Go Sensations website hacked
-
Kaya.gs
- Lives with ko
- Posts: 294
- Joined: Fri Aug 12, 2011 10:52 am
- Rank: 6d
- GD Posts: 0
- KGS: Dexmorgan
- Wbaduk: c0nanbatt
- Has thanked: 25 times
- Been thanked: 78 times
- Contact:
Re: Go Sensations website hacked
Im actually quite surprised at this. Go4Go was affected the same way which can say this was pretty targeted.
Specially because there is really no motivation whatsoever to "hack" a site like GoSensations, which has absolutely no security value whatsoever.
Specially because there is really no motivation whatsoever to "hack" a site like GoSensations, which has absolutely no security value whatsoever.
Founder of Kaya.gs
-
uPWarrior
- Lives with ko
- Posts: 199
- Joined: Mon Jan 17, 2011 1:59 pm
- Rank: KGS 3 kyu
- GD Posts: 0
- Has thanked: 6 times
- Been thanked: 55 times
Re: Go Sensations website hacked
hermitek wrote:It was already hacked on 21. february. I guess they don't care about security much.
That's likely not the issue here.
This are go websites after all, so they are not run by professional web developers and big companies. I wouldn't be surprised if they didn't know how the attackers got those privileges on the first place.
-
badukJr
- Lives with ko
- Posts: 289
- Joined: Sat Jan 07, 2012 1:00 pm
- Rank: 100
- GD Posts: 100
- Has thanked: 7 times
- Been thanked: 42 times
Re: Go Sensations website hacked
Kaya.gs wrote:Im actually quite surprised at this. Go4Go was affected the same way which can say this was pretty targeted.
Specially because there is really no motivation whatsoever to "hack" a site like GoSensations, which has absolutely no security value whatsoever.
That's why security by obscurity is a failed idea. I hope that is considered for your website.
- RBerenguel
- Gosei
- Posts: 1585
- Joined: Fri Nov 18, 2011 11:44 am
- Rank: KGS 5k
- GD Posts: 0
- KGS: RBerenguel
- Tygem: rberenguel
- Wbaduk: JohnKeats
- Kaya handle: RBerenguel
- Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
- Location: Barcelona, Spain (GMT+1)
- Has thanked: 576 times
- Been thanked: 298 times
- Contact:
Re: Go Sensations website hacked
Security by obscurity is not the issue here (and usually in most web attacks): any web page online can be hacked. My Google account could be compromised, my VPS server could be compromised. And there's no obscurity roaming around: I have a Google account (obviously), and my VPS runs Arch Linux (although I use a high entropy, long passphrase)
Geek of all trades, master of none: the motto for my blog mostlymaths.net
-
brodie
- Dies in gote
- Posts: 48
- Joined: Mon May 02, 2011 3:10 pm
- Rank: kgs 10 dgs 14
- GD Posts: 15
- KGS: brodie
- DGS: brd
- Location: taipei
- Has thanked: 10 times
- Been thanked: 9 times
Re: Go Sensations website hacked
For those that have said that x is likely not the issue here, what do you suppose the issue was? A hacker practicing, goofing off, or a kid that lost his last game on kgs by a half moku and was pissed at the go world?
- RBerenguel
- Gosei
- Posts: 1585
- Joined: Fri Nov 18, 2011 11:44 am
- Rank: KGS 5k
- GD Posts: 0
- KGS: RBerenguel
- Tygem: rberenguel
- Wbaduk: JohnKeats
- Kaya handle: RBerenguel
- Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
- Location: Barcelona, Spain (GMT+1)
- Has thanked: 576 times
- Been thanked: 298 times
- Contact:
Re: Go Sensations website hacked
Brodie, it was probably someone running an automated server scanner probably tied to an automated hacking tool. If the server is unprotected, bam. No need for it to be a go player, know the site or anything: you just run it against a list of IPs and a bell rings when one server can be hacked.
Security by obscurity is a way to secure a site (or something) just not telling how it was done. For example, if you use a custom built operating system or webserver stack (one you did in your spare time), it is only secure because no-one has cared to look at how to crack it, not because it is top-notch secure.
Security by obscurity is a way to secure a site (or something) just not telling how it was done. For example, if you use a custom built operating system or webserver stack (one you did in your spare time), it is only secure because no-one has cared to look at how to crack it, not because it is top-notch secure.
Geek of all trades, master of none: the motto for my blog mostlymaths.net
- daal
- Oza
- Posts: 2508
- Joined: Wed Apr 21, 2010 1:30 am
- GD Posts: 0
- Has thanked: 1304 times
- Been thanked: 1128 times
Re: Go Sensations website hacked
RBerenguel wrote: ...No need for it to be a go player...
'Cept that his hack included a message that he had also hacked a series of go-related websites.
Patience, grasshopper.
- RBerenguel
- Gosei
- Posts: 1585
- Joined: Fri Nov 18, 2011 11:44 am
- Rank: KGS 5k
- GD Posts: 0
- KGS: RBerenguel
- Tygem: rberenguel
- Wbaduk: JohnKeats
- Kaya handle: RBerenguel
- Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
- Location: Barcelona, Spain (GMT+1)
- Has thanked: 576 times
- Been thanked: 298 times
- Contact:
Re: Go Sensations website hacked
It was a message in the RSS feeds/subsections. I thought that "hacked" was referring to these parts. Also afaik KGS has never been hacked.
Geek of all trades, master of none: the motto for my blog mostlymaths.net
-
brodie
- Dies in gote
- Posts: 48
- Joined: Mon May 02, 2011 3:10 pm
- Rank: kgs 10 dgs 14
- GD Posts: 15
- KGS: brodie
- DGS: brd
- Location: taipei
- Has thanked: 10 times
- Been thanked: 9 times
Re: Go Sensations website hacked
Seems to have happened again, but under the Tygem section, and this time with the signature of Anonymous. Unless, of course, this is an April Fool's joke by Go Sensations lampooning their security problems a little while back. I'm not sure, neither of them quite seem to make sense...
- balistic
- Dies in gote
- Posts: 44
- Joined: Sun Dec 11, 2011 1:55 am
- GD Posts: 0
- Has thanked: 14 times
- Been thanked: 5 times
Re: Go Sensations website hacked
It's a legit breach. The intruder claiming to be "anonymous" (what a joke) is actually some noob who is in effect using gosensations to generate money using a bitcoin javascript miner. 
edit: effectively > in effect
edit: effectively > in effect
Last edited by balistic on Mon Apr 02, 2012 9:29 pm, edited 2 times in total.
-
Grisalger
- Beginner
- Posts: 9
- Joined: Mon Oct 24, 2011 11:06 am
- Rank: 2 dan
- GD Posts: 0
- Has thanked: 1 time
- Been thanked: 1 time
Re: Go Sensations website hacked
balistic wrote:It's a legit breach. The intruder claiming to be "anonymous" (what a joke) is actually some noob who is effectivly using gosensations to generate money using a bitcoin javascript miner.
Noob question: what does this mean? How can those "anonymus we are legion"-posts make money?
-
cata
- Dies with sente
- Posts: 72
- Joined: Sun Sep 25, 2011 9:39 pm
- Rank: KGS 2k
- GD Posts: 0
- KGS: cata
- Has thanked: 1 time
- Been thanked: 24 times
Re: Go Sensations website hacked
They can't make money, it's FUD. This strategy would be less effective than changing the homepage to a Paypal link that says "please send me money, thanks."
-
Grisalger
- Beginner
- Posts: 9
- Joined: Mon Oct 24, 2011 11:06 am
- Rank: 2 dan
- GD Posts: 0
- Has thanked: 1 time
- Been thanked: 1 time
Re: Go Sensations website hacked
So it is not effectively generating any money then?
I am still curious about what the strategy is. How does someone believe he will make money by posting on gosensations, I can't come up with a strategy that would work even in the imagination of the most delusional. I have no idea about any of this. It's as mysterious to me like ko to a 30 kyu.
I am still curious about what the strategy is. How does someone believe he will make money by posting on gosensations, I can't come up with a strategy that would work even in the imagination of the most delusional. I have no idea about any of this. It's as mysterious to me like ko to a 30 kyu.