Costello HomePages have been hijacked!
-
- Posts: 475
- Joined: Tue Dec 07, 2004 3:25 pm
- Location: SF
Costello HomePages have been hijacked!
http://www.elviscostello.info/wiki/index.php/Main_Page
http://elviscostello.info/index.php
I feel violated.
(Plus I need a reference source soon...)
http://elviscostello.info/index.php
I feel violated.
(Plus I need a reference source soon...)
-
- Posts: 5992
- Joined: Sat Apr 03, 2004 5:49 am
- Location: Belgium
Now these websites seem to work properly again, but yesterday they were hacked. A 'Columbian' webpage was displayed everytime you tried to reach these website.MOJO wrote:What do you mean by "hijacked" and why have you decided these websites are of lesser value or importance than any other?
Since you put me down, it seems i've been very gloomy. You may laugh but pretty girls look right through me.
- thepopeofpop
- Posts: 414
- Joined: Mon Jul 26, 2004 7:19 am
- Location: Newcastle, Australia (& Citizen of the World)
The site itself - this is only one website, not two - wasn't hacked per se. In fact I was on there yesterday and it was fine. I'm pretty sure I would have been contacted by the webmaster if there'd been a problem with the site as I am one of the founders/admins of the EC Wiki.sweetest punch wrote:Now these websites seem to work properly again, but yesterday they were hacked. A 'Columbian' webpage was displayed everytime you tried to reach these website.
It sounds like somehow your connections to the website were being redirected to a different website. Probably an issue with the ISP you are using.
- And No Coffee Table
- Posts: 3530
- Joined: Thu Aug 21, 2003 2:57 pm
- King Hoarse
- Posts: 1450
- Joined: Thu Apr 22, 2004 11:32 pm
- Location: Malmö, Sweden
- Otis Westinghouse
- Posts: 8856
- Joined: Tue Jun 03, 2003 3:32 pm
- Location: The theatre of dreams
- thepopeofpop
- Posts: 414
- Joined: Mon Jul 26, 2004 7:19 am
- Location: Newcastle, Australia (& Citizen of the World)
OK - I've now been informed by the webmaster that it was hacked. Apparently I'd been accessing it on that day somewhat prior to the dread hacking. As you say just the front page of the "main" site was defaced, but the entire wiki was screwed up. The wiki was restored pretty quickly but only up to August 9 (when it was last backed up). Any updates made since then have been lost forever.And No Coffee Table wrote:I had the same problem yesterday. I doubt Dr. Luther, Sweetest Punch, and I all have the same ISP.
It affected every page of the Wiki site but only the front page of the old site.
I guess that one of the problems of having wikis is that they do create a security "hole" in that all of a sudden you have multiple users with admin privileges. If just one of those account's passwords is hacked then the whole site can be compromised, unfortunately. Also, it could be that the wiki software has some bug in it that allows "backdoor" access...
I run a website myself and I had an old message board that eventually got hacked ("by Turks" so the hackers informed me) but the rest of the site (including a new message board system) was untouched, so go figure.
Unfortunately the world we live in is inhabited by nasty little people with criminal minds and too much time on their hands.
So I apologise for not taking you seriously. The people responsible have now been sacked.
Of course, that last apology really won't do. Therefore, the people responsible for sacking the people responsible for the previous problem have also been sacked.
That previous joke was nicked from Monty Python. Therefore the people responsible for sacking the people responsible for sacking the people responsible for the original problem have also been sacked.
- thepopeofpop
- Posts: 414
- Joined: Mon Jul 26, 2004 7:19 am
- Location: Newcastle, Australia (& Citizen of the World)
The main site is OK, but there are problems with the wiki. The performance of the wiki has definitely suffered since the restore of the wiki data.Otis Westinghouse wrote:Neither link working for me.
Unfortunately we only run this thing in our spare time so we will do our best but can't make any promises as to exactly when it will all be working smoothly. The webmaster has asked the site's service provider for assistance in determining:
1.) Who hacked the site
2.) What we can do to prevent future incidents
-
- Posts: 475
- Joined: Tue Dec 07, 2004 3:25 pm
- Location: SF
-
- Posts: 475
- Joined: Tue Dec 07, 2004 3:25 pm
- Location: SF
- DrSpooky
- Site Admin
- Posts: 823
- Joined: Sun Oct 19, 2003 7:31 pm
- Location: Huntsville, Alabama
- Contact:
I am sorry to hear that it got hacked. You have to be ever vigilant to guard against hacks. This site is currently hosted on a dedicated machine with a dedicated Internet connection and a very tight firewall. There is a script which will ban an IP address if the machine notices too many "bad" entries in the security log. If you remember, this site was broken into about 2 years ago and we got ZERO response from the hosting company. Since it was a shared hosting machine, others could easily have caused a break-in.
The software packages used on these sites have to be constantly monitored for upgrades. I use the same Wiki software on another project and we had to install a Wiki spam filter.
I hope things can be restored soon. There was a LOT of good information in that Wiki.
The software packages used on these sites have to be constantly monitored for upgrades. I use the same Wiki software on another project and we had to install a Wiki spam filter.
I hope things can be restored soon. There was a LOT of good information in that Wiki.
- thepopeofpop
- Posts: 414
- Joined: Mon Jul 26, 2004 7:19 am
- Location: Newcastle, Australia (& Citizen of the World)
Thanks DrSpooky!
The wiki has been restored back to how it was on August 17, but unfortunately it's still inaccessible.
We'll let you know when you get it back up and running - but at the moment it's looking iffy.
That's where we are at, currently. I suspect that the problem has affected some of the other websites they host too.DrSpooky wrote:If you remember, this site was broken into about 2 years ago and we got ZERO response from the hosting company.
The wiki has been restored back to how it was on August 17, but unfortunately it's still inaccessible.
We'll let you know when you get it back up and running - but at the moment it's looking iffy.
- DrSpooky
- Site Admin
- Posts: 823
- Joined: Sun Oct 19, 2003 7:31 pm
- Location: Huntsville, Alabama
- Contact:
This is why this site is self-hosted on a machine I own on an Internet connection we don't share. If something goes wrong, it is MY fault -- not some other user who opened a security hole or some sysadmin bozo who won't respond.thepopeofpop wrote:Thanks DrSpooky!
That's where we are at, currently. I suspect that the problem has affected some of the other websites they host too.
The wiki has been restored back to how it was on August 17, but unfortunately it's still inaccessible.
We'll let you know when you get it back up and running - but at the moment it's looking iffy.
If there is anything I can do, please ask.
John E has paoted to listerv-
Hi all,
There are still quite a lot of problems getting the wiki back up and
running. I won't go into all the details, but I will say that a lot fo
the site from my Web Hosting people have been hacked, and Support Desk
is trying furiously to fix all the problems that everyone is having.
The site is backed up until Thurs 17 Aug, meaning that there were only
about 2 days of updates that have been lost.
At present the wiki is still not working, and I do not have any access
to the account, to upload any files, or even look at what is there.
It is progressing slowly, and I hope that we can have it back up and
working again soon.
Any help solving this and getting the wiki back up and running would
be appreciated.
Cheers, JohnE
Hi all,
There are still quite a lot of problems getting the wiki back up and
running. I won't go into all the details, but I will say that a lot fo
the site from my Web Hosting people have been hacked, and Support Desk
is trying furiously to fix all the problems that everyone is having.
The site is backed up until Thurs 17 Aug, meaning that there were only
about 2 days of updates that have been lost.
At present the wiki is still not working, and I do not have any access
to the account, to upload any files, or even look at what is there.
It is progressing slowly, and I hope that we can have it back up and
working again soon.
Any help solving this and getting the wiki back up and running would
be appreciated.
Cheers, JohnE
- spooky girlfriend
- Site Admin
- Posts: 3007
- Joined: Mon Jun 02, 2003 5:19 pm
- Location: Huntsville, Alabama
- Contact:
- DrSpooky
- Site Admin
- Posts: 823
- Joined: Sun Oct 19, 2003 7:31 pm
- Location: Huntsville, Alabama
- Contact:
I hope that we can find a way to get JohnE's wonderful content back online ASAP.
It is really hard to stay on top of all the security updates and this unfortunately is what happens. If you all recall, this site got nailed about two years ago from some hacking. I try now to install security updates as fast as they are available.
It is really hard to stay on top of all the security updates and this unfortunately is what happens. If you all recall, this site got nailed about two years ago from some hacking. I try now to install security updates as fast as they are available.
- verbal gymnastics
- Posts: 13655
- Joined: Wed Jun 11, 2003 6:44 am
- Location: Magic lantern land
-
- Posts: 326
- Joined: Tue Jun 03, 2003 1:13 pm
- Location: Sweet Sweet Mesquite Texas
EC/Wiki is back, with this message -
http://www.elviscostello.info/wiki/inde ... =Main_Page
Wiki is being maintained and cannot be edited until complete. This may take some time.
Sorry for any inconvenience.
http://www.elviscostello.info/wiki/inde ... =Main_Page
Wiki is being maintained and cannot be edited until complete. This may take some time.
Sorry for any inconvenience.