Log in

View Full Version : Help me dreambunnies.com is hacked


ßúññ¥€lmérTbtCC
Jan 15, 2003, 12:26 PM
Just now the www.dreambunnies.com website has been hacked by bolt CC, ( RK DDL AA and bomb fusion clanleader )

I dont know how he did it, but ofcource i use the Police and stuff ( wich will not work ) to help me with this, anbd the people of gisol wich are hosting my site

If you just understand how i am feeling at the moment,
My site cost me 100 $ , if you look at www.dreambunnies.com and go to our forums you'l see whats wrong, for now the bunnyelmer account on the forusm are banned :/ is there anything what i can do ?

Isnt hacking a site wich cost 100 $ and much time and work, just because of a game a bit to much ?

KRSplat
Jan 15, 2003, 12:36 PM
Go to the police. They can help you.

(You payed $100? They only cost $70 I thought.)

Was there any deleted content? (Stupid question, but maybe there was nothing there before.) If there wasn't, then I see no problem... oh wait. Except for the fact that you're banned. Ugh.

BlazinDragon
Jan 15, 2003, 01:01 PM
Originally posted by ßúññ¥€lmérTbtCC
Just now the www.dreambunnies.com website has been hacked by bolt CC, ( DK DDL AA and bomb fusion clanleader )

DK? DK didnt hack ur website! Our clanwebsite got hacked 2 times already! Neways, hope it goes back up again.

Blackraptor
Jan 15, 2003, 01:09 PM
Thats the reason i still refuse to make a webpage

KRSplat
Jan 15, 2003, 01:17 PM
Killerrabbit: The forums are what are messed up. There is one post that has the name Bolt DK saying XD SUX SUX... and all of the forum names are messed up and say "XD SUX". All of the other posts have been deleted, and BunnyElmer is banned.

Link
Jan 15, 2003, 01:43 PM
That's what happens if you're not careful with passwords.

But do you have access to the MySQL database? Just go in and either unban yourself or make a different account an admin.

Trafton
Jan 15, 2003, 01:46 PM
It says Bolt RK, not Bolt DK. Also, your one account I can see is not banned- maybe the hacker just deleted them. No one I can find has administrative access.

ßúññ¥€lmérTbtCC
Jan 15, 2003, 09:41 PM
It is RK, not DK, sorry anywayz some frends of me logged on the admin accounts
leroy logged on Nightmare's account i gave him the password because i knew nightmare's password ( he is Sauron and i know him in real-life)
Bobby aka dizzy did an succesfull guess on Crono's password wich is also an admin. My ip WAS banned but the good people who accesed the admin panel unbannen me and banned bolt.

Now i simply restored the whole database with a backup and banned bolt again. The backup is jsut a bit old so thats the problem but its better to start over :D.

Chiyu
Jan 15, 2003, 10:05 PM
Ahem. Don't call him Bolt CC. Lizard/Bullet/Bolt/BlackEnergy is not in CC (anymore).

http://members.lycos.nl/craccoclan/PHPBB2/viewtopic.php?t=395

ßúññ¥€lmérTbtCC
Jan 15, 2003, 10:34 PM
Bolt his ip is : 217.122.38.152
cp283446-a.landg1.lb.home.nl

I made this (stupid) ip adress to be banned. Now i hope the home.nl or the people from gisol are going to send him a nice fee :).

dopeh
Jan 15, 2003, 10:39 PM
As it sounds, your forums have been hacked. That has nothing to do really with your website as they have prolly done it via the forums only. Otherwise you couldn't expect your website still to be up. So lets calm down a bit..
You might want to ask how to act when your forums are hacked here (http://www.phpbb.com/phpBB/viewforum.php?f=1)

Btw, do you have proof against Bolt? You have any log files which tell it was him? If not, there's nothing, but then I mean totally nothing, you can do except banning him from the website.

ßúññ¥€lmérTbtCC
Jan 15, 2003, 10:43 PM
They where hacking in the ftp if i am not mistaking i saw so in the ftp sesion control, ofcource i directly disconected them into my user panel, and changed passwords and stuff.

dopeh
Jan 15, 2003, 10:46 PM
Hacking the FTP makes you not able to access either the database or the forum ACP.

$tilettø
Jan 16, 2003, 12:25 AM
he will prolly get a warning nothing more.
So its Fixed again? Nice. i made a fast script that makes you admin again but thats not needed. nice

Chiyu
Jan 16, 2003, 05:26 AM
I believe that Bolt was friends with XD? After all, you even hired him once to fight for your clan in a clanwar. It could have also been someone pretending to be Bolt, though it could have also been the real Bolt, he's so unpredictable...

MoonBlazE
Jan 16, 2003, 07:10 AM
De kaasschaaf is zwart.

Stijn
Jan 16, 2003, 07:46 AM
Once upon a time there was someone who was angry on velk because she said some off-topic things while the person in question wanted to discuss DDL.

Anyway, Elmer, is it already fixed?

ßúññ¥€lmérTbtCC
Jan 16, 2003, 08:14 AM
Yes it is,

and Cracco Boy ***, are you talking about. For me Bolt has never been a good/accepted frend. He be banned.

HACKERS TO BE BANNED

And he shall be banned FOREVER.

Tik
Jan 16, 2003, 08:59 AM
Originally posted by ßúññ¥€lmérTbtCC
Yes it is,

and Cracco Boy (-), are you talking about. For me Bolt has never been a good/accepted frend. He be banned.

HACKERS TO BE BANNED

And he shall be banned FOREVER. BANNED!
FROM SERVER!

ßúññ¥€lmérTbtCC
Jan 16, 2003, 10:13 AM
Now, they ( RK, DDL, BOM and AA ) are cloning me.

Trafton
Jan 16, 2003, 11:35 AM
Glad to here that it is being restored. I'm sorry to hear that someone found it necessary to hack you. I would recommend changing your password and the passwords of anyone with Moderator Access or Above to avoid any problems like this in the future. If you have not done so, upgrade to the newest version. NEVER TELL ANYONE YOUR PASSWORD. This is the golden rule. Even those who you trust. If you knew Onion's password, that means that others may know it. Change it. Also, ban the IP of anyone involved. Though that won't completely secure everything, it is the best that you can do.

Oh, yes. RK, AA, and DDL have cloned me many times. They clone a lot of people. The clones obviously aren't real. Clones can't really do much damage. They are either so ridiculously obvious that no one believes them or they don't do anything strange so no one cares. Just ignore them, and they will probably stop. :)

Radium
Jan 16, 2003, 02:22 PM
Pie.

Krezack
Jan 16, 2003, 11:18 PM
HAHA. It was actually me who did the hacking. I tdid it all with my 2-bit ICE-pick +7.

Trafton
Jan 29, 2003, 12:18 PM
I hate to revive topics, but you've been hacked again. I noticed this as it happened; Crono did it. He was the only user online, no users were hidden, and he was obviously the one who deleted the forums and replaced them with "XD SUX". He still has administrative access. I would recommend that you cut that off once you fix it.

Chiyu
Jan 30, 2003, 06:03 AM
Everytime when I try to go to the XDMB it says:

phpBB : Critical Error

Could not get theme data for themes_id [3]

Trafton
Jan 30, 2003, 11:31 AM
It changed to that shortly after I posted.

EDIT: You've been hacked again. Whoever did it used Stiletto's account.

ßúññ¥€lmérTbtCC
Jan 30, 2003, 08:49 PM
I restored the forums again :/
i'm now gonna use the help of php and gisol. IF i really can succeed the hackers wil get an fee of 750 $

$tilettø
Jan 30, 2003, 10:18 PM
IF i really can succeed the hackers wil get an fee of 750 $ LOL that will never work unles you have log files and real proofe of who they are,

EDIT: You've been hacked again. Whoever did it used Stiletto's account. They did? i missed it i only logged in yesterday maked BE administrator again and his user active because that was also disabled, and then they banned me i belive it was the user "Craccoboy CC" not sure trough

oh yeah i changed my password into a decimal number incase they guesed that

Chiyu
Jan 31, 2003, 11:47 AM
Yea right, I just posted a message.. I came to the MB around the same time as Crono and DarkSun, the time before it was restored.

ßúññ¥€lmérTbtCC
Jan 31, 2003, 11:48 AM
I am almost 100 % sure this image will be removed, just ignore it anyway.

As the image i had to post before was removed bolt told me that if i would attach this image and it would be removed again that he woudnt brother me with it. So this is the last i do.

http://members.lycos.nl/bunnyelmer/yayfor1olt2.jpg

So there i hope your happy bolt.

ßúññ¥€lmérTbtCC
Feb 1, 2003, 01:05 PM
http://members.lycos.nl/bunnyelmer/mygodtheprofe.jpg

As i just checked the forums, hacked again,
-The BunnyElmer account was non-admin and renamed and passworded changed
-The other high level acces accounts where returned to normal users
-Enigma and Deathmaster where made admin

As i restored the forums evreything was ok again but i didnt know who hacked uss, the e-mail of the admin was changed to kihirlaaa@hotmail.com or something but the hacker sended a mass e-mail ( e-mail to evreyone on the board ) wich was also in my inbox, then i checked the ip ( as u see in the screenshot ) where the e-mail came from, the e-mail was sended with Enigma's admin account so i directly checked Enigma's ip on the restored forums but the ip 212.125.145.246 did not match any of Enigma's. So 212.125.145.246 is the one who hacked the forums.

Enigma
Feb 1, 2003, 01:47 PM
Am i getting involved now? Lovely. I do wonder what i've got to do with this. Hackers, and especially dutchie hackers should leave me out of their lives. Seriously though, the IP is not one of mine indeed. The first numbers don't match any of the dynamic IPs i have. I think i might have a close look at the things that get posted under my account there.

Newspaz
Feb 1, 2003, 02:45 PM
Originally posted by ßúññ¥€lmérTbtCC
*removed image because AA would hack me again if i woudnt*

As i just checked the forums, hacked again,
-The BunnyElmer account was non-admin and renamed and passworded changed
-The other high level acces accounts where returned to normal users
-Enigma and Deathmaster where made admin

As i restored the forums evreything was ok again but i didnt know who hacked uss, the e-mail of the admin was changed to kihirlaaa@hotmail.com or something but the hacker sended a mass e-mail ( e-mail to evreyone on the board ) wich was also in my inbox, then i checked the ip ( as u see in the screenshot ) where the e-mail came from, the e-mail was sended with Enigma's admin account so i directly checked Enigma's ip on the restored forums but the ip (*Removed*) did not match any of Enigma's. So (*removed*) is the one who hacked the forums.

LOL, you're letting them bribe you? Anyway Shadow and I are pretty sure we know who it is. You can send me a message if you'd like me to be more specific.

Trafton
Feb 1, 2003, 02:48 PM
I think that I know too, but I'd rather not guess, since I haven't actually researched very heavily.

<Crono>
Feb 1, 2003, 05:13 PM
I'd suggest, that you change every single password relating to yours or any other admins account, your mySQL password, and your ftp/control panal password. It also might be wise to switch to another Forum software, such as Invisionboard (or vBulliton though I doubt you could afford that) These two are both made by commercial companies and will probabbly have better security. I can convert the phpBB2 database to Iinvision if u do decide to do this.

Trafton
Feb 1, 2003, 05:25 PM
Just out of curiosity, why am I banned?

EDIT: I now see on the DDL site that they think I did this. I can guarantee you that I did not. While it is true that I know DarkSun very well, DarkSun did not actually post that message. DarkSun posted it and someone replaced it with a message sharing the same title, but nothing else. DarkSun uses the same computer as me. This much is true. But I did not hack the web site. Since Crono did not know that it was edited, it is obvious he did not do it. So I offer an apology. It was unacceptable of me to jump to conclusions just because he is in DDL. I'm disappointed in myself for doing so. However, I can guarantee you I did not hack the site, nor do I clone. I do not know Crono well, and he does not know me, but I'm generally a peaceful person. I dislike server crashing and board hacking and I would NEVER do such a thing. It makes sense to blame me, because it was true that I was on a lot when it happened. But with all honesty, I did not do it. I apologize to Crono for making it look like he did it. It was obviously someone using his account. But I can promise you that I am, in truth, not evil at all. I came trying to help out getting the site unhacked, and let my assumptions get the best of me. I know there is no excuse for doing that, but I did not hack the site. I'm sorry for blaming you. It was never my intention to do harm.

<Crono>
Feb 1, 2003, 07:11 PM
I accept your apology Trafton and am sorry that I blamed you. It was wrong of both of us just to blame people like we did.

EvilMike
Feb 1, 2003, 10:07 PM
i did it and i will destroy all of u with my telnet client and linux on thursday

ßúññ¥€lmérTbtCC
Feb 1, 2003, 10:44 PM
Originally posted by Trafton
Just out of curiosity, why am I banned?

EDIT: I now see on the DDL site that they think I did this. I can guarantee you that I did not. While it is true that I know DarkSun very well, DarkSun did not actually post that message. DarkSun posted it and someone replaced it with a message sharing the same title, but nothing else. DarkSun uses the same computer as me. This much is true. But I did not hack the web site. Since Crono did not know that it was edited, it is obvious he did not do it. So I offer an apology. It was unacceptable of me to jump to conclusions just because he is in DDL. I'm disappointed in myself for doing so. However, I can guarantee you I did not hack the site, nor do I clone. I do not know Crono well, and he does not know me, but I'm generally a peaceful person. I dislike server crashing and board hacking and I would NEVER do such a thing. It makes sense to blame me, because it was true that I was on a lot when it happened. But with all honesty, I did not do it. I apologize to Crono for making it look like he did it. It was obviously someone using his account. But I can promise you that I am, in truth, not evil at all. I came trying to help out getting the site unhacked, and let my assumptions get the best of me. I know there is no excuse for doing that, but I did not hack the site. I'm sorry for blaming you. It was never my intention to do harm.

I will let the admin here check your ip with the darksun account on my forum, if it matches i unban you. I thought it was the hacker again, wich does have a 56k modem so the ip of the hacker will always chanche, but i have a lot information about all now.

<Crono>
Feb 2, 2003, 10:07 AM
errr... it has come to my attention that the poster name was Darksun AA, which would mean that even if it was edited, Darksun is affiliated with the group most likly behind the attack...

Trafton
Feb 3, 2003, 11:57 AM
I originally posted as "DarkSun." If you noticed, "DarkSun AA" was listed as a Guest. This was not me. I have different IPs since I have logged in from my dad's work and the library due to my computer being broken. I also never use "lol" on message board messages. The truth is that I find this sickening. I would never hack anyone. The IP originating from my dad's work contains "ramstad." I'm not sure about the library one. To be honest, I'm really not the kind of person who would ever do such a thing, but I can understand your suspicion.

Krezack
Feb 4, 2003, 08:40 PM
Oh god don't you guys get it? For cripes sake, I doubt finding IP numbers will help, you need to FIX the loophole they are using. The only way you can do that is upgrading the forum. I know merely by the sound of this thread which loophole they are using.

I'll tell Trafton. He can help you.

EvilMike
Feb 4, 2003, 10:04 PM
http://home.online.no/~gremmem/engrish_ttt_captions/60-80/two-towers-06.jpg

Newspaz
Feb 5, 2003, 05:34 AM
Originally posted by Krezack
Oh god don't you guys get it? For cripes sake, I doubt finding IP numbers will help, you need to FIX the loophole they are using. The only way you can do that is upgrading the forum. I know merely by the sound of this thread which loophole they are using.

I'll tell Trafton. He can help you.

Actually, they've already switched from PHPBB2 to InvisionBoard. But both were hacked.

<Crono>
Feb 5, 2003, 08:42 PM
Actually, as far as I am aware the new iBF board hasnt been hacked.

Ikrihil AA
Feb 6, 2003, 12:00 AM
Maybe I was involved in the hacking. But maybe I wasn't.

Krezack
Feb 6, 2003, 01:19 AM
Originally posted by Newspaz
Actually, they've already switched from PHPBB2 to InvisionBoard. But both were hacked.

Which version of Iboards? The latest I know of are stable.

Looks like you've got an inside. Threat. Someone who you think is nice. Remove their access.

Bah. What's the URL? I'll try and help.

Newspaz
Feb 6, 2003, 01:37 AM
Originally posted by <Crono>
Actually, as far as I am aware the new iBF board hasnt been hacked.

It was... Well, BunnyElmer's account was. Someone posted pr0n in his signature.
Btw, the url is http://xdforum.dreambunnies.com/

MoonBlazE
Feb 6, 2003, 01:43 AM
It is really amazing how serious people can take a game. A nearly dead one, too.

Tik
Feb 6, 2003, 07:06 AM
Originally posted by Ikrihil AA
Maybe I was involved in the hacking. But maybe I wasn't. <img src="http://www.spiffyjuice.com/pikz/exit5.jpg">

Chiyu
Feb 6, 2003, 10:09 AM
Originally posted by Moonblaze
It is really amazing how serious people can take a game. A nearly dead one, too.

It's not nearly dead.

ßúññ¥€lmérTbtCC
Feb 14, 2003, 01:01 PM
http://members.lycos.nl/bunnyelmer/wegotthehackproofe.jpg

What do you think of this, My account got deleted, but here you see the fantastic proofe of who did that.

Its over, this IS the proofe, the Isp was Home.nl