Site Attack

Status
Not open for further replies.

bobster1982

Club Member
Aug 9, 2007
4,024
1,198
Grimsby
Well Hello!

over 7 hours work but we are back.. No hiding anything so here is the full run down of what happened. Excuse the technical terms and the rambling but im a bit drained so I will try and keep it simple

At approx 18:00 the site was attacked by a DDOS

This caused a server error allowing a group of hackers called the 2600uk KREW access to the servers root. They installed 2 scripts and tied them into the system files of the forum with the vision of causing a bit of mayhem. Unluckily for them the countermeasures installed on the database rejected the attack but somehow they still managed to cause some damage to the database. Google spiders crossed the damaged files on a scan and thats why they suddenly locked the site out. I have since been in contact with google and they are now happy to revoke the lockout.

I have also informed our host and they are now investigating the problem.

The repair...

I take backups of the site to make sure in a total disaster we can be up and running as soon as possible. Now rather than just loosing 7 days of info I patched in part of the backup to repair damaged sections and then tied them into the main database. I have removed the damaged scripts and removed the hackers scripts.

I have made sure we are running the most up to date modern server modules and software to make sure we hopefully imune to this happening again.

The forum is currently running a debug mode. This is for me to let you guys "test" the forum and let me monitor any faults that may occur. I hope they wont but when you have been staring at pages of PHP code for a good few hours I might have missed something.

I have tested the major things but I cant check every single link on the site so thats where the debugging and you guys come into play. The forum will be slightly slower for a few days while this is running.

Good to have you back as it has been a rather lonely place!!

Rob
 
Last edited:
Dude in all seriousness hats off to you thanks for all the work you have put into this to get us up and running in just over 24 hours!!!!

JJ
 
Well done Rob, Hats off to you as i truely know how difficult it can be to sort this kind of mess out...
Thanks for all your hard work, But i must add, That was the longest 24 hours i have had in the last 8 months...:LOL:
 
Fast work Rob. Well done to you. I expected not to see this place again for a good week or so.

The club owes you a beer or 24 (to replace that case you smashed ;))
 
Yep - that was super quick, was expecting it to be down for days if not weeks. (y)
 
That is beautiful work Rob. I do DR and systems for a living, can't help with PHP or DBs much, but just make sure you keep several weeks worth of backups, especially if it is public knowledge that you do them on a Fri evening (best time to attack would be just before then, and hope it ain't noticed). You now know how to suck eggs Grandma. ;)
 
Well done Rob, Hats off to you as i truely know how difficult it can be to sort this kind of mess out...
Thanks for all your hard work, But i must add, That was the longest 24 hours I have had in the last 8 months...:LOL:

Seconded! Rob, you're a star, getting us back online so quickly sounds like it was no mean feat.
 
Top man Rob - massive respect to you dude (y)

(except forgot the case sensetive sequence in my user name/password so couldn't get back on - stressing like an alcy who couldn't get the cork out of the bottle :LOL:)
:D
 
Well done Rob. Your eye's must be sore from looking at the screen for so long. What a head ache !!! I take me hat off to ya mate. Thanks for getting us back up and running (y)
 
Thank you & well done Rob!!
monk.gif
 
Status
Not open for further replies.