FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Technical Support and Feedback (https://www.flyertalk.com/forum/technical-support-feedback-386/)
-   -   flyertalk site redirected? (https://www.flyertalk.com/forum/technical-support-feedback/1019581-flyertalk-site-redirected.html)

IB-Dick Nov 23, 2009 7:36 pm


Originally Posted by colonius (Post 12868263)
3.) A system that has been compromised as far as having backdoors installed, should never be considered safe until reinstalled or restored from a known good backup. Evidence that "they never accessed the database" may be false, since the backdoor application could as well have scrubbed the log files to hide its tracks - very common, btw.

And yes, I do system security for a living.

We understand the flaws in md5 hashes, however everyone I've personally discussed this with has verified that the vBulletin hashing method is sufficiently secure.

While we haven't restored the files from backup, hourly snapshots were diff'ed and we have ensured that the system is secure. This was a script kiddie script that exploited a vulnerability right after it was announced and before we had an attempt to patch.

colonius Nov 23, 2009 8:51 pm


Originally Posted by IB-Dick (Post 12870176)
We understand the flaws in md5 hashes, however everyone I've personally discussed this with has verified that the vBulletin hashing method is sufficiently secure.

If it uses MD5, it must be considered broken. This has nothing to do with vB, it is the algorithm that is at fault.


While we haven't restored the files from backup, hourly snapshots were diff'ed and we have ensured that the system is secure. This was a script kiddie script that exploited a vulnerability right after it was announced and before we had an attempt to patch.
Good to learn that you verified the system's integrity to be uncompromised (which the check against the backups did). ^

I assume that you did additional checks to verify the confidentiality of the password data?

Steph3n Nov 23, 2009 8:56 pm

MD5 is so secure :rolleyes:
http://milw0rm.com/cracker/insert.php

http://www.hashchecker.com/

sure salt adds a minor bit of complexity, but a little computer 'pepper' and it fades away.

these sites are HARDLY an effective way, just an example.
This is especially true if someone had a level of server access at any point.

IB-Dick Nov 24, 2009 10:40 am


Originally Posted by colonius (Post 12870550)
If it uses MD5, it must be considered broken. This has nothing to do with vB, it is the algorithm that is at fault.



Good to learn that you verified the system's integrity to be uncompromised (which the check against the backups did). ^

I assume that you did additional checks to verify the confidentiality of the password data?

Of course. As I said before, there is no way that password data was compromised.

Downunder girl Nov 25, 2009 6:10 am


Originally Posted by mshaikun (Post 12867652)
Let me join with others in saying thanks to our hard working IT gurus.

Bigger sites have been hacked including sensitive government sites. The test of IT is how fast they can get things back together. Where we addicts look for instant gratification, you did well guys.

While I would like to say thanks, right now I am at the point of throwing my hands in the air. For SOME unknown reason to me, I am at 50% functionality on FT and have been since the FIRST attack (on 13 Nov I believe). I cant search, I cant PM or reply to PMs, I struggle to quote anyone's threads and doing a simple post on this thread so far has taken me 3 tries and 10 minutes. I keep getting redirected to the Internet Explorer page.....IE cannot display this webpage! So I am feeling much less thankful :td:.

My messages sent to FT HELP have gone unanswered :(. I wont even start about how the FT Chat room has been broken for me and others for nearly 2 weeks since the first attack :td:.

I have a trade thread in CC which I cant access/search to bump. It sure is a BUZZ KILL :(

Luckily Twitter has been keeping me mildly amused, but how much longer until FT IT gets these issues under control?????

I am in the camp of feeling relieved that I DIDNT subscribe and PAY money for this. Sorry but for me, its just gone on way TOO long.

IB-Dick Nov 25, 2009 5:48 pm

We have been working around the clock to combat this ongoing cyber attack. While service has not yet been restored to normal, progress is being made. The site is most dramatically effected by those overseas in Asia, Australia, and NZ.

We once again apologize for the inconvenience.

Downunder girl Nov 26, 2009 12:10 am


Originally Posted by IB-Dick (Post 12881162)
We have been working around the clock to combat this ongoing cyber attack. While service has not yet been restored to normal, progress is being made. The site is most dramatically effected by those overseas in Asia, Australia, and NZ.

We once again apologize for the inconvenience.

Thank you for replying and letting us know of the situation ^.

What has made Asia, Australia and NZ be more dramatically effected?

P.S I only got redirected twice before being able to post this post :D.

IB-Dick Nov 26, 2009 4:32 pm


Originally Posted by Downunder girl (Post 12882455)
Thank you for replying and letting us know of the situation ^.

What has made Asia, Australia and NZ be more dramatically effected?

P.S I only got redirected twice before being able to post this post :D.

One part of the cyber attack was mostly coming from that area, I believe. I'm not sure though.

Downunder girl Dec 6, 2009 6:10 am

IB-Dick - thank you for responding.

Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error :(.

This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant :td:.

What is going on?

:(

colonius Dec 6, 2009 10:16 am


Originally Posted by Downunder girl (Post 12934868)
IB-Dick - thank you for responding.

Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error :(.

This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant :td:.

What is going on?

:(

I guess it is impossible to tell what is happening on your machine, but have you considered a local problem, like a malware infection of your system? Things you might try if you have just a little computer knowledge - or some friend who has:

try to install an alternative browser and see if the problem persists:

www.opera.com
www.firefox.com

Both browsers are "one click" downloads and a second click to install. If these browsers run fine, make sure to do a full malware check of your computer with a good up to date Antivirus product. Kaspersky would be a good choice and runs for free for at least 30 days.

If the problem persists, go to www.sun.com and download the current Java package. Do a re-install.

If the problem still persists, try the following:

www.knoppix.org

At that site, you can download a "Live Linux" DVD image, which needs to be burned to a DVD, of course. Your computer must be able to boot from a DVD. Boot Knoppix, which will take you all the way to a running, graphical desktop with many applications, including Firefox. If this brings back your flyertalk completely, your Windows installation is infected by something. Knoppix includes tools to eradicate Windows malware, but you should only try this with at least mid-level computer knowledge.

The reason I recommend the Live Session DVD/CD approach is that this is the only way to make sure that you boot a clean, infection-free system.

IB-Dick Dec 7, 2009 11:44 am

For starters, eveything that colonius has said is right on. I'd first start off by trying a different browser. That can really help diagnose problems.


Originally Posted by Downunder girl (Post 12934868)
IB-Dick - thank you for responding.

Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error :(.

This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant :td:.

What is going on?

:(

FT chat is broken for almost everybody, and we're working on getting that sorted out asap.

If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions:
1.) Got to Start > Run...
2.) Type in "cmd" (no quotes) and hit OK.
3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter.
4.) Copy the output and paste it in here.

There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window.

goalie Dec 7, 2009 12:36 pm


Originally Posted by IB-Dick (Post 12941685)
For starters, eveything that colonius has said is right on. I'd first start off by trying a different browser. That can really help diagnose problems.



FT chat is broken for almost everybody, and we're working on getting that sorted out asap.

If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions:
1.) Got to Start > Run...
2.) Type in "cmd" (no quotes) and hit OK.
3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter.
4.) Copy the output and paste it in here.

There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window.

how would that equate to those of us using a mac? ;)

colonius Dec 7, 2009 1:07 pm


Originally Posted by goalie (Post 12942043)
how would that equate to those of us using a mac? ;)

Since Mac OS is based on BSD Unix, it will have a traceroute utility somewhere. (Windows is the only OS that names it differently). Since I am not intimate with Mac OS: Google is your friend. ;)

jackal Dec 7, 2009 5:02 pm


Originally Posted by colonius (Post 12942281)
Since Mac OS is based on BSD Unix, it will have a traceroute utility somewhere. (Windows is the only OS that names it differently). Since I am not intimate with Mac OS: Google is your friend. ;)

Applications>Utilities>Terminal

At the prompt ([yourname]$), type (without quotes) "traceroute www.flyertalk.com" and hit return. It'll look something like this:

Code:

Last login: Sun Dec  6 22:03:04 on ttys000
xx-xx-178-69:~ jackal$ traceroute www.flyertalk.com
traceroute to flyertalk.com (67.201.16.68), 64 hops max, 40 byte packets
 1  * * *
 2  81-188-165-209 (209.165.188.81)  7.023 ms  10.632 ms  5.774 ms
 3  32-128-165-209 (209.165.128.32)  8.107 ms  16.984 ms  25.133 ms
 4  52-129-165-209 (209.165.129.52)  46.111 ms  37.644 ms  43.164 ms
 5  217-129-165-209 (209.165.129.217)  47.766 ms  49.909 ms  38.661 ms
 6  ge1-0.cr01.sea01.mzima.net (206.81.80.44)  43.749 ms  43.741 ms  53.306 ms
 7  te2-0.cr02.sjc02.us.mzima.net (69.174.120.81)  60.199 ms  53.506 ms  53.296 ms
 8  te0-1.cr01.lax02.us.mzima.net (69.174.120.85)  73.087 ms  60.371 ms  68.887 ms
 9  xe1-0.cr01.lax01.mzima.net (64.235.224.181)  69.084 ms  67.269 ms  73.567 ms
10  xe0-0.cr01.lax06.us.mzima.net (216.193.255.98)  87.500 ms  73.503 ms  68.107 ms
11  67.201.17.150 (67.201.17.150)  68.489 ms  65.303 ms  60.852 ms
12  flyertalk.com (67.201.16.68)  70.547 ms  61.350 ms  61.976 ms
13  * * *
14  * * *
15  * flyertalk.com (67.201.16.68)  61.114 ms !H  60.864 ms !H
xx-xx-178-69:~ jackal$


goalie Dec 7, 2009 5:22 pm


Originally Posted by jackal (Post 12943828)
Applications>Utilities>Terminal

At the prompt ([yourname]$), type (without quotes) "traceroute www.flyertalk.com" and hit return. It'll look something like this:

Code:

Last login: Sun Dec  6 22:03:04 on ttys000
xx-xx-178-69:~ jackal$ traceroute www.flyertalk.com
traceroute to flyertalk.com (67.201.16.68), 64 hops max, 40 byte packets
 1  * * *
 2  81-188-165-209 (209.165.188.81)  7.023 ms  10.632 ms  5.774 ms
 3  32-128-165-209 (209.165.128.32)  8.107 ms  16.984 ms  25.133 ms
 4  52-129-165-209 (209.165.129.52)  46.111 ms  37.644 ms  43.164 ms
 5  217-129-165-209 (209.165.129.217)  47.766 ms  49.909 ms  38.661 ms
 6  ge1-0.cr01.sea01.mzima.net (206.81.80.44)  43.749 ms  43.741 ms  53.306 ms
 7  te2-0.cr02.sjc02.us.mzima.net (69.174.120.81)  60.199 ms  53.506 ms  53.296 ms
 8  te0-1.cr01.lax02.us.mzima.net (69.174.120.85)  73.087 ms  60.371 ms  68.887 ms
 9  xe1-0.cr01.lax01.mzima.net (64.235.224.181)  69.084 ms  67.269 ms  73.567 ms
10  xe0-0.cr01.lax06.us.mzima.net (216.193.255.98)  87.500 ms  73.503 ms  68.107 ms
11  67.201.17.150 (67.201.17.150)  68.489 ms  65.303 ms  60.852 ms
12  flyertalk.com (67.201.16.68)  70.547 ms  61.350 ms  61.976 ms
13  * * *
14  * * *
15  * flyertalk.com (67.201.16.68)  61.114 ms !H  60.864 ms !H
xx-xx-178-69:~ jackal$


thank you ^


All times are GMT -6. The time now is 4:46 am.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.