PDA

View Full Version : Kendo-world database hacked?



dotnet
5th June 2007, 04:20 AM
Did you get similar e-mails? The spammer got hold off the email-address I used when I registered with KW. I just hope the sender is fake ;-). I did not supply the header of the mail, but you'll find the content below. Or was it just an unlucky chain of events:

Sender:
online@kendo-world.com

subject:
Hi! all member kendo-world.com

content:
welcome to http://XXXXXXXXXXXXXX.biz Thebest site for all :D

Cheers,
dotnet

P.S.: I changed the URL, since I don't want to promote the site the spammer spamvertised .......

Kenzan
5th June 2007, 04:25 AM
I think Hamish is aware of this...
It appears he was working on the server this morning.

~And I am certain he will put something out later explaining what happened if he feels it is appropriate.

Personally, I also received multiple spam spoofs from the Kendo-World Server to all of my email accounts associated with this forum.
I could be wrong, It looked like a 'bot hack to me.

I am sure Hamish has it under control.

Neil Gendzwill
5th June 2007, 04:28 AM
He's updated the forum software to the latest version, which is why it was down for a little while. I've let him know of your concerns but I think he's probably packed it in for the night, it's about 4:30 am where he is.

samurai80
5th June 2007, 04:42 AM
I got the same message as Dotnet at my e-mail account but I didn't open it. I was wondering where that message came from.

dotnet
5th June 2007, 04:42 AM
Dear Kenzan, dear Neil,

don't worry. As long as he is aware of the leak its fine - at least with me ;-).

That's the price you have to pay for comfort (nice bulletin board software). You're always trying to fix weaknesses. My site actually got hacked (defacement) twice due to an unsafe plugin.

Cheers,
dotnet

nysamurai
5th June 2007, 05:13 AM
Ditto. I got it too. Looked kind if suspicious given the URL. I open the e-mail, thought better of it and deleted both of the strange messages I received. Some people have too much time on their hands, I suppose.

Mugu
5th June 2007, 05:15 AM
Has the "Hacker Viet Nam" user name in the "Welome" thread in the Women Forum always been there or is it just me started to notice that?

Paikea
5th June 2007, 05:24 AM
Has the "Hacker Viet Nam" user name in the "Welome" thread in the Women Forum always been there or is it just me started to notice that?That looks to be recent.That user did have a nasty little spam post earlier in the day...looks like they were busy.

Mugu
5th June 2007, 05:27 AM
That looks to be recent.That user did have a nasty little spam post earlier in the day...looks like they were busy.

What's strange about it that it was Hamish? who started the thread... but under the thread it says "Hacker Viet Nam".

Mugu
5th June 2007, 05:34 AM
This is (http://www.mludesign.com/stuff/thread.gif) what I mean

Neil Gendzwill
5th June 2007, 05:35 AM
Yes, that's on every thread started by Hamish. Not sure how to purge that corruption, maybe Hamish does.

Alex
5th June 2007, 02:21 PM
He got into Hamish's administrator area of the Forum Software, and caused a little bit of mischief. All is taken care of now, but please let us know if you notice anything strange going on.

Kyung
5th June 2007, 11:05 PM
Viet Nam guy hacked and posted at 10:4? AM yesterday (Monday). I noticed that name change of the first forum. Then soon the whole board went down.
Hate hackers.

ScottUK
5th June 2007, 11:10 PM
Hate hackers.They have their purposes - tameshigiri...

Alex
5th June 2007, 11:10 PM
Please your honour, just 5 minutes alone with the hacker in a dojo...:mad:

ScottUK
5th June 2007, 11:15 PM
How come that this is yours and Hamish's site, yet you post rarely? Don't tell me you actually spend your spare time practicing? :D

Alex
5th June 2007, 11:19 PM
too busy trying to make a magazine.

Neil Gendzwill
5th June 2007, 11:44 PM
He got into Hamish's administrator area of the Forum Software, and caused a little bit of mischief. All is taken care of now, but please let us know if you notice anything strange going on.The name as starter of any of Hamish's threads is still "Hacker Viet Nam". I couldn't fix it by mucking with Hamish's profile - you'll have to bust out some sql chops for that one.

hamish
10th June 2007, 11:32 AM
I've reviewed the hacker's activity, and he only seems to have sent mail out, and not compromised the database address list, so the mails that went out during the hack appear to be the limit of it.

I'm trying to repair the post name corruption now.

Hamish

LarsCW
10th June 2007, 11:14 PM
They have their purposes - tameshigiri...

kiri-kaeshi is way more fun, then some kiri-kaeshi men-doh and if he does it wrong 1 time he had to do the whole dojo of 200 all over:D

Hisham
11th June 2007, 07:56 PM
Take the best of both worlds, kiri kaeshi with a shinken, the hacker of course would only be given a shinai :evil: