Jump to content

Forum Board Roll Back


Recommended Posts

None ofd the pictures are showing for me, they are just showing little Red X's.

 

I had that problem before, but then realised that I wasn't waiting long enough for the pictures to download. You'd never guess I had a degree in IT would you? 8)

Link to comment
Share on other sites

Guest yaduk

As many of you are aware Shetlink was the subject of technical difficulties over the weekend. This was definetly a "malicious attack", but almost undoubtedly had absolutely nothing to do with the Sakchai campaign.

 

The phpBB application is prone to remote file-include vulnerabilities due to a failure in the application to properly sanitize user-supplied input. The forum encapsulated within php-Nuke, Shetlinks software, is a variation of the main phpBB development thread built specifically for php-Nuke.

 

An attacker can exploit the remote file-include issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible - in this case the attacker was interested in and able to send spam emails originating from the Shetlink domain. This is very much how a lot of spam is sent across the Net along with zombie computer nets etc.

 

With this process and subsequent arbitrary code the perpetrator(s) also attempted to apply; for means unknown, code into the Shetlink sites database backend - this caused an incident of corruption in several interconnecting tables - the site is based on 113 backend tables. It was for this reason that it was decided with much regret to close the site and re-load with a backup copy from the previous night. Bryan and the Shetlink team decided it best to have the site re-launched and fire-fight the situation as the site was/is an integral communication point of the Sakchai campaign.

 

The sites software was patched and from scouring all server logs, "rules" specific to the attack have been formulated and injected into the security module of the http server, thus stopping dead in its tracks any further similar attempt. Ironically for Shetlink their mis-fortune has in fact increased the security for all other sites hosted on yadUKHosting with the new "rules" applied.

 

I do hope this clears any misconception in the weekends goings on.

 

Lastly I wish the Sakchai Campaign all the best in its task.

 

Kind regards,

 

John

Link to comment
Share on other sites

Pictures looking OK here. More than likely it is loading in a cached copy. Internet Explorer is notorious for failing to load websites correctly once the amount of temporary internet files collects up.

 

Go to Tools > Internet Options > Click on 'Delete Files'. Probably best to do this when you aren't viewing the Shetlink site.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
 Share

×
×
  • Create New...