For Neopets ONLY discussion.
Topic locked

Wed Dec 22, 2004 2:42 am

Hey all. Most of you prob. dont know me, but I am a regular at neocolours. for the past couple of days, our main index to our forums has been hacked. today when I try and get on, agahst! it is all gone. We are pretty sure that it is a networm that has been going around, and we are all suffering from withdrawl, hence my visiting here. I just want to say that I am very touched that you guys were worrying about us, and just wanted to say thank ya very much :)

Wed Dec 22, 2004 2:52 am

the_neopia_fairy wrote:I don't get it...just what is so "exploitable" about the forums as they are now?

Something in the coding that can be abused, that's all.

Yes, it probably is because of that new worm, which spread quite rapidly. The reason that PPT and a few other phpBB sites (Gaia Online comes into my head) is because they're upgraded to 2.0.11, which is safe from the hackings/worms because the exploitable code is fixed.

So yes, we're safe, and so is everyone who visited the forums. What I've read indicates that it only attacks webservers, not our computers.

Wed Dec 22, 2004 2:54 am

hey Illuen, this is Two-Tone from the neocolor forum

Wed Dec 22, 2004 2:58 am

I recognsed ya two-tone. You will never guess this, but I am illuen at the neocolours forum. I know, It is a complete mystery how i came with the name I have on ppt. I am just crazy like that, ya know? Being completely random and all :)

Wed Dec 22, 2004 3:16 am

This site is defaced!!!

--------------------------------------------------------------------------------

NeverEverNoSanity WebWorm generation 10.


Thats what it says now ><;;

Wed Dec 22, 2004 3:20 am

plushie wrote:
This site is defaced!!!

--------------------------------------------------------------------------------

NeverEverNoSanity WebWorm generation 10.


Thats what it says now ><;;

Yep, that's the same worm that's wreaking havoc at similar forums.

Wed Dec 22, 2004 3:22 am

DiscordantNote wrote:
plushie wrote:
This site is defaced!!!

--------------------------------------------------------------------------------

NeverEverNoSanity WebWorm generation 10.


Thats what it says now ><;;

Yep, that's the same worm that's wreaking havoc at similar forums.


Its not just the forums, the main site also...

Wed Dec 22, 2004 6:51 am

I remember a lot of posts from the Neocolors forums.
A lot of very interesting posts.

*shrugs* I'm sad the sites been hacked, and I hope you enjoy your stay.

Wed Dec 22, 2004 7:02 am

DiscordantNote wrote:Yep, that's the same worm that's wreaking havoc at similar forums.


YOu go onto Google and look up "this site has been defaced" and you find at least 30 pages of results that say that. o_o Wow... this is really going around....

Wed Dec 22, 2004 8:58 am

This isn't affecting vBulletin type forums is it? If it is, there's someone I need to contact asap before it gets his!

Wed Dec 22, 2004 11:13 am

this sounds really bad, I hope they clear this up asap

Wed Dec 22, 2004 1:39 pm

Somebody posted on Neocolours' Livejournal Community saying that they'd phoned sam, and he said he'd fix it as soon as he had internet.

Wed Dec 22, 2004 1:40 pm

Not hacked, wormed. There's a new worm (Santy.A) that attacks forums using pHpbb.

http://www.computerworld.com/securityto ... 53,00.html

"Worm uses Google to hit thousands of PHP sites"
http://www.cbronline.com/article_news.a ... 4C5E4E36DE

So it's a internet-wide thing...not a single person :x

According to Symantec... "Perl.Santy is a worm written in Perl script that attempts to spread to Web servers running versions of the phpBB 2.x bulletin board software prior to 2.0.11., which are vulnerable to the PHPBB Remote URLDecode Input Validation Vulnerability (BID 11672). Other systems are not affected. If successful, the worm copies itself to the server and overwrites files with the following extensions:"

So, PinkPT is NOT at risk of attack :) "Powered by phpBB 2.0.11 (0) © 2001, 2002 phpBB Group"

Wed Dec 22, 2004 3:22 pm

whoa, so it's a virus eh?

Wed Dec 22, 2004 4:01 pm

Shadowcat301 wrote: Then I went to the main page and it said that the site is defaced. It also said this: NeverEverNoSanity WebWorm generation 10. Hmm...
!!! That's the third site I've saw which that happened to! Is anybody safe anymore? :o
Topic locked