Enzo

Member +
probably not expecting to see anything from me but people need to know.....

yea so that matt bridgette, aka socks made a copy of my site uk starlet club with his croneys, aparently it was for the greater good or some shit as he wasnt happy with how i ran my forum.(im still like what the fuck?!)...i could have sued him with the help of family but 10k for that with a 90% return...just doesnt figure right...

well anyway the bit i want uz all to know..... he infected my forum somehow giving it database errors. i couldnt prove this at all and couldnt remedy it eather....totaly outwith my skill level...to the outside world it looked as if id moved it back to a shared server and got database errors....not the case..
welll..........if he hadnt done this i might have been able to pick up the pieces....im past most of it all now but people need to know the maliciousness that this guy is..hence writing this post

on thursday there i pulled the plug on my dedicated virtual server effectivly killing uksc for good., its costed me 120 ish per month so from october to now is what 500 ish quid i spent on a dead site, fool me i know but i just couldnt bring it to myself to pull the plug after 8 years of hard graft, i plucked up the courage to put a notice to close it with my server provider..


went on that ukso a few weeks back now for the frist time after bucketep91 highlighted me to a thread hed made about what happened, he wanted people to know and was fucked off with the smoke screen socks and co were pushing to justify it... and was sorta sadened by reading peoples reasons for warrenting this and that in regards to stealling the database etc, and winced at all the fanboys badmouthing me for this n that... its weard how forums are full of chinese wispers & brown nosing.... and well everyhthing moves on..so in that respect glad to not be a part of it any more.

the reason im writing this though is to let people know that matt left me with a sabotagged site which i couldnt fix.., the database errors that convieniently apeared 2 days after he ripped a copy of my site for his ukso were his doing and i can prove it with the email bellow....any of you that tried to brouse uksc from october till when i shut it down will know what im on about...it basically rendered my site usuless forcing database errors...this drove all traffic away from my site in quite an effective calculated way

i got this email after notifying my hosting provider to close the dedicated virtual server......plese read it, it shows what a **** that *** ***** was, and how hed planned this as part of shipping everyone over by leaving me with nothing....

***********************************************
| THIS IS A ONE-WAY EMAIL NOTICE ONLY.
| PLEASE USE THE ACCOUNTCENTER TO RESPOND.
***********************************************

It has come to our attention that your 'ukstarletclub.com' (dv) Dedicated-Virtual Server has been compromised and is attacking other servers on the Internet. This degrades your service, as well as others, and is a large consumer of resources overall.

After investigating this activity, it appears that your server has been hacked at the root level. Evidence of this can be found in the following back door "root" users on the server:

user:x:0:0::/home/user:/bin/bash
test:x:0:0::/home/test:/bin/bash
oracle:x:0:0::/home/oracle:/bin/bash
bwadmin:x:0:0::/home/bwadmin:/bin/bash

The following malicious root cron job was also present:
* * * * * /mnt/ /.s/yum-log/update >/dev/null 2>&1

The following malicious files were found:
mnt/ /.s
mnt/ /.s/shtl
mnt/ /.s/contrib
mnt/ /.s/contrib/config
mnt/ /.s/contrib/config/servers
mnt/ /.s/contrib/config/servers/UNDERNET
mnt/ /.s/contrib/config/config
mnt/ /.s/contrib/config/Input.pl
mnt/ /.s/emech.user1
mnt/ /.s/mech.levels
mnt/ /.s/shtd
mnt/ /.s/randfiles
mnt/ /.s/randfiles/randinsult.e
mnt/ /.s/randfiles/randaway.e
mnt/ /.s/randfiles/randversions.e
mnt/ /.s/randfiles/randkicks.e
mnt/ /.s/randfiles/randsay.e
mnt/ /.s/randfiles/randsignoff.e
mnt/ /.s/randfiles/randnicks.e
mnt/ /.s/randfiles/randpickup.e
mnt/ /.s/emech.user
mnt/ /.s/mech.set
mnt/ /.s/shtb


It appears the attacker removed lines from your log files to cover their tracks.

READ THE FOLLOWING INFORMATION VERY CAREFULLY!

Your (dv) Dedicated-Virtual Server is hacked and, at this time, has been stopped. The hacker who gained access to your system has replaced key system files with hacked versions. These copied versions are highly unstable and will most likely allow future back doors into your system; regardless of any security measures you implement from this point forward.


the reason of this post is people need to know that he did this, there needs to be a record of it somewhere that doesnt get deleted so posted this here publicaly. hupefully some of you people reading this will grow to hate this **** for what he did and please....let him know.


this is a public forum and i know there will be loads of different opinions on this but i just want people to know as what happened to uksc was horrably wrong.

not going to say anthing else on the matter now and will go silent again , just content if u the starlet crew have read this and remember the full picture...

iv got a stack of parts to sell so will make a forsale thread at some point when i can bring myself to do that,

if anyone has the skills to help me fix fucked uksc, get it off that dv and onto a new one, please send me and email joecole@sonarfmuk.co.uk,
failing that all records of it get wiped off the server on the 28th

if no one can help il just concentrate on extreem-ep.net and persue my hobby through posting starlet video guides on there

peace out starlet junkies
 
Last edited by a moderator:

Phil

Super Moderator
Sorry to hear this Enzo, ive never been much of a Uksc user, but i feel for you.

im not sure what the Tgtt police can do to help, but no doubt they will do what they can, macker/Dylan or dylans mate bit of a tech guru, might be your best bet to speak to.

really disappointed to here this! i trust we have enough members on here with lengthy experience to insure that noone could ever pull the plug on us?

i do also hope that Socks gets the proper blacklist treatment he deserves now that he has maliciously hacked the site he claimed to love.

Disgusted to hear this.

Phil
 

Kyran

Member +
Iv been a Long time member of both Uksc and Tgtt and and its sad to see UKSC go down like this. iv spoken to geo a number of times about this and its all so fucked up! 8years is a long time! geo had uksc running before socks even had a license! its nice that you finally have proof of what happened bro! and all eyes can now be opened!

What's done is done and we can change the past but that doesn't mean we should forget the past or play ignorant. uksc was rapped and everyone knows it!
 

TrisK

Member +
Im not exactly a unbiased source being a mod over at UKSO.

But, i have been doing server administration for a number of years, as a hobby, and now as a job for 4 years.

Those logs make me think of some sort of backdoor system. That could only be installed with root access.
It is possible that it was done by somebody with root SSH access.

It is also likely that if passwords werent the most secure, either short/dictionary based/used on other sites it could have been done by anyone.

A lot of computers are set up to scan servers, and try all sorts of user/pw combinations til they get in. Once the hacker is in, it then uses your server to add other servers to its 'botnet' of comprimised servers.

In my opinion, and experience (and from having it happen to 1 of my servers in my younger days) i think this could be the case.

Sure your web host has some sort of helpdesk and can provide some assistance?
 

socks

Member +
well anyway the bit i want uz all to know..... he infected my forum somehow giving it database errors. i couldnt prove this at all and couldnt remedy it eather....totaly outwith my skill level...

Incorrect... Didnt alter uksc in any way... I dont know why it has errors...

the reason im writing this though is to let people know that matt left me with a sabotagged site which i couldnt fix.., the database errors that convieniently apeared 2 days after he ripped a copy of my site for his ukso were his doing and i can prove it with the email bellow....

Again, Incorrect. Didnt sabotage a thing...
I think if you get your facts straight it was about a week after you removed my access privileges IIRC...


plese read it, it shows what a **** that *** ***** was, and how hed planned this as part of shipping everyone over by leaving me with nothing....

It shows your server was hacked yes...

Via gaining access to ROOT Access... I never even had ROOT Access to your server... Which you need to edit ROOT Files...

Does that email show it was me? No.
Was it me? No.
 

SupaStu

Member +
You could check what the cron job does/when it ran etc, but really you would be better to wipe off all the data on the disks/volumes and do a full restore from a point in time where the suspect files and cron jobs did not exist. You may lose some data, but at least you would have a fresh start. The support team would be able to advise what restore points are available and when the last backup was that does not contain the dodgy cron job and corrupted files.

You should only have OS folders, and the mounts with the database/app on it. You can check what cron jobs are running and get the support team to confirm they are correct (if any are even needed). Cron jobs are simply scheduled tasks that run certain scripts. I would be hoping you have a long retention on the database data or you may not be able to restore far back in time.
 

Somhairle

Lifer
This thread is relevant to my interests........



The following malicious root cron job was also present:
* * * * * /mnt/ /.s/yum-log/update >/dev/null 2>&1


Says to me its that its a remote kernel patch......
 
Last edited:

Rev

Member +
Good to hear from you Enzo they say it takes as many years to get over a relationship so I guess you will be about for a while maybe 8 more.
The timing of your hack does seem poor but for what it is worth here is a honey pot log from a program designed to catch hackers ( in this case out side the system ).
You will notice the code in the Sixth example is very similar to what your server has experienced.http://blog.macuyiko.com/2011/03/running-ssh-honeypot-with-kippo-lets.html
 

Phil

Super Moderator
I predict bandwagon jumping before all facts are offered. Shoot first, ask later.....

since i assumed the first post proved everything im already on the bandwagon. (wooohooo)

hurry up and and sort this out technical stuff Som so i know whether to get off the "SOCKS is a theiving scheming scumbag" bandwagon, or transfer to firstclass and order up a high horse for the duration for this dispute.

Phil
 

wickedep

Trader
whats done is done mate,sorry to hear about it. dont know all the facts so not going to take sides. but why not start a new forum mate? start afresh...yes, it will be a lot of work...but i am sure there will be many people that will join to use the forum. dont be discouraged...remember its not how many times you fall that count...it how you stand back up!! good luck..

sacha
 

weeJohn

Lifer
I am with Sasha on this one, make a new forum, bigger and better than before. This time you can maybe iron out any bumps you met during the running of the last forum, make it easier for yourself and any staff involved.
 

Tobz91

Member +
Don't let 8 years go to waste think how much money you've invested, use it as some 'healthy' competition and see it as that regardless of any possible sabotage. Forget it improve uksc and without that error I know people will still use the site regardless of ukso it's good to have a number of forums. Revamp it, and heighten your security! I can see both yours an matts side of the story it's very confusing, I can't judge anyone atall.

Hope you make the right decision, uksc was an excellent site prior to the errors.
 

Somhairle

Lifer
In layman's terms yes, a remote patch looks to have been applied with those files, that's the key they are talking about.

Its a remote patch to the root kernel that allows access and is meant to loop an insult if applied correctly, so if its just causing database errors then they haven't even hacked it properly........

This hack has been done before, its not a new attack.

If your anyway Ubuntu inclined, post it up on the Ubuntu forums.

And Phil, i'm working on that other project ;)
 

Phil

Super Moderator
since i assumed the first post proved everything im already on the bandwagon. (wooohooo)

hurry up and and sort this out technical stuff Som so i know whether to get off the "SOCKS is a theiving scheming scumbag" bandwagon, or transfer to firstclass and order up a high horse for the duration for this dispute.

Phil

I see this subject is one where alot of people have strong feelings.. so

FOR CLARIFICATION PURPOSES :)

the above is stupid post by a stupid member (ME)

this post and any others made by me should be read in light of the above statement and should be promptly laughed at or ignorified.

i see this is a serious subject/thread and my posts are attracting fan-mail(angry style) therefore i would like to wish Enzo and everyone or anyone else wronged hurt abused or offended, all the best hope there is a suitable outcome 'in the long grass'.

Phil
 
Last edited:

Somhairle

Lifer
suspiciouscat_zps19e5ecf3.jpg
 
Top