Bottom Gun BBSSubmarineSailor.com
Find a Shipmate
Reunion Info
Books/Video
Binnacle List (offsite)
History
Boat Websites
Links
Bottom Gun BBS
Search | Statistics | User listing Forums | Calendars | Quotes |
You are logged in as a guest. ( logon | register )


At random: "The Navy is not a job, it's not a career. It's a way of life.” -- MMCM (SS) "Grump" Barrie
Crew Database down indefinitely - I got hacked!
Moderators:

Jump to page : 1 2
Now viewing page 1 [25 messages per page]
   Forums-> Submarine DiscussionMessage format
 
Don Gentry
Posted 2009-07-11 10:20 AM (#28491)


Admin

Posts: 2297

Location: Renton, WA
Subject: Crew Database down indefinitely - I got hacked!

Looks like I'm a victim of SQL Injection attack.  Someone got access to the crew database and added a bunch of references to a website.  The bad thing is it overwrote data in many instances.  One of the fields that got attacked was the one that stores email addresses (don't worry, they weren't stolen, just modified).  I'm busy stripping out all the bogus SCRIPT references but some email addresses have definitely be truncated (shortened) and rendered useless.  It's too early to tell but it could be that ten years of this labor of love could have just gone up in smoke.  I am so pissed that if I could somehoe find the low-life son of a bitch that did this, I could shoot him between the eyes and sleep like a baby.

The database is off line for I don't know how long...

The BBS is fine.

Ric
Posted 2009-07-11 10:22 AM (#28492 - in reply to #28491)


Plankowner

Posts: 9165

Location: Upper lefthand corner of the map.
Subject: RE: Crew Database down indefinitely - I got hacked!

Probably one of those dipsticks we've been chasing fora year now and closing off their avenues of attack.
PatH
Posted 2009-07-11 10:27 AM (#28493 - in reply to #28491)


Great Sage of the Sea

Posts: 618

Location: Issaquah WA, USA
Subject: RE: Crew Database down indefinitely - I got hacked!

If you find the dirty dog that did that, I volunteer for the firing squad!  Rotten s.o.b.!
Stoops
Posted 2009-07-11 1:06 PM (#28497 - in reply to #28491)
Master and Commander

Posts: 1405

Location: Houston, TX (Best state in the US)
Subject: RE: Crew Database down indefinitely - I got hacked!

It was the Norks~!

Edited by Stoops 2009-07-11 1:07 PM
Ralph Luther
Posted 2009-07-11 1:31 PM (#28499 - in reply to #28491)
COMSUBBBS

Posts: 6180

Location: Summerville, SC
Subject: RE: Crew Database down indefinitely - I got hacked!

In a way I'm sorry to have blown the whistle but then again it could have gotten worse. Don if there is anything we can do..holler.
Don Gentry
Posted 2009-07-11 6:25 PM (#28508 - in reply to #28499)


Admin

Posts: 2297

Location: Renton, WA
Subject: RE: Crew Database down indefinitely - I got hacked!

This is separate from the Google issue and antivirus alerts.  I got the double-whammy.
MAD DOG
Posted 2009-07-12 5:10 AM (#28509 - in reply to #28508)


Master and Commander

Posts: 1262

Location: Va.Beach,Va.
Subject: RE: Crew Database down indefinitely - I got hacked!

Probably the same jackasses who've been sending all those unsolicited e-mails
addressed to "Shipmate".
RCK
Posted 2009-07-12 9:38 AM (#28510 - in reply to #28509)
Master and Commander

Posts: 1431

Subject: RE: Crew Database down indefinitely - I got hacked!

MAD DOG - 2009-07-11 8:10 PM

Probably the same jackasses who've been sending all those unsolicited e-mails
addressed to "Shipmate".


Can't be the same people who have been sending me unsolicited E- Mail addressed to s**thead. I guess they can't spell.
Ric
Posted 2009-07-12 12:50 PM (#28514 - in reply to #28510)


Plankowner

Posts: 9165

Location: Upper lefthand corner of the map.
Subject: RE: Crew Database down indefinitely - I got hacked!

...I wasn't sure those were getting through..... LOL
snakeyez
Posted 2009-07-12 1:06 PM (#28516 - in reply to #28491)


Senior Crew

Posts: 186

Location: Chunky, MS
Subject: RE: Crew Database down indefinitely - I got hacked!

Yeah it seems that running a website with anything besides basic HTML requires daily monitoring and backups. You have to keep all of your software up to date and even then there are things that are out of your hands. Like your host having the most up to date software.

You know about blocking unwanted IP addresses/ranges with the use of a .htaccess file right?
chiefjoe
Posted 2009-07-13 3:48 AM (#28530 - in reply to #28491)
Senior Crew

Posts: 188

Location: Manassas, VA
Subject: RE: Crew Database down indefinitely - I got hacked!

Don,

If there is a monetary incursion to recover, Please post it. I am willing to absorb part of it and I think the community would help.

Joe P
Ralph Luther
Posted 2009-07-13 5:26 AM (#28531 - in reply to #28530)
COMSUBBBS

Posts: 6180

Location: Summerville, SC
Subject: RE: Crew Database down indefinitely - I got hacked!

Don, Joe has a great idea. Do let us know and I'm certain the hat will be passed.
PaulR
Posted 2009-07-13 6:13 AM (#28532 - in reply to #28530)


Master and Commander

Posts: 1269

Location: Hopewell Junction NY
Subject: RE: Crew Database down indefinitely - I got hacked!

chiefjoe - 2009-07-13 6:48 AMDon,If there is a monetary incursion to recover, Please post it. I am willing to absorb part of it and I think the community would help.Joe P


Great idea..."I'm All In".
Pig
Posted 2009-07-13 8:48 AM (#28536 - in reply to #28491)
Plankowner

Posts: 5024

Location: Gulfport, MS
Subject: RE: Crew Database down indefinitely - I got hacked!

Count me in. Don has made this "our board"... "we" should cover the cost of fixing it.
Ralph Luther
Posted 2009-07-13 9:00 AM (#28538 - in reply to #28531)
COMSUBBBS

Posts: 6180

Location: Summerville, SC
Subject: RE: Crew Database down indefinitely - I got hacked!

Dog-gone Don, I should have your snail mail address here somewhere. Damn CRS has set in again.
Anyone with Don's snail mail address please post it or send it to me PM. It's past due for me to send him some dinero to run this show. Thanks in advance
GaryKC
Posted 2009-07-13 1:33 PM (#28546 - in reply to #28491)


COMSUBBBS

Posts: 3670

Location: Kansas City Missouri
Subject: RE: Crew Database down indefinitely - I got hacked!

Don

I'm not a smart as the other fellers, don't know what "monetary incursion to recover" is, but I'd be glad to send you some money if it will help.

Ric
Posted 2009-07-13 2:58 PM (#28548 - in reply to #28516)


Plankowner

Posts: 9165

Location: Upper lefthand corner of the map.
Subject: RE: Crew Database down indefinitely - I got hacked!

Don's an IT propeller head.. he probably does...

Flapper
Posted 2009-07-13 3:25 PM (#28549 - in reply to #28491)


Master and Commander

Posts: 1107

Location: Tucson AZ
Subject: RE: Crew Database down indefinitely - I got hacked!

I'm in too, if there is a collection plate being passed.
Ralph Luther
Posted 2009-07-13 4:27 PM (#28553 - in reply to #28538)
COMSUBBBS

Posts: 6180

Location: Summerville, SC
Subject: RE: Crew Database down indefinitely - I got hacked!

Shipmates, I dug down into my archives and found Don's addy:

Don Gentry
912 2nd St.
Renton, WA 98057

Now Don, don't you go scrubbing this off the thread. Let us have the opportunity to lend a hand from one Shipmate to another.
Corny
Posted 2009-07-14 12:00 AM (#28560 - in reply to #28491)


Plankowner

Posts: 23

Location: Riverside, CA
Subject: RE: Crew Database down indefinitely - I got hacked!

Just saw this thread. Had been gone since early Saturday morning, racing at El Mirage. Very sorry to hear your database was hacked. Count me in if a donation to the "Ships Kitty" is needed to cover repairs.

Corny

Don Gentry
Posted 2009-07-14 2:20 AM (#28561 - in reply to #28553)


Admin

Posts: 2297

Location: Renton, WA
Subject: NO MONEY NEEDED- but THANKS!!!

Money is not an issue shipmates - but thanks for the gesture!!  Please don't send anything - heck, I'm a double-dipper as of six months ago so as long as I stay employed, I'm setting pretty well

I have most of the data recovered with the biggest loss being some email addresses being truncated (shortened) by the malicious code.  I'm keeping the database off line until I can ramp up security - one of my hockey teammates is a security guy who is helping me with that as he's up to speed on the latest attacks.

I hope to be back online by the end of the month - stay tuned.

Don Gentry
Posted 2009-07-14 2:21 AM (#28562 - in reply to #28560)


Admin

Posts: 2297

Location: Renton, WA
Subject: RE: Crew Database down indefinitely - I got hacked!

Corny, how'd you guys do in El Mirage?
miss lumpy bumps
Posted 2009-07-14 5:12 PM (#28564 - in reply to #28491)


COMSUBBBS

Posts: 2540

Location: Wappingers Falls, NY
Subject: RE: Crew Database down indefinitely - I got hacked!...HE'S BACK...

and none too soon...withdrawl started to set in!!!
miss lumpy bumps
Posted 2009-07-14 5:17 PM (#28565 - in reply to #28561)


COMSUBBBS

Posts: 2540

Location: Wappingers Falls, NY
Subject: RE: NO MONEY NEEDED- but THANKS!!!

TOO LATE!!!
Corny
Posted 2009-07-14 5:41 PM (#28567 - in reply to #28562)


Plankowner

Posts: 23

Location: Riverside, CA
Subject: RE: Crew Database down indefinitely - I got hacked!

Our '38 Coupe was still at home in the shop. Almost all back together (new head, new cam, suspension changes and more) but it will be ready for Bonneville in 3 weeks. The goal is 160 on the 3 mile course. We want to put the record out of reach. We will have the car back at El Mirage in Sept to run the 1.3 mile course with a lower geared rearend. Goal there is 150.

Our club had 8 vehicles running at El Mirage last weekend (4 cars and 4 motorcycles) and I had Patrol Duty on Sunday. It was very HOT but we all had a great time.

In June we had a pretty bad MC crash at El Mirage. (not one of the Road Runners) I don't think I sent you the pictures. I will mail them to you in a separate e-mail. As bad as the crash looked, he only had some minor bleeding in the brain, some cuts and bruises and 2 or 3 cracked vertebrea. He will be in a neck brace for 6 to 8 weeks and is off work for a while but all things considered, he was a very lucky fellow.

Jump to page : 1 2
Now viewing page 1 [25 messages per page]
Printer friendly version
E-mail a link to this thread
Jump to forum :


(Delete all cookies set by this site)
Running MegaBBS ASP Forum Software v2.0
© 2003 PD9 Software