Some bunch of #%&$s hacked our website

General conversations about Go belong here.
Javaness
Lives with ko
Posts: 293
Joined: Wed Apr 21, 2010 1:20 am
GD Posts: 0
Has thanked: 10 times
Been thanked: 41 times

Some bunch of #%&$s hacked our website

Post by Javaness »

Some rotten toads hacked the IGA website.
Why do people have to do that. I have had to spend 3 hours now getting it cleaned and reinstalled etc before it can be unsuspended.
RAGE


PS: Anyone know where to find the A-Team?
User avatar
kirkmc
Lives in sente
Posts: 1072
Joined: Tue Apr 20, 2010 3:51 am
Rank: 5K KGS
GD Posts: 1165
KGS: Dogen
Location: Stratford-upon-Avon, England
Has thanked: 32 times
Been thanked: 70 times
Contact:

Re: Some bunch of #%&$s hacked our website

Post by kirkmc »

Javaness wrote:Some rotten toads hacked the IGA website.
Why do people have to do that. I have had to spend 3 hours now getting it cleaned and reinstalled etc before it can be unsuspended.
RAGE


PS: Anyone know where to find the A-Team?


3 hours? You don't have backups? If you back up regularly, it should take you a very short time to reload everything. Just sayin'...
My blog about Macs and more: Kirkville
User avatar
cdybeijing
Lives in gote
Posts: 581
Joined: Fri Apr 30, 2010 2:27 am
Rank: IGS 2 dan
GD Posts: 0
Location: Shanghai, China
Has thanked: 96 times
Been thanked: 100 times
Contact:

Re: Some bunch of #%&$s hacked our website

Post by cdybeijing »

kirkmc wrote:
Javaness wrote:Some rotten toads hacked the IGA website.
Why do people have to do that. I have had to spend 3 hours now getting it cleaned and reinstalled etc before it can be unsuspended.
RAGE


PS: Anyone know where to find the A-Team?


3 hours? You don't have backups? If you back up regularly, it should take you a very short time to reload everything. Just sayin'...


Kick a man while he's down, why don't you?! ;-)
User avatar
TMark
Lives in gote
Posts: 325
Joined: Wed Apr 21, 2010 11:06 am
GD Posts: 484
Location: The shores of sunny Clapham
Has thanked: 1 time
Been thanked: 283 times
Contact:

Re: Some bunch of #%&$s hacked our website

Post by TMark »

Kicking a man when he is up is rather difficult; the best time is when he down. Backup early, backup often. Any computer professional should know that.

Best wishes.
No aji, keshi, kifu or kikashi has been harmed in the compiling of this post.
http://www.gogod.co.uk
User avatar
Fedya
Lives in gote
Posts: 603
Joined: Tue Apr 20, 2010 8:21 pm
Rank: 6-7k KGS
GD Posts: 0
Has thanked: 43 times
Been thanked: 139 times

Re: Some bunch of #%&$s hacked our website

Post by Fedya »

kirkmc wrote:
3 hours? You don't have backups? If you back up regularly, it should take you a very short time to reload everything. Just sayin'...

I'm surprised you didn't tell him this wouldn't have happened if he'd been using a Mac. :razz:
User avatar
kirkmc
Lives in sente
Posts: 1072
Joined: Tue Apr 20, 2010 3:51 am
Rank: 5K KGS
GD Posts: 1165
KGS: Dogen
Location: Stratford-upon-Avon, England
Has thanked: 32 times
Been thanked: 70 times
Contact:

Re: Some bunch of #%&$s hacked our website

Post by kirkmc »

Fedya wrote:
kirkmc wrote:
3 hours? You don't have backups? If you back up regularly, it should take you a very short time to reload everything. Just sayin'...

I'm surprised you didn't tell him this wouldn't have happened if he'd been using a Mac. :razz:


Nothing to do with Macs. I manage a bunch of web sites and forums (all on hosted Linux servers). I have daily backups of the SQL databases, and regular backups of all files. If something like this happens, just delete everything and reload the backups.

Of course, you need to find how the hackers got in, which is a more serious problem. If you're using a CMS, you look for vulnerabilities; if not, there's a problem with your host.
My blog about Macs and more: Kirkville
vash3g
Lives with ko
Posts: 277
Joined: Thu Apr 29, 2010 8:49 pm
Rank: 5k
GD Posts: 111
Has thanked: 41 times
Been thanked: 87 times

Re: Some bunch of #%&$s hacked our website

Post by vash3g »

AGA is looking for a new webmaster, maybe they can help you find one too... ^_^
Decisions are made by those who show up.
and possibly those willing to attend secret meetings in ancient basements
User avatar
wms
Lives in gote
Posts: 450
Joined: Tue Apr 20, 2010 4:23 pm
GD Posts: 0
KGS: wms
Location: Portland, OR USA
Has thanked: 257 times
Been thanked: 287 times
Contact:

Re: Some bunch of #%&$s hacked our website

Post by wms »

And the three hours thing might mean with backups. KGS does a nightly backup to my server at home, but I have several gigabytes of database and a few hundred GB of game records. Plus there's a lot of configuration involved. If I had to start from a freshly formatted disk with just the OS (which is always best after being hacked), it would probably take me a solid day of hard work to get things working, then another day or two to get all the games put back.
User avatar
Numsgil
Lives in gote
Posts: 614
Joined: Wed Apr 21, 2010 10:07 am
Rank: 1 Kyu KGS
GD Posts: 0
KGS: Numsgil
Has thanked: 28 times
Been thanked: 65 times

Re: Some bunch of #%&$s hacked our website

Post by Numsgil »

wms wrote:but I have several gigabytes of database and a few hundred GB of game records.


Are the game records not stored in a database? I ask purely from curiosity :)
Javaness
Lives with ko
Posts: 293
Joined: Wed Apr 21, 2010 1:20 am
GD Posts: 0
Has thanked: 10 times
Been thanked: 41 times

Re: Some bunch of #%&$s hacked our website

Post by Javaness »

3 hours is roughly the entire timeframe for the trouble.
Discovering the website has some problem, figuring out what on earth is going on, finding out how to actually get some support from your hosting company, working out what to do (because it is not my job), doing it..
User avatar
wms
Lives in gote
Posts: 450
Joined: Tue Apr 20, 2010 4:23 pm
GD Posts: 0
KGS: wms
Location: Portland, OR USA
Has thanked: 257 times
Been thanked: 287 times
Contact:

Re: Some bunch of #%&$s hacked our website

Post by wms »

Numsgil wrote:
wms wrote:but I have several gigabytes of database and a few hundred GB of game records.


Are the game records not stored in a database? I ask purely from curiosity :)
No, they are not. Multi-kbyte blocks of data can go into a database as BLOBs or TEXTs, but usually a plain file system is more efficient (especially if the files are rewritten frequently, as is the case for in-play KGS game records). After all, a file system *IS* a database, in that it maps file names to streams of data, and it does that extremely efficiently.

In addition to the runtime efficiency issues, having them as separate files makes it a lot easier to work with the backups; backing up 40 million smallish files, only a few thousand of which change or get added every day, is pretty easy. Backing up a 350GB database is a lot more effort.
wessanenoctupus
Dies with sente
Posts: 116
Joined: Wed Apr 28, 2010 11:50 pm
Rank: KGS 1k
GD Posts: 417
KGS: badukboris
Has thanked: 12 times
Been thanked: 31 times

Re: Some bunch of #%&$s hacked our website

Post by wessanenoctupus »

hey there Mr.WMS

could you put up a torrent of the KGS database :-)

it might be fun to look at.
User avatar
kirkmc
Lives in sente
Posts: 1072
Joined: Tue Apr 20, 2010 3:51 am
Rank: 5K KGS
GD Posts: 1165
KGS: Dogen
Location: Stratford-upon-Avon, England
Has thanked: 32 times
Been thanked: 70 times
Contact:

Re: Some bunch of #%&$s hacked our website

Post by kirkmc »

wessanenoctupus wrote:hey there Mr.WMS

could you put up a torrent of the KGS database :-)

it might be fun to look at.


"It might be fun?" 350 GB to download just because "it might be fun"? Geez...
My blog about Macs and more: Kirkville
User avatar
Mehmet
Beginner
Posts: 15
Joined: Tue May 04, 2010 11:52 pm
Rank: 1k
GD Posts: 82

Re: Some bunch of #%&$s hacked our website

Post by Mehmet »

How is it easy to hack a web site? Do you have a firewall?

I'm not a expert but do your web site use other than 8080 port? Close any other unused ports.
User avatar
Li Kao
Lives in gote
Posts: 643
Joined: Wed Apr 21, 2010 10:37 am
Rank: KGS 3k
GD Posts: 0
KGS: LiKao / Loki
Location: Munich, Germany
Has thanked: 115 times
Been thanked: 102 times

Re: Some bunch of #%&$s hacked our website

Post by Li Kao »

Mehmet wrote:How is it easy to hack a web site? Do you have a firewall?

I'm not a expert but do your web site use other than 8080 port? Close any other unused ports.

One of the most common types of attack is exploiting a known whole in standard web-applications like CMS, forums,...
Sanity is for the weak.
Post Reply