PPCGeeks

PPCGeeks (http://forum.ppcgeeks.com/index.php)
-   Site News & Announcements (http://forum.ppcgeeks.com/forumdisplay.php?f=20)
-   -   PPCGeeks.com FTP Vandalized. Everyones help needed! (http://forum.ppcgeeks.com/showthread.php?t=19969)

Wideawake 03-03-2008 12:38 PM

PPCGeeks.com FTP Vandalized. Everyones help needed!
 
It looks like someone decided to take there time and delete our FTP folders for HTC Titan & HTC Vogue sections on the FTP site. I dont know who would do such a thing but we are looking at trying to find out who this person was. We are also looking for ways to stop these childish acts from happening in the future.

If anyone has downloaded files off the ftp from the vogue and titan sections and has them stored locally then please upload what you have so we can attempt to rebuild this back. Thanks for any help.
~Mike

computercarl 03-03-2008 12:39 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Mike, Why cant we force users to create a user name and password, or even automate it to match the one on the forum... and even create a user that can only download for the noobs...

Wideawake 03-03-2008 12:43 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Quote:

Originally Posted by computercarl (Post 200657)
Mike, Why cant we force users to create a user name and password, or even automate it to match the one on the forum... and even create a user that can only download for the noobs...


Im am looking into a system like this Carl, this is the first major problem we have seen since our FTP was released. Hopefully it will be our last.
~Mike

Goddbody 03-03-2008 12:53 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Try looking into a backup method for that file on your serbver Mike, i mean if thats feasable, because I can image with the volume your running here it probably is a huge database.

Wideawake 03-03-2008 01:03 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Quote:

Originally Posted by Goddbody (Post 200674)
Try looking into a backup method for that file on your serbver Mike, i mean if thats feasable, because I can image with the volume your running here it probably is a huge database.

Well the FTP is on a different server than the website and our site is backed up. But ya the ftp now has 6GB used so I can imagine it with the titan and vogue folders. So thats kind of hard to keep backed up.
~mike

Goddbody 03-03-2008 01:11 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Well sounds like a vunerablity which is the case usually with public access to a database. One good thing though, it happened. Now you can take the measures so it doesn't happen again. im going to ask around here at AT&T about security measures for this issue. I'll pm you when I get an answer. Haters are lurking bruh which comes with success. smh

Fresh2Death 03-03-2008 01:19 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
what nerd has the time to do something so corny as this? i cant stand people that do these things. they need to grow up and get a life!

Wideawake 03-03-2008 01:29 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Quote:

Originally Posted by Goddbody (Post 200690)
Well sounds like a vunerablity which is the case usually with public access to a database. One good thing though, it happened. Now you can take the measures so it doesn't happen again. im going to ask around here at AT&T about security measures for this issue. I'll pm you when I get an answer. Haters are lurking bruh which comes with success. smh


No vulnerability at all. The FTP was a public FTP in which anyone could upload, delete, move, and download files. No restrictions on a completely different machine. So no worries....just gotta find a solution to let ppl upload and download but can only delete the files if they uploaded them. Dunno how to do but Im looking. Thanks for the help tho! And we know about them haters. :disgust:
~mike

blue4shizzle 03-03-2008 01:30 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
i think they prolly just dragged the files from the ftp server and onto their own which caused the files to disappear.. maybe we should set up a ftp for dummies and let them know to copy and paste instead of dragging files

Goddbody 03-03-2008 01:35 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Thats true hizzle, maybe exactly what happened.

Pibe38 03-03-2008 01:48 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Who would want ALL the Mogul and Vogue files? I mean, it is a possibility and I hope that's what happened.

However, there really are people out there with nothing better to do.

Wideawake 03-03-2008 01:51 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Yeap who would need all those files? And not take the folder structure......I mean all the folders are still there but someone took there time and deleted all the files only. Odd? I think so...
~mike

mindfrost82 03-03-2008 02:17 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
I'm not sure about allowing them to delete files they uploaded since everyone uses the same account, but you could probably set permissions on the FTP directory (and all subdirectories and files) to disallow deleting and moving. If something needed to be deleted or moved, you could always have the admin account and do it.

InvincibleLiving 03-03-2008 02:25 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
What in the world?! hearing about this makes me feel enraged... i really want to hope somehow it was an accident, but from how it was described it's not likely.

Perasite 03-03-2008 04:30 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
I'd agree with mindfrost. It would be easiest (once it is all uploaded again) to set everything to read only for the public account. Then make an additional account that has full access. The problem then becomes that no one can add to the FTP without going through the admin account. I think the FTP is still on Dreamhost, right Mike? If so, then anonymous FTP is only $3.95/month or $47.40/year. This would allow for an upload only account, that no one can delete from. An admin could move approved stuff into a second folder which is download only. Again, no one could delete stuff. The admin account would be the only on that could make big changes.

dzuchowski 03-03-2008 08:35 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
i think sprint did it or htc did it.... they are aware of this site...

tobeychris 03-04-2008 02:03 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
They didn't actually take the folder structures... everything is gone. If you right click and refresh the ftp they're not there. I think OMJ saw it first as when I saw the FTP his were the only files that had started to be uploaded, I put mine there next, but the all the folders had to be remade, at least on the vogue side.

reeg420 03-04-2008 09:33 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Quote:

Originally Posted by nautica2450 (Post 200803)
What in the world?! hearing about this makes me feel enraged... i really want to hope somehow it was an accident, but from how it was described it's not likely.


I totally agree. Horrible that someone would do something like that...I mean COME ON. WTF


I wish I had some of the files to help.

Pibe38 03-04-2008 09:40 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Just a reminder, remember to be careful when downloading off a public FTP. We received a tip of a fake file and it is being taken care of, so far it seems harmless, it was just a waste of space.

However, if someone deleted everything, they could also upload harmful content.

Just be careful since someone seems to have nothing better to do than to screw with a community that provides so much for each other.

blasphemous_prime 03-04-2008 09:44 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Quote:

Originally Posted by Pibe38 (Post 202920)
Just a reminder, remember to be careful when downloading off a public FTP. We received a tip of a fake file and it is being taken care of, so far it seems harmless, it was just a waste of space.

However, if someone deleted everything, they could also upload harmful content.

Just be careful since someone seems to have nothing better to do than to screw with a community that provides so much for each other.

Word taken and appreciated. good lookin' out and i've seen a post of a thread you shut down earlier, and the original poster on that thread, i had a funny feeling that this was someone trying to come back and scare us.

Wideawake 03-04-2008 10:42 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Quote:

Originally Posted by 6700Yuma (Post 200957)
I'd agree with mindfrost. It would be easiest (once it is all uploaded again) to set everything to read only for the public account. Then make an additional account that has full access. The problem then becomes that no one can add to the FTP without going through the admin account. I think the FTP is still on Dreamhost, right Mike? If so, then anonymous FTP is only $3.95/month or $47.40/year. This would allow for an upload only account, that no one can delete from. An admin could move approved stuff into a second folder which is download only. Again, no one could delete stuff. The admin account would be the only on that could make big changes.


looking into this one 6700yuma, I hadnt forgot about ur suggestion. ;)
~mike

s10onn2o 03-05-2008 01:40 AM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
why do aholes have to mess up somthing good and free at that matter CHILDISH

iceblue 03-05-2008 02:56 AM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
This is nut’s. First I want to know how everyone had permissions? Why did we need 777 permission on the FTP? It would be very simple to login to the server setup with something like cpanel or even set ftp permission in a consol. How in the world did the server not allow this?

I assumed peoples folders were approved by the admins and they received a write permission over there folder. Have the server Logs gave to you from the admin and check what IP and time the files were deleted then trace the ip pool. You can then call the company you find the user hosted from talk to the admin there have the records of the ip used on the delete and time to match his assigned pool addresses to registered user MAC addresses. That will tell you who did it.

Unless he was smart and used another persons user account or public computer and or wifi connection.

iceblue 03-05-2008 03:00 AM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Quote:

Originally Posted by s10onn2o (Post 203222)
why do aholes have to mess up somthing good and free at that matter CHILDISH

I would say this was a free hack that a n00b stumbled upon. Since only the titan folders were delete this more then likely is not the case. I know when I started we would scan pool ranges and see what we could come up with and run attacks and exploits to learn how servers responded differently. Some we get some we didn’t. I remember spending 2 weeks almost messing with a router for an ATM. Allot of times when n00bs try running scans and find something were they get 777 permission they get giddy and dump the server. Instead of monitoring it for a higher level brake. :angry7:

EDGE23 03-09-2008 03:20 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Quote:

Originally Posted by 6700Yuma (Post 200957)
I'd agree with mindfrost. It would be easiest (once it is all uploaded again) to set everything to read only for the public account. Then make an additional account that has full access. The problem then becomes that no one can add to the FTP without going through the admin account. I think the FTP is still on Dreamhost, right Mike? If so, then anonymous FTP is only $3.95/month or $47.40/year. This would allow for an upload only account, that no one can delete from. An admin could move approved stuff into a second folder which is download only. Again, no one could delete stuff. The admin account would be the only on that could make big changes.

if mike is willing to go that route, ill be happy to help $$$. just let me know.

GirlGoneGeek 03-09-2008 03:32 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Wide now has it fixed. Thanks for the suggestions. It's an anonymous FTP server now.

Baffles 03-09-2008 06:22 PM

Re: PPCGeeks.com FTP Vandalized. Everyones help needed!
 
Why not put FTP on the monster server used for this site? Assuming you got the one we were talking about on IRC, you could (and I personally would if it were me) set up VMs, one for the site, one for FTP, etc. Then FTP would still be totally isolated, but you could have complete control over it and use the resources you already have instead of paying someone like dreamhost.


All times are GMT -4. The time now is 04:40 PM.

Powered by vBulletin® ©2000 - 2025, Jelsoft Enterprises Ltd.
©2012 - PPCGeeks.com


Content Relevant URLs by vBSEO 3.6.0