flyertalk site redirected?
#46
Join Date: Feb 2009
Posts: 959
3.) A system that has been compromised as far as having backdoors installed, should never be considered safe until reinstalled or restored from a known good backup. Evidence that "they never accessed the database" may be false, since the backdoor application could as well have scrubbed the log files to hide its tracks - very common, btw.
And yes, I do system security for a living.
And yes, I do system security for a living.
While we haven't restored the files from backup, hourly snapshots were diff'ed and we have ensured that the system is secure. This was a script kiddie script that exploited a vulnerability right after it was announced and before we had an attempt to patch.
#47


Join Date: Jul 2002
Location: Victoria, BC
Programs: UA 1k, AA Exec Plt 2MM, HH Diamond, *wood Gold, disgruntled Amex Ex-Centurion
Posts: 594
While we haven't restored the files from backup, hourly snapshots were diff'ed and we have ensured that the system is secure. This was a script kiddie script that exploited a vulnerability right after it was announced and before we had an attempt to patch.
I assume that you did additional checks to verify the confidentiality of the password data?
#48
FlyerTalk Evangelist
Join Date: Mar 2008
Location: ACT/GRK/DAL/ABI/MIA/FLL
Programs: OMNIArchist, OMNIArchy!, OMNIIDGAS
Posts: 23,478
MD5 is so secure 
http://milw0rm.com/cracker/insert.php
http://www.hashchecker.com/
sure salt adds a minor bit of complexity, but a little computer 'pepper' and it fades away.
these sites are HARDLY an effective way, just an example.
This is especially true if someone had a level of server access at any point.

http://milw0rm.com/cracker/insert.php
http://www.hashchecker.com/
sure salt adds a minor bit of complexity, but a little computer 'pepper' and it fades away.
these sites are HARDLY an effective way, just an example.
This is especially true if someone had a level of server access at any point.
Last edited by Steph3n; Nov 23, 2009 at 9:08 pm
#49
Join Date: Feb 2009
Posts: 959
If it uses MD5, it must be considered broken. This has nothing to do with vB, it is the algorithm that is at fault.
Good to learn that you verified the system's integrity to be uncompromised (which the check against the backups did). ^
I assume that you did additional checks to verify the confidentiality of the password data?
Good to learn that you verified the system's integrity to be uncompromised (which the check against the backups did). ^
I assume that you did additional checks to verify the confidentiality of the password data?
#50
Join Date: Jul 2007
Location: Sydney, Australia
Programs: VA Gold, UA, SPG Gold, HH Diamond, Marriott Gold, IHG Ambassador
Posts: 3,644
My messages sent to FT HELP have gone unanswered
. I wont even start about how the FT Chat room has been broken for me and others for nearly 2 weeks since the first attack I have a trade thread in CC which I cant access/search to bump. It sure is a BUZZ KILL

Luckily Twitter has been keeping me mildly amused, but how much longer until FT IT gets these issues under control?????
I am in the camp of feeling relieved that I DIDNT subscribe and PAY money for this. Sorry but for me, its just gone on way TOO long.
#51
Join Date: Feb 2009
Posts: 959
We have been working around the clock to combat this ongoing cyber attack. While service has not yet been restored to normal, progress is being made. The site is most dramatically effected by those overseas in Asia, Australia, and NZ.
We once again apologize for the inconvenience.
We once again apologize for the inconvenience.
#52
Join Date: Jul 2007
Location: Sydney, Australia
Programs: VA Gold, UA, SPG Gold, HH Diamond, Marriott Gold, IHG Ambassador
Posts: 3,644
We have been working around the clock to combat this ongoing cyber attack. While service has not yet been restored to normal, progress is being made. The site is most dramatically effected by those overseas in Asia, Australia, and NZ.
We once again apologize for the inconvenience.
We once again apologize for the inconvenience.
What has made Asia, Australia and NZ be more dramatically effected?
P.S I only got redirected twice before being able to post this post
.
#53
Join Date: Feb 2009
Posts: 959
One part of the cyber attack was mostly coming from that area, I believe. I'm not sure though.
#54
Join Date: Jul 2007
Location: Sydney, Australia
Programs: VA Gold, UA, SPG Gold, HH Diamond, Marriott Gold, IHG Ambassador
Posts: 3,644
IB-Dick - thank you for responding.
Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error
.
This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant
.
What is going on?
Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error
. This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant
What is going on?
#55


Join Date: Jul 2002
Location: Victoria, BC
Programs: UA 1k, AA Exec Plt 2MM, HH Diamond, *wood Gold, disgruntled Amex Ex-Centurion
Posts: 594
IB-Dick - thank you for responding.
Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error
.
This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant
.
What is going on?

Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error
. This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant
What is going on?

try to install an alternative browser and see if the problem persists:
www.opera.com
www.firefox.com
Both browsers are "one click" downloads and a second click to install. If these browsers run fine, make sure to do a full malware check of your computer with a good up to date Antivirus product. Kaspersky would be a good choice and runs for free for at least 30 days.
If the problem persists, go to www.sun.com and download the current Java package. Do a re-install.
If the problem still persists, try the following:
www.knoppix.org
At that site, you can download a "Live Linux" DVD image, which needs to be burned to a DVD, of course. Your computer must be able to boot from a DVD. Boot Knoppix, which will take you all the way to a running, graphical desktop with many applications, including Firefox. If this brings back your flyertalk completely, your Windows installation is infected by something. Knoppix includes tools to eradicate Windows malware, but you should only try this with at least mid-level computer knowledge.
The reason I recommend the Live Session DVD/CD approach is that this is the only way to make sure that you boot a clean, infection-free system.
#56
Join Date: Feb 2009
Posts: 959
For starters, eveything that colonius has said is right on. I'd first start off by trying a different browser. That can really help diagnose problems.
FT chat is broken for almost everybody, and we're working on getting that sorted out asap.
If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions:
1.) Got to Start > Run...
2.) Type in "cmd" (no quotes) and hit OK.
3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter.
4.) Copy the output and paste it in here.
There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window.
IB-Dick - thank you for responding.
Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error
.
This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant
.
What is going on?

Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error
. This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant
What is going on?

If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions:
1.) Got to Start > Run...
2.) Type in "cmd" (no quotes) and hit OK.
3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter.
4.) Copy the output and paste it in here.
There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window.
#57
Moderator: Smoking Lounge; FlyerTalk Evangelist



Join Date: Feb 2004
Location: SFO
Programs: Lifetime (for now) Gold MM, HH Gold, Giving Tootsie Pops to UA employees, & a retired hockey goalie
Posts: 29,074
For starters, eveything that colonius has said is right on. I'd first start off by trying a different browser. That can really help diagnose problems.
FT chat is broken for almost everybody, and we're working on getting that sorted out asap.
If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions:
1.) Got to Start > Run...
2.) Type in "cmd" (no quotes) and hit OK.
3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter.
4.) Copy the output and paste it in here.
There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window.
FT chat is broken for almost everybody, and we're working on getting that sorted out asap.
If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions:
1.) Got to Start > Run...
2.) Type in "cmd" (no quotes) and hit OK.
3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter.
4.) Copy the output and paste it in here.
There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window.
#58


Join Date: Jul 2002
Location: Victoria, BC
Programs: UA 1k, AA Exec Plt 2MM, HH Diamond, *wood Gold, disgruntled Amex Ex-Centurion
Posts: 594
#59
FlyerTalk Evangelist




Join Date: Mar 2004
Location: SGF
Programs: AS, AA, UA, AGR S+, Choice Platinum
Posts: 23,317
At the prompt ([yourname]$), type (without quotes) "traceroute www.flyertalk.com" and hit return. It'll look something like this:
Code:
Last login: Sun Dec 6 22:03:04 on ttys000 xx-xx-178-69:~ jackal$ traceroute www.flyertalk.com traceroute to flyertalk.com (67.201.16.68), 64 hops max, 40 byte packets 1 * * * 2 81-188-165-209 (209.165.188.81) 7.023 ms 10.632 ms 5.774 ms 3 32-128-165-209 (209.165.128.32) 8.107 ms 16.984 ms 25.133 ms 4 52-129-165-209 (209.165.129.52) 46.111 ms 37.644 ms 43.164 ms 5 217-129-165-209 (209.165.129.217) 47.766 ms 49.909 ms 38.661 ms 6 ge1-0.cr01.sea01.mzima.net (206.81.80.44) 43.749 ms 43.741 ms 53.306 ms 7 te2-0.cr02.sjc02.us.mzima.net (69.174.120.81) 60.199 ms 53.506 ms 53.296 ms 8 te0-1.cr01.lax02.us.mzima.net (69.174.120.85) 73.087 ms 60.371 ms 68.887 ms 9 xe1-0.cr01.lax01.mzima.net (64.235.224.181) 69.084 ms 67.269 ms 73.567 ms 10 xe0-0.cr01.lax06.us.mzima.net (216.193.255.98) 87.500 ms 73.503 ms 68.107 ms 11 67.201.17.150 (67.201.17.150) 68.489 ms 65.303 ms 60.852 ms 12 flyertalk.com (67.201.16.68) 70.547 ms 61.350 ms 61.976 ms 13 * * * 14 * * * 15 * flyertalk.com (67.201.16.68) 61.114 ms !H 60.864 ms !H xx-xx-178-69:~ jackal$
#60
Moderator: Smoking Lounge; FlyerTalk Evangelist



Join Date: Feb 2004
Location: SFO
Programs: Lifetime (for now) Gold MM, HH Gold, Giving Tootsie Pops to UA employees, & a retired hockey goalie
Posts: 29,074
Applications>Utilities>Terminal
At the prompt ([yourname]$), type (without quotes) "traceroute www.flyertalk.com" and hit return. It'll look something like this:
At the prompt ([yourname]$), type (without quotes) "traceroute www.flyertalk.com" and hit return. It'll look something like this:
Code:
Last login: Sun Dec 6 22:03:04 on ttys000 xx-xx-178-69:~ jackal$ traceroute www.flyertalk.com traceroute to flyertalk.com (67.201.16.68), 64 hops max, 40 byte packets 1 * * * 2 81-188-165-209 (209.165.188.81) 7.023 ms 10.632 ms 5.774 ms 3 32-128-165-209 (209.165.128.32) 8.107 ms 16.984 ms 25.133 ms 4 52-129-165-209 (209.165.129.52) 46.111 ms 37.644 ms 43.164 ms 5 217-129-165-209 (209.165.129.217) 47.766 ms 49.909 ms 38.661 ms 6 ge1-0.cr01.sea01.mzima.net (206.81.80.44) 43.749 ms 43.741 ms 53.306 ms 7 te2-0.cr02.sjc02.us.mzima.net (69.174.120.81) 60.199 ms 53.506 ms 53.296 ms 8 te0-1.cr01.lax02.us.mzima.net (69.174.120.85) 73.087 ms 60.371 ms 68.887 ms 9 xe1-0.cr01.lax01.mzima.net (64.235.224.181) 69.084 ms 67.269 ms 73.567 ms 10 xe0-0.cr01.lax06.us.mzima.net (216.193.255.98) 87.500 ms 73.503 ms 68.107 ms 11 67.201.17.150 (67.201.17.150) 68.489 ms 65.303 ms 60.852 ms 12 flyertalk.com (67.201.16.68) 70.547 ms 61.350 ms 61.976 ms 13 * * * 14 * * * 15 * flyertalk.com (67.201.16.68) 61.114 ms !H 60.864 ms !H xx-xx-178-69:~ jackal$

