GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Fucking Hacked Server!!!!!!!!! (https://gfy.com/showthread.php?t=342366)

SplitInfinity 08-19-2004 10:15 PM

Hey, I just thought about something,
if you still have your web servers logs, I bet
your hackers IP is in the web logs.....

He will have been the VERY FIRST person to see the IFRAMES....
They always test their work just after they implemeted the html
modifications...... They normally will be one of the very first hits
in your web logs just after the mods were done so thats a good
way to age the hack and know what time it occurred.....

Keep in mind the last octets of his ip may change because his ISP told me
they only have that one class C for their broadband customers...

:-)

SplitInfinity 08-19-2004 10:21 PM

Just emailed him again:

SUBJECT: Yahoo space utilization

he will click on it, say Fuck that spammer and delete it....
meanwhile I log him again.

I have logged him from the same class C 3 times now during the hours of 1am to 3 am PST so that is his hours of operation and that time fits daytime in his countrys time zone. :-)

So were creating a dossier on this guy.
:-)

SplitInfinity 08-19-2004 10:23 PM

Looks like some of you guys tried my honeypot link:

Notice the gfy referral links. :-0

62.42.228.6 www.splitinfinity.com - [19/Aug/2004:16:32:47 -0700] "GET /themainman HTTP/1.1" 302 302 "http://www.gofuckyourself.com/showthread.php?s=&threadid=342366&perpage=50&pagen umber=2" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
68.83.122.119 www.splitinfinity.com - [19/Aug/2004:17:35:57 -0700] "GET /themainman HTTP/1.1" 302 302 "http://www.gfyboard.com/showthread.php?s=&threadid=342366&perpage=50&pagen umber=2" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040707 Firefox/0.9.2"
164.107.220.226 www.splitinfinity.com - [19/Aug/2004:17:58:51 -0700] "GET /themainman HTTP/1.1" 302 302 "http://www.gofuckyourself.com/showthread.php?s=&threadid=342366&perpage=50&pagen umber=2" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)"

exposed 08-19-2004 10:23 PM

Quote:

Originally posted by KC
If the box was comprimised, then start over with a clean install on a new box. Don't think you can "plug" the hole and everything will be secure again.

Once it's been compromised it's damaged goods.

pfttt....not true

exposed 08-19-2004 10:26 PM

Quote:

Originally posted by SplitInfinity
Amazing how many adult sites are engagine in bad adware:

http://www.webhelper4u.com/CWS/cwsbyalphanumeric.html

I just got an ICQ from a stranger telling me that if I push any
further they will come kill me. They are hackers paid by adult
industry to hack sites and put that on them, fucked up shit.

Fuck them, I will keep pushing and find out who they are
and expose them for hacking into sites illegaly. Put aside
the adware part, they are still breaking and entering.

I'm coming to get ya!


lmfao

exposed 08-19-2004 10:31 PM

Quote:

Originally posted by SplitInfinity
I have caught your hacker!

Here is the lowdown.....

To find the hacker you must first find out who owns those domains.....
And the only way to see who owns those domains (because the info is fake)
is to find out WHO is receiving the emails for the domain's contact email account,
which for all those domains, is the same person.

This person uses a yahoo email address, and getting the info on who owns
an email account from yahoo would be very difficult, especially considering
they most likely filled in fake info there as well. So why not get their IP from yahoo you ask? Because yahoo won't help you without a subpeona.....
Even friends I have at yahoo can't help me because they do not allow access
to logs except to their legal dept. which is a pain to deal with as well.....

So, I ask myself, If this person is using a yahoo web based email account to check his mail, and we need his IP address to identify him, let's get the IP already!

I decided to email an artifical spam mail to him. The secret here is that
he is the ONLY one getting this spam mail. I used a rather catchy subject
that he COULD NOT RESIST:

"Hacker Caught?"

When he looked at the email, it was nothing special. I made it look like an
ad to an online casino. He would take a peek at it, then most likely just delete it
thinking to himself, "fucking spammer!", while his heart pumped heavily thinking
perhaps he had been caught.

What he DID NOT KNOW that happened behind the scenes is that in the spam
mail, the only image that was loaded in the email was an invisible 1x1 pixel.
All other items in the mail were HTML.

This 1x1 hidden pixel was loaded off of MY server using an image name that NO ONE would know. In fact, the image doesn't even exist and since I set the
height and width of the image to 1, he would not see a broken image in there
anyways..... this would simply generate a couple log entries on my server
letting me know HIS HOME COMPUTERS IP ADDRESS because in order to use
yahoo mail, you have to use a web browser, and he certainly did!!!

Because the image does not exist on my server, but his browser tried to load it,
his accessing his yahoo mail led to 2 entries in my server logs. One is the access_log entry, and the other, when the image could not be found, was the error_log entry.

The URL to the non-existant image is: http://www.splitinfinity.com/themainman

access_log entry:
195.131.125.119 www.splitinfinity.com - [19/Aug/2004:01:01:46 -0700] "GET /themainman HTTP/1.1" 302 302 "http://us.f403.mail.yahoo.com/ym/ShowLetter?MsgId=1922_1014156_59656_1208_1013_0_84 6_4944_1839376362&Idx=0&YY=48958&inc=25&order=down &sort=date&pos=0&view=&head=&box=Inbox" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040707 Firefox/0.9.2"

error_log entry:
[Thu Aug 19 01:01:46 2004] [error] [client 195.131.125.119] File does not exist: /home/split/splitinfinity.com/public_html/themainman, referer: http://us.f403.mail.yahoo.com/ym/Sho...ead=&box=Inbox


******** His IP address is: 195.131.125.119 **********

This is most likely a dynamic IP, but, since we know the time and date of the
access, we can call the IP owner (his ISP as listed below) and perhaps get
that information. I will continue to send him some of these emails and
log all the ip ranges he comes from, which im sure at this point will all be
the same isp since it is a broadband connection on his end.

w00000h00000!

betcha he didn't see that coming.


hahaha nice!

owned.

SplitInfinity 08-20-2004 11:17 AM

Hahahah,

Had to change my honeypot link in the emails I sent him because
I got 124 GFY'ers trying to load it up to see what it does.... lol!
That will interfere with my forensics. :-) So I changed it from here on out.

You guys dont wanna be mistaked for Joe hacker do you?

HEY, there cold be a nice reality show, Joe Hacker.

:-)

FrankWhite 08-20-2004 11:55 AM

Quote:

Originally posted by SplitInfinity
Hahahah,

Had to change my honeypot link in the emails I sent him because
I got 124 GFY'ers trying to load it up to see what it does.... lol!
That will interfere with my forensics. :-) So I changed it from here on out.

You guys dont wanna be mistaked for Joe hacker do you?

HEY, there cold be a nice reality show, Joe Hacker.

:-)


whats your icq ? i need to get in touch with you.

spacemonk 08-20-2004 12:11 PM

SplitInfinity :thumbsup :thumbsup

SplitInfinity 08-20-2004 02:39 PM

64791506

:-)

SplitInfinity 08-20-2004 02:40 PM

Thanks for the :thumbsup

SplitInfinity 08-20-2004 04:34 PM

We sold several accounts yesterday with the offer we posted, it appears that people liked it a lot. We have decided to offer it again today.

Today we have 3 more 10Mb/s Unmetered Dedicated Server packages available.

- P4 2.4ghz
- 1GB RAM
- 80GB IDE
- 10Mb/s Unmetered Bandwidth (10Mb/s port)
- Linux/FreeBSD
- Cpanel available at extra cost if desired.
- $500.00 per month
- FREE SETUP

Use coupon ' chrislovesme ' for 75% off of your order.

--> Click Here to order Instantly <--

We can have you online today. Contact me if you have any questions.

skoalman 08-20-2004 04:54 PM

You can have so much more fun with that guy, you know he's just begging to come at you now.

SplitInfinity 08-20-2004 05:38 PM

hahahah! The guy ICQ'd me!

I sent him an email saying:

SUBJECT: hey dude, ICQ ME.

Wanted to know if I can hire you to do network security for me.
I was referred to you by some porn people.


he replied and is sending me a resume. hahahah!
The fuker lives in seattle! He is in Russia for the summer to visit
some relatives and study there.
hahaha

I cant wait to get all his info. I will scan the shit when I get the fax.
Note: He is FAXING it to me.... Let's hope the part of russia where he
is has caller ID.
:-)

JayJay 08-20-2004 05:54 PM

Quote:

Originally posted by SplitInfinity
hahahah! The guy ICQ'd me!

I sent him an email saying:

SUBJECT: hey dude, ICQ ME.

Wanted to know if I can hire you to do network security for me.
I was referred to you by some porn people.


he replied and is sending me a resume. hahahah!
The fuker lives in seattle! He is in Russia for the summer to visit
some relatives and study there.
hahaha

I cant wait to get all his info. I will scan the shit when I get the fax.
Note: He is FAXING it to me.... Let's hope the part of russia where he
is has caller ID.
:-)

BUMP!
You Rock

sixxxthsense 08-20-2004 05:59 PM

Quote:

Originally posted by SplitInfinity
hahahah! The guy ICQ'd me!

I sent him an email saying:

SUBJECT: hey dude, ICQ ME.

Wanted to know if I can hire you to do network security for me.
I was referred to you by some porn people.


he replied and is sending me a resume. hahahah!
The fuker lives in seattle! He is in Russia for the summer to visit
some relatives and study there.
hahaha

I cant wait to get all his info. I will scan the shit when I get the fax.
Note: He is FAXING it to me.... Let's hope the part of russia where he
is has caller ID.
:-)

u've taken this to the extreme! what do u plan to do to this fuck? :Graucho

gwilkins 08-20-2004 06:01 PM

Quote:

Originally posted by SplitInfinity
hahahah! The guy ICQ'd me!

I sent him an email saying:

SUBJECT: hey dude, ICQ ME.

Wanted to know if I can hire you to do network security for me.
I was referred to you by some porn people.


he replied and is sending me a resume. hahahah!
The fuker lives in seattle! He is in Russia for the summer to visit
some relatives and study there.
hahaha

I cant wait to get all his info. I will scan the shit when I get the fax.
Note: He is FAXING it to me.... Let's hope the part of russia where he
is has caller ID.
:-)

Wow, with the death threat and all the money he's stolen you could put him in jail for a very long time. I'm sure the FBI would love to hear from you. They could just pick him up at the airport in Seattle :)

KC 08-20-2004 06:23 PM

Quote:

Originally posted by exposed
pfttt....not true
pfft... yes.. true.

How can you be certain you have plugged every hole of a rooted box?

SplitInfinity 08-20-2004 10:20 PM

You can be reasonable certain if you know what you are doing and take steps in advance of ever being hacked to prevent major corruption, like kernel level ACL's and so forth, however you cannot ever be truly certain until you first know HOW he got in and WHAT they ran to rootkit your system.

For example, if you find their rootkit, the you can be pretty sure... but
NEVER 100%. I would never say 100% because were human and we miss
obvious things. Hackers use the psychological understanding they know of us
to abuse us and re-enter our systems....

Lots of hackers imbed backdoors in our own php scripts... so even a program
YOU WROTE might have been modified by the hacker without you knowing
to email him your password file so he can run crack on it or even to execute other files he hid on the server at his request by loading a url he hid on your box....
Run on sentences tonight.

:-)

cosis 08-20-2004 10:53 PM

i guess we know he doesnt read gfy

SplitInfinity 08-20-2004 11:12 PM

:anon <- lets hope that aint him. hahaha

Firehorse 08-21-2004 06:57 PM

Nice work SplitInfinity. Time to kick some ass! :BangBang:

darnit 08-21-2004 07:26 PM

I understood exactly 0% of that but very impressive! Awsome work :thumbsup

Dirty F 08-22-2004 04:59 AM

Got the fax yet?

Dirty F 08-22-2004 05:00 AM

OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: Singel 258
Address: 1016 AB
City: Amsterdam
StateProv:
PostalCode:
Country: NL

Btw, whats up with these guys? They live 5 mins from my place.

Radik 08-22-2004 05:10 AM

Kernel trojans are the shit. none of this crappy replacing binaries crap.

sinnerscorner 08-22-2004 06:35 AM

Quote:

Originally posted by Battuss
OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: Singel 258
Address: 1016 AB
City: Amsterdam
StateProv:
PostalCode:
Country: NL

Btw, whats up with these guys? They live 5 mins from my place.

It is the Dutch Division of RIPE an organization which
hands out IP space to ISP'S.

SplitInfinity 08-23-2004 11:29 PM

His fax isnt working, he keeps trying to fax me to no avail.... long distance dirty phone lines are noisy.... error says too much line noise.

He will try from his work. LOL!

SplitInfinity 08-25-2004 11:08 PM

Got his FAX!!! What a moron.

I gotta scannerize this shit!


hahahaha

Moose 08-25-2004 11:13 PM

Chris that was my fax

It didn't come out?

damn

sorry

SplitInfinity 08-26-2004 12:16 AM

hahahah

Moose, that hacker actually faxed me a resume. He even put his parents phone numbers and addresses down as references.

cspdinc 08-26-2004 01:24 AM

this is the best shit I have ever read here... I know who to call in the near future for help now.

SplitInfinity 08-26-2004 01:29 AM

Anyone got a flat bed scanner?

Ahhh I will fax it to efax and screen shot it.
That should work coz my scanner aint.

lol

Agent White 08-26-2004 01:54 AM

I found AdultMovieSearcher's partner application page and sweet-hot-sex.com/s main TGP page both attempting to run the CHM exploit last week.


Are either of these yours, makingcoin? I posted the news on thinkreel, so you may want to reply there if so.

JayJay 08-26-2004 05:25 AM

Quote:

Originally posted by SplitInfinity
Anyone got a flat bed scanner?

Ahhh I will fax it to efax and screen shot it.
That should work coz my scanner aint.

lol

LMAO we need to see this shit :1orglaugh

SplitInfinity 09-01-2004 09:36 AM

Should I hire him? LMAO!

SmokeyTheBear 01-02-2005 01:06 AM

pics ?? or did you hire him ?

Platinumpimp 01-02-2005 01:29 AM

Quote:

Originally Posted by SplitInfinity
Here is another domain he owns/owned:

Domain Name: B00GLE.COM

Registrant:
n/a
Janet Jacjson ([email protected])
Hali-gali, 77
Deli
null,12345
IN
Tel. +91.226370256

Creation Date: 31-Mar-2004
Expiration Date: 31-Mar-2005

Domain servers in listed order:
ns1.smartdns.org
ns2.smartdns.org
ns1.smartnic.org
ns2.smartnic.org


Administrative Contact:
n/a
Janet Jacjson ([email protected])
Hali-gali, 77
Deli
null,12345
IN
Tel. +91.226370256

Technical Contact:
n/a
Janet Jacjson ([email protected])
Hali-gali, 77
Deli
null,12345
IN
Tel. +91.226370256

Billing Contact:
n/a
Janet Jacjson ([email protected])
Hali-gali, 77
Deli
null,12345
IN
Tel. +91.226370256

Status:SUSPENDED
Note: This Domain Name is Suspended. In this status the domain name is
InActive and will not function.

Janet Jacjson...LOL fake info all the way. When's she going to flash her titty again :disgust :1orglaugh

- Jesus Christ - 01-02-2005 01:31 AM

Only a moron views e-mail in anything other than plain text format.


(in yahoo mail check the "Security: Block HTML graphics in email messages from being downloaded" box)


This guy is a putz...

chupacabra 01-02-2005 01:32 AM

nice work SI... crontab his punk ass.

oh, and btw, nice buildup towards reaching your 666th post..! http://twash.com/iku/leperkiss.gif


All times are GMT -7. The time now is 12:29 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123