications. She gets a virus browsing the wrong place... 30 seconds to restore. (ok she doesn't do mail on linux so her mail takes a tad more care.)


Posted by: 3dc   2005-07-20 12:00  

#25  Sorry but with Linux we have, between other things, selinux that it is military-grade or more exactly spook-grade security (originated in the NSA). With SELINUX if a service is out of date and hacked it will be unable to cause damage even with root access rights.

Posted by: JFM   2005-07-20 11:55  

#24  I'm going to have to call a pro to help us out.

Wow. I thought Fred was as professional as there is. Poor, stupid, ungezogener hackerboy.

Hi! My name is trailing wife, and I can find nothing on the web to take the place of Rantburg.
Posted by: trailing wife   2005-07-20 11:55  

#23  I'm real good at the beer drinking part. My computer skills end where those long black string-like things (wires?) enter the big square box.
Posted by: Steve   2005-07-20 11:52  

#22  Whoops - License restrictions prevent the use of the sucessful WindowsXP port under XEN. (Somebody needs to figure out how to force Bills evil hand to play ball someday... - course someday never comes.)

XEN virtulization performance

IBM's mainframe product is "IBM zServer machine" so if you find some hosting service using these machines restoration is real quick.

Posted by: 3dc   2005-07-20 11:52  

#21  I have no idea how to set up a proxy. On the other hand, Robi Sen's pretty close by, and I know where they sell beer... Shoot me an email.
Posted by: Fred   2005-07-20 11:48  

#20  Steve I bet you can even put your foot up on the bumper and lean in *just so* when the server hood is open...

Fred, sorry you've got this nonsense to deal with.
Posted by: Seafarious   2005-07-20 11:48  

#19  Figured something bad happened -- I knew it couldn't be my Mac!

Thanks for the info, Fred, and let me and the other moderators know what we can do to help. I'm really good standing next to someone at the computer, beer in hand, kibbitzing away.
Posted by: Steve White   2005-07-20 11:44  

#18  At the risk of slower speed.
Running windows from a virtual machine would make restoration much easier and the whole thing more robust.

The idea would be a virtual server on an old IBM mainframe. (They can do virtual windows or linux servers for load balancing and ease of replacement) Lots of IBM mainframes are used for that these days. Some of the virtual serving companies are actually that.

The cheaper solution is a BSD or Linux machine running VMWARE or similar and having windows as a hosted operating system. Think of it as a overlay that can be swapped out on the fly and replaced with an alternate or backup. You could have several rantburgs running at once. It would drive the hackers crazy.

an example of VMware honeypots is here.

Xen is the best virtual machine with almost no speed reduction problems BUT you need to get special versions of Windows to run on it.
XEN info

Posted by: 3dc   2005-07-20 11:42  

#17  Fred - better make sure Robi Sen is NOT from Germany!

Well, just because I'm paranoid doesn't mean somebody isn't after me®!
Posted by: Bobby   2005-07-20 11:28  

#16  Fred,

I would be happy to help you lock down your systems and make them secure. Unlike what gromky implies any system on the network can be hacked and its more or less just as easy to hack a Linux system that is not locked down as a Windows one. Its just that Unix and Linux people tend to be more knowledgable and proactive. Its pretty simple though to make Windows systems secure enough to keep out everyone except the most sophisticated of attackers.
Posted by: Robi Sen   2005-07-20 11:17  

#15  Well said, Anon! Thanks for all you do, Fred! I was beginning to get the shakes too. I know, I know, the first step is admiting you have a problem. OK, here goes:

"Hi, I'm BA, and I have a REAL problem with the Religion of Pieces."

"Hi, BA!"
Posted by: BA   2005-07-20 11:11  

#14  Looks like another freedom fighter from enlightened and sophisticated Europe, taking on the imperialist, warmongering US red staters that slander the Religion of Peace(Tm).

Well, if indeed he's german, he's living in a dying out country that will belong to its turkish immigrants in just a few decades (sorry, TGA, but that's what I think). For now, he's part of the fighting avant-garde, but in his old days (with social security bankrupt), he'll be a stranger in his own country. I wonder if he will then keep the same worldview?
Hackerboy may be a nuisance, but he will end up in the trashbin of History, despite his holier-than-you attitude and his belief in him being on the side of Goodness.

Mr. Pruitt, keep up the good work, and thanks again for RB! Don't let theses undersexed neo-leftist geeks drag you down! You've achieved and lived more than what they'll ever be able to do in their pitiful lives!
Posted by: anonymous5089   2005-07-20 10:58  

#13  This isn't the only site I've had access problems with over the last 36 hours. It seems like the whole net is slowed down today.
Posted by: Abdominal Snowman   2005-07-20 10:53  

#12  likem th muki, 10 arts oly holdy mee fern 2 hr.
Posted by: Shakie the peachseedy   2005-07-20 10:47  

#11  Fred, Is it OK to use a proxy at RB?
Posted by: Red Dog   2005-07-20 10:39  

#10  Gee, TGA, couldn't you just comment like normal people? [wag]
Posted by: Jackal   2005-07-20 10:39  

#9  Fred, Is it OK to use a proxy at RB?
Posted by: Red Dog   2005-07-20 10:39  

#8  Might be a good time to hit the tip jar...
Posted by: Dragon Fly   2005-07-20 10:37  

#7  German you say? Send in the Royal Flying Corps...
Posted by: Howard UK   2005-07-20 10:34  

#6  What is needed is an electronic RPG that can travel through the internet, destroy his computer and burn his nasty little hands. Hackers are a very strange and weird breed-they seem to have a great deal of ego involvement in their hacking. They like to think they are smarter than everyone else. Good luck Fred in trying to deal with this dorkus.
Posted by: John Q. Citizen   2005-07-20 10:26  

#5  thanx fed. ima get overn teh shakens now.
Posted by: muck4doo   2005-07-20 10:22  

#4  Thanks again for all your effort Fred. Wish I knew more to help.
Posted by: Yosemite Sam   2005-07-20 10:22  

#3  Well, I hate to say I told you so, but a Windows-based server is just asking to get hacked. Rantburg seems pretty married to the Windows platform, though, so I don't really see any solution. :(
Posted by: gromky   2005-07-20 10:21  

#2  Thanks Fred. Gxd - I had have the RB jones bad!!
Posted by: Doc8404   2005-07-20 10:20  

#1  Thought so,noticed things getting wierd last night.Fred you are a priceless jem.
Posted by: raptor   2005-07-20 10:17  

00:00