68k Macintosh Liberation Army Forums
68k Macintosh Liberation Army Forums
Home | Members | Search | FAQ
 All Forums
 General 68kMLA News & Stuff
 68kmla server Hacked!
Author Topic  
Graphite Goodness
New Member


USA
88 Posts
Posted - 01 Apr 2002 :  11:55:52
Someone using Timaclover's login and pass has logged into the 68kmla server and gave both guest and reg. accounts a heave-how and made everyone unnamed guests with no permissions turned on. Go ahead try yourself! The name of this culprit was "www.gshag33.tk" his i/p was "64.166.61.59". When I messaged him he said he had to go and then disconnected me.

cinemafia
Guerrilla Recon Leader


USA
2965 Posts
Posted - 01 Apr 2002 :  11:59:20
Aha, so that why I haven't been able to login! What a b*stardo!

666th poster and 666th thread-creator
Mod of the Mac II series Forums
Total 68K Macs liberated: 7
Regular Disappear!

Edited by - cinemafia on 01 Apr 2002 12:01:58Go to Top of Page

Trash80toG-4
NIGHT STALKER


USA
2899 Posts
Posted - 01 Apr 2002 :  12:12:00
i don't do hotline so i can't check it out, which end of this alleged incident is the april fools joke?


jt

Go to Top of Page

cinemafia
Guerrilla Recon Leader


USA
2965 Posts
Posted - 01 Apr 2002 :  12:15:48
quote:
which end of this alleged incident is the april fools joke?

Well, as far as I can tell, the 68kMLA Hotline server has been inaccessible for at least two weeks...

666th poster and 666th thread-creator
Mod of the Mac II series Forums
Total 68K Macs liberated: 7
Regular Disappear!Go to Top of Page

TiMacLover
Senior Member


USA
1282 Posts
Posted - 01 Apr 2002 :  12:33:39
Ok I just got up right now and Graphite told me, I have been asking Da Penguin about secruity and stuff, another sad thing is that you can actually get the IP of a Hotline server and steal anyone's password on that server, it is really easy, I am glad if this is not some joke that my password was a dumb one not one I use for other things. I'll look some more into this.

Jeremy

"I'll see you on the Dark Side Of The Moon" - Pink Floyd

Covert Ops 68k
68k Hacks General
Macs Liberated:16Go to Top of Page

Trash80toG-4
NIGHT STALKER


USA
2899 Posts
Posted - 01 Apr 2002 :  12:34:13
quote:

Well, as far as I can tell, the 68kMLA Hotline server has been inaccessible for at least two weeks...



jt

Go to Top of Page

TiMacLover
Senior Member


USA
1282 Posts
Posted - 01 Apr 2002 :  15:42:08
what? IM serious!

Jeremy

"I'll see you on the Dark Side Of The Moon" - Pink Floyd

Covert Ops 68k
68k Hacks General
Macs Liberated:16Go to Top of Page

FireWire is fast
General, 4 star


USA
1559 Posts
Posted - 01 Apr 2002 :  15:47:10
any hackers in the house which would like to wreck havoc via his IP address?...

--------------------
keeper of the website and beholder of the Quadra/Centris Stick of Justice™
--------------------Go to Top of Page

Da Penguin
Senior Member


USA
1094 Posts
Posted - 01 Apr 2002 :  16:45:38
Ok first off my lesson has been to read ALL the forums before positng....duh penguin *hits head* (i poseted aboot this in 'website' if anyone ants waht i have on it.
Ok, anyhue, From waht I have found TiMac supposedly has a book mark of my server on his server for hotline.I *think*, i acquired this knowledge only a day ago when someone else was logged in and HONESTLY knew and tried asking me why he was in an admin account. So it looks like this has been all an honest mistake. However, in the past it has been the same person who has UL'd.........PPC!!!!!!! apps before. So his IP has been banned yadda yadda. As fore my IP, it changes on a 4-5 day basis, and i JUST changged it purposly now, so security should be all better *hopes*. As for why the server hasbeen down, new one lines in the whole house and OS problems.
Ugh, such a long day. If I come up with anything else, Ill post back. Over and out.

~The Penguin

|Captain, Intelligence Operations|
There is only one path and that is the path that you take, but you can take more than one path.
68k.torpedobird.com <-- Hotline ServerGo to Top of Page

cinemafia
Guerrilla Recon Leader


USA
2965 Posts
Posted - 01 Apr 2002 :  16:47:50
Thanks for the heads up, Penguin! I'll be looking forward to gettign back on the server soon!

666th poster and 666th thread-creator
Mod of the Mac II series Forums
Total 68K Macs liberated: 7
Regular Disappear!Go to Top of Page

Da Penguin
Senior Member


USA
1094 Posts
Posted - 01 Apr 2002 :  16:49:47
One more thing for Ti.,
Mail me with a new password for your account. It has been temp suspended just incase. Also, all accounts have been rightfully restored, just fyi. Maile me with any complaints or yadda yadda, magicpenguin@mac.com.

~The PenguinGo to Top of Page

TiMacLover
Senior Member


USA
1282 Posts
Posted - 01 Apr 2002 :  21:41:02
OMG! I am soo sorry, I really need to remeber what to and not to share! Sorry guys!

Jeremy

"I'll see you on the Dark Side Of The Moon" - Pink Floyd

Covert Ops 68k
68k Hacks General
Macs Liberated:16Go to Top of Page

Tallgeese
Full Member


USA
523 Posts
Posted - 01 Apr 2002 :  23:25:31

Bugger! Such problems! I suppose these are just logistical issues common to any army.

Sgt. Tallgeese
Thread Lord of Darkness
Apple II Squad Leader
68k Mac Liberation Army

68k Macs Liberated: 4Go to Top of Page

raWr
Junior Member


Tuvalu
491 Posts
Posted - 02 Apr 2002 :  00:40:45
http://samspade.org/t/asn?a=5678

traceroute adsl-64-166-61-59.dsl.frsn01.pacbell.net

Pac Bell Internet Services (NETBLK-PBI-NET-8) PBI-NET-8
64.160.0.0 - 64.175.255.255
FRSN01 ADSL Rback2 PPPoX (NETBLK-SBCIS-1001030-163039) SBCIS-1001030-163039
64.166.60.0 - 64.166.63.255

Fleet Covert Ops

Padlock MagnetGo to Top of Page

~Coxy
Leader, Tactical Ops Unit


Australia
2822 Posts
Posted - 02 Apr 2002 :  05:27:42
For a moment there I was worried about some permanent damage...

Good to here that nothing too bad happened.

~Coxy - Leader, Tactical Operations Unit
00014 Macs liberatedGo to Top of Page

raWr
Junior Member


Tuvalu
491 Posts
Posted - 02 Apr 2002 :  07:15:47
"


>From: "policy@pbi.net" <kana1@pbi.net>
>Reply-To: "policy@pbi.net" <kana1@pbi.net>
>To: Pál ----------- <littlegreencube@hotmail.com>
>Subject: SBCIS Policy Department (KMM154940V34120L0KM)
>Date: Tue, 02 Apr 2002 01:56:04 -0600
>
>THIS IS AN AUTO-RESPONSE MESSAGE - PLEASE DO NOT REPLY TO THIS MESSAGE
>
>Please read carefully! This may be the only response we send you.
>
>Thank you for writing Pacific Bell's Internet Policy Department. This
>address is designated for reporting violations of Pacific Bell's Terms &
>Conditions and Acceptable Use Policy.
>
>We make every effort to investigate all reports of abusive activity in
>a timely manner. The information that you have provided will be used to
>investigate the incident for violations of our Acceptable Use Policy and
>Terms & Conditions, which you can view at:
>
>http://public.pacbell.net/faq/
>
>If you are a Pacific Bell Internet customer writing concerning
>problems you are having with your Internet Service, please direct your
>message
>to the Technical Support Department at: support@pacbell.net.
>
>Since the current volume of email prohibits a personal reply to each
>report, unless additional information is required, THIS MAY BE THE ONLY
>RESPONSE YOU WILL RECEIVE.
>
>When reporting violations, please follow these guidelines in order to
>significantly expedite the investigation process:
>
>-> To report unsolicited commercial email (UCE/spam), please forward
>the entire message, including full headers, leaving the original subject
>
>
>line intact. You will recognize full headers by the "received" line(s)
>shown. If you need assistance in enabling full headers, please refer to
>the help section of your email client.
>
>-> To report off-topic commercial newsgroup postings, please forward a
>copy of the offending post, including full headers, leaving the original
>subject line intact.
>
>-> To report scans, probes, hacking attempts, or similar activity,
>please include an excerpt of your auto-generated log files showing
>ONLY THE INCIDENTS PERTAINING TO PACIFIC BELL INTERNET, cut & pasted
>directly into the email message, including:
>
> *Offending IP Address
> *Date
> *Specific Time
> *Time Zone
> *Source/Destination Ports
> *Any other brief pertinent details
>
>***Screenshots cannot be accepted in lieu of log excerpts.***
>
>***Please DO NOT INCLUDE TRACEROUTES, WHOIS LOOKUPS, or PING results,
>as these do not contribute to the investigation, and can often cause the
>
>
>message to become "garbled" or unreadable.***
>
>***Please make sure that you are not sending an attachment that is in
>a proprietary format (i.e. a log file readable only by your firewall
>program or one that requires special software to view, .xls). If you do
>send an attachment, please note the format type in your email
>message.***
>
>----------------------------
>Pacific Bell Internet
>Policy Department
>abuse@pacbell.net
>----------------------------"

I need the log files (I assume you have those!) sent to my email account. Time to stir things up


Fleet Covert Ops

Padlock MagnetGo to Top of Page

AnubisTTP
Junior Member


USA
308 Posts
Posted - 02 Apr 2002 :  07:16:34
Well Timaclovers iBook was just stolen and then someone breaks into the hotline server using his account. Doesn't it stand to reason that whoever did it is the one who stole his ibook, and that that person got the location of the server and the admin password out of his bookmarks or something. And unless the culprit has a static IP adderess I don't think we can do a portflood or launch much of any other type of "hack attack" aganst him.

AnubisTTP
68k Macintosh Liberation Army
Macs Liberated:15Go to Top of Page

Trash80toG-4
NIGHT STALKER


USA
2899 Posts
Posted - 02 Apr 2002 :  07:33:15
quote:

And unless the culprit has a static IP adderess I don't think we can do a portflood or launch much of any other type of "hack attack" aganst him.


even if the effort turns out fruitless, exploring possibilities and formulation SOP for next time and a how-to for site content is a really good idea, IMHO! some of you net geeks should pitch in, i'm useless on this one!


jt

Go to Top of Page

raWr
Junior Member


Tuvalu
491 Posts
Posted - 02 Apr 2002 :  08:35:10
Like i said - email me the logs, I'll take care of it. Since he has DSL (assuming he is a moron and that is his real IP address (highly likely)) his IP number is static. I on the other hand use a modem pool. Not that i h4><><0r, but still I also need date, time etc. Read the above mail thouroughly and then send files to me. ps ALL THAT HAXX0R IS BELONGS TO ME.

Fleet Covert Ops

Padlock Magnet

Edited by - raWr on 02 Apr 2002 08:40:36Go to Top of Page

Da Penguin
Senior Member


USA
1094 Posts
Posted - 02 Apr 2002 :  13:34:51
rawr, i got to almost the same conclusion today in school...heh, funny. Anyhue, i DO still need to know which logs you need, hotline splits them into
-UL's
-DL's
-Account Mods
-Attempted and working connections
-Errors

Im just tryin to keep file size down, even if u do have DSL. I'll snip up the parts you want, or send you the whole file. Let me know via email once again. Thanks for your help that I am unfortuneatly to busy to handle as of right now. Anyhue, lemme know. Magicpenguin@ mac.com

As for the attacker loggin in again and all. He attempted to login only a few hours later that nite, but hasnt since. His IP has been banned, which will temp keep him from connecting period. All Accounts have also been rotated and passwords swapped out. Extra redundant systems have been taken into account, this unfortuneatley includes removing some features from admins, but this is the price of security apparently. Still, I'm happy I'm running a mac, makes it that much harder for them to screw anything up too bad ;)

~The Penguin

|Captain, Intelligence Operations|
There is only one path and that is the path that you take, but you can take more than one path.
68k.torpedobird.com <-- Hotline ServerGo to Top of Page

Tallgeese
Full Member


USA
523 Posts
Posted - 02 Apr 2002 :  15:04:35

TRS-80, I'm with you... I feel like a netard. I learned most of my stuff before this 'inter-web' thing took off... I feel so old and out of it.

Sgt. Tallgeese
Thread Lord of Darkness
Apple II Squad Leader
68k Mac Liberation Army

68k Macs Liberated: 4Go to Top of Page

AnubisTTP
Junior Member


USA
308 Posts
Posted - 02 Apr 2002 :  15:34:10
Well I pinged the IP to see if it was connected and then did a port scan. I got replys on port 135 (the location service port according to AGnettools) and 139 (the NETBIOS Session Service port according to AGnettools).I am pretty sure NETBIOS is a PC thing, so it was most likely not done from a Mac.

AnubisTTP
68k Macintosh Liberation Army
Macs Liberated:15Go to Top of Page

Trash80toG-4
NIGHT STALKER


USA
2899 Posts
Posted - 02 Apr 2002 :  15:55:38
quote:


TRS-80, I'm with you... I feel like a netard. I learned most of my stuff before this 'inter-web' thing took off... I feel so old and out of it.




i try to keep the distinction between the net and the web clear in my own head at least! never really did the net, but the First-Class bbs interactions weren't all that different than this joint, except for the LINKS and google!

who was the guy who nailed the hackers (clifford stoller ?)? i've got a couple of really good magazine articles about net security, maybe i should get a firewall with as much time as i've been keeping the connection/browser running in the background while i'm "working!"

i feel out of it in terms of the nuts and bolts of that xml - html kinda stuff, but figuring the ins and outs of the information systems i think i'm finally starting to get a handle on!

maybe i CAN still learn a trick or two!


jt

Go to Top of Page

TiMacLover
Senior Member


USA
1282 Posts
Posted - 02 Apr 2002 :  16:38:12
WO WOW WOW NO....

Ok what is all this turing people in thing? I mean this is what happen when I had my own hotline server up I had my Links folder on sharing cause I have some good servers and I fotgot that I had the 68kMLA one with my login, someone mistakely downloaded and loged in thinking otherwise no hacking, the iBook was stolen a lil while ago and it was in OS X boot with a login so its useless

Jeremy

"I'll see you on the Dark Side Of The Moon" - Pink Floyd

Covert Ops 68k
68k Hacks General
Macs Liberated:16Go to Top of Page

Graphite Goodness
New Member


USA
88 Posts
Posted - 02 Apr 2002 :  19:45:41
Hold on a second. It said Fresno in the information that raWr found. I leave a few miles away from Fresno. I dont know anyone with DSL though. Theres only one person I know who is stupid enough to do this and he has cable. I'm thinking he was a wuss and used one of his friend's connections.I'd ask him if he did it , but he lies out of his teeth.

Go to Top of Page

Da Penguin
Senior Member


USA
1094 Posts
Posted - 02 Apr 2002 :  21:03:04
Whoa, enough of the policing of internet and rampaging on a bounty hunt mission. Simple Lil mistake on Ti's part. although you did get one thing wrong Ti, this person def knew what they was doing. Aboot a month ago they tried UL'ing PPC files. And now this under the same name. That is until they changed there name to 'new admin' screwedd with my admin account, then deleted it as well as lots of crucial files. Person knew what they was doing. BUT it has been stopped and no need to be completely alarmist IMHO. Then again maybe im just being too passive. Just my two cents

~The Penguin

|Captain, Intelligence Operations|
There is only one path and that is the path that you take, but you can take more than one path.
68k.torpedobird.com <-- Hotline ServerGo to Top of Page

Tallgeese
Full Member


USA
523 Posts
Posted - 02 Apr 2002 :  21:05:53

I think we'd better calm down before we turn into the "68k Mac Vigilante Posse"

Sgt. Tallgeese
Thread Lord of Darkness
Apple II Squad Leader
68k Mac Liberation Army

68k Macs Liberated: 4Go to Top of Page

MacMoose
Junior Member


USA
176 Posts
Posted - 02 Apr 2002 :  21:14:05
quote:

I think we'd better calm down before we turn into the "68k Mac Vigilante Posse"

Can I be the guy with the pitchfork?

------------------
MacMoose
Medical Spec., 68k MLA
Total 68K Macs liberated: 9 and counting
------------------
Go to Top of Page

Tallgeese
Full Member


USA
523 Posts
Posted - 02 Apr 2002 :  21:17:26

Only if I get to be Batman!

Sgt. Tallgeese
Thread Lord of Darkness
Apple II Squad Leader
68k Mac Liberation Army

68k Macs Liberated: 4Go to Top of Page

raWr
Junior Member


Tuvalu
491 Posts
Posted - 03 Apr 2002 :  00:11:10
I say we screw them.

Fleet Covert Ops

Padlock MagnetGo to Top of Page

~Coxy
Leader, Tactical Ops Unit


Australia
2822 Posts
Posted - 03 Apr 2002 :  06:12:00
quote:

who was the guy who nailed the hackers (clifford stoller ?)? i've got a couple of really good magazine articles about net security, maybe i should get a firewall with as much time as i've been keeping the connection/browser running in the background while i'm "working!"



Clifford Stoll, I think, if you're referring to "The Cuckoo's Egg" (which was fiction.)

~Coxy - Leader, Tactical Operations Unit
00014 Macs liberatedGo to Top of Page

Trash80toG-4
NIGHT STALKER


USA
2899 Posts
Posted - 03 Apr 2002 :  07:44:47
quote:

quote:

who was the guy who nailed the hackers (clifford stoller ?)?


Clifford Stoll, I think, if you're referring to "The Cuckoo's Egg" (which was fiction.)


thanks, not remembering that name was killin' me!
as i recall, the book was a fictionalized account of stoll's real life experiences. his contrarian views on the web were even more refreshing than dvorak columns. now i 've learned that there are two books full of them, thanks!

the blurbs are very interinsing and quite on topic:
http://shop.barnesandnoble.com/bookSearch/isbnInquiry.asp?userid=18OVQP4L6U&mscssid=VJQJ39GQVPMK8KV26VSWA6UFJB74D0V4&isbn=0-385-24946-2

jt

back again: why does the software seem to handle aome long urls and not others? this one comes out fine, others get munged up, anybody got a clue?

i was also wondering if there is a site that decodes isbn #'s and tells what category a book is in along with all the other info.

Edited by - trash80toG-4 on 03 Apr 2002 07:59:56Go to Top of Page

~Coxy
Leader, Tactical Ops Unit


Australia
2822 Posts
Posted - 03 Apr 2002 :  08:11:55
Are you referring to his non-fiction book: "Silicon Snake Oil" or something like that I think it was called.

Oh, and the URLs get screwed up not based on length, but when a site like google or altavista uses another URL as an index in, say, double quotes:

www.abc.com/cache=2348239482348283+"www.xyz.com"

~Coxy - Leader, Tactical Operations Unit
00014 Macs liberatedGo to Top of Page

Trash80toG-4
NIGHT STALKER


USA
2899 Posts
Posted - 03 Apr 2002 :  09:42:21
quote:

Are you referring to his non-fiction book: "Silicon Snake Oil" or something like that I think it was called.


the newer books andhis rep in the web community stem from his notoriety gained from events fictionalised in the original story. they do not appear to be referred to as fictional in the blurbs explaining who he is. i think i remember hearing about him in news stories from before the publication of cuckoos egg, but i could be wrong. check the blurbs, is it listed under fiction?

jt

Go to Top of Page

~Coxy
Leader, Tactical Ops Unit


Australia
2822 Posts
Posted - 03 Apr 2002 :  17:50:50
In our libraries it was listed under fiction, and his commentary books were non-fiction and under 004.

~Coxy - Leader, Tactical Operations Unit
00014 Macs liberatedGo to Top of Page

titok16
Junior Member


USA
116 Posts
Posted - 04 Apr 2002 :  00:32:36
enuf about books, lets establish 68ks as "hack machines"
sweet
i wish we could find jeremys ibook while dancing to mission impossible music

Tito

Tito
Macs Liberated:
Powerbook 145
Powerbok 150
Powerbook 160
Apple \\c (now dead)Go to Top of Page

raWr
Junior Member


Tuvalu
491 Posts
Posted - 04 Apr 2002 :  11:33:26
Little update...

"The use of Southwestern Bell Internet accounts to attempt to gain
unauthorized access to a host, server or network is prohibited by our
Acceptable Use Policy which may be found at the following URL:

http://public.swbell.net/faq/

I will investigate your complaint and take appropriate action.

On behalf of Southwestern Bell Internet, I apologize for any
inconvenience caused by our customer. Please do not hesitate to write
again if you have any questions or if you wish to report other instances
of abuse by Southwestern Bell Internet customers."


---------------------------------------------------------
Pacific Bell Internet Policy Department
abuse@pacbell.net
---------------------------------------------------------

Penguin: I trust that you know which parts of the logfiles I need. ;) You know, when was he online, what connection, UL, DL etc etc... How big are the logfiles?


RAWR.

Fleet Covert Ops

Padlock MagnetGo to Top of Page

Trash80toG-4
NIGHT STALKER


USA
2899 Posts
Posted - 04 Apr 2002 :  11:42:25
quote:

Penguin: I trust that you know which parts of the logfiles I need. ;) You know, when was he online, what connection, UL, DL etc etc... How big are the logfiles?


good work, raWr and penguin,
tag em' an' bag em'! *gives thumbs up!*


jt

Go to Top of Page

raWr
Junior Member


Tuvalu
491 Posts
Posted - 05 Apr 2002 :  04:11:30
combat.uxn.com

RAWR.

Fleet Covert Ops

Padlock MagnetGo to Top of Page

   

68k Macintosh Liberation Army Forums

© 2001-2003 68kMLA

Go To Top Of Page

68k of the Week: kastegir's PowerBook 180.