Go Back   EQ2Flames Forum > EQ2Flames Center Stage > Rate-a-Retard

Reply
 
LinkBack Thread Tools
Old 05-13-2008, 01:04 PM  
Visitor
 
Character: Mogaba
Guild: Disciples of Destiny
Server: Najena

Posts: 38
Photos: (0)

Default Re: Everyone using EQDKP

So the person hacking the sites was doing everyone a favor and that makes it okay?

I understand what gm9 and Pinski are saying, but I also understand where Flayedskin is coming from.
Kenji is offline   Reply With Quote
Old 05-13-2008, 01:05 PM  
Show Don't Tell
 

Posts: 9,280
Photos: (0)

Send a message via ICQ to Pinski Send a message via AIM to Pinski Send a message via MSN to Pinski Send a message via Yahoo to Pinski
Default Re: Everyone using EQDKP

Quote:
Originally Posted by Flayedskin View Post
Pinsky, I hear where you are coming from, the aspect I am going with is he put malicious software in the form of 2 different trojans onto the forum sites that would have infected unsuspecting people. An image and changing the site layout...thats funny and I can laugh with that. Posting malicious code is something entirely else.

Yes its relatively easy to restore the information, as you are well aware..but its harder to make sure that he didn't damage any of the guild members that used any of our forums in that time period. I think you can understand and respect that.
Quote:
Originally Posted by kenman View Post
There was nothing malicious, just the ancient JPG that crashed unpatched IEs. And for the record, that IP... isn't mine. Rofl.
So, obviously I think you've got this all wrong then. And for the record, no that IP that ballad's posted isn't Kenman's.

How is it harder to make sure, you know there's logs for a reason right? Or are you too stupid to enable those logs to know what happens on your forums? If you don't have logged enabled, then you should be hacked, imo. If you are too stupid to proper secure and setup logging systems to track things, then I hope you get hacked.
__________________
How many times do you hear it? It goes on all day long
Everyone knows everything And no one's ever wrong
Until later...
Who can you believe? It's hard to play it safe
But apart from a few good friends We don't take anything on faith
Until later..
Pinski is offline   Reply With Quote
Old 05-13-2008, 01:06 PM  
Show Don't Tell
 

Posts: 9,280
Photos: (0)

Send a message via ICQ to Pinski Send a message via AIM to Pinski Send a message via MSN to Pinski Send a message via Yahoo to Pinski
Default Re: Everyone using EQDKP

Quote:
Originally Posted by Kenji View Post
So the person hacking the sites was doing everyone a favor and that makes it okay?

I understand what gm9 and Pinski are saying, but I also understand where Flayedskin is coming from.
No, the person posting the PoC code is the one doing everybody a favor fucking moron. The person hacking the sites is a complete retard, but unless he did serious damage to you, you're a fucking moron for wanting to take him to a court.
__________________
How many times do you hear it? It goes on all day long
Everyone knows everything And no one's ever wrong
Until later...
Who can you believe? It's hard to play it safe
But apart from a few good friends We don't take anything on faith
Until later..
Pinski is offline   Reply With Quote
Old 05-13-2008, 01:09 PM  
There is nothing to beer, but beer itself
 
Vainamoinen's Avatar
 
Server: Najena

Posts: 2,042
Photos: (15)

Default Re: Everyone using EQDKP

CustName: Otelco
Address: 505 3rd Ave East
City: Oneonta
StateProv: AL
PostalCode: 35121
Country: US
RegDate: 2006-06-06
Updated: 2006-06-06

NetRange: 72.242.218.0 - 72.242.219.255
CIDR: 72.242.218.0/23
NetName: ITCD-72-242-218-0
NetHandle: NET-72-242-218-0-1
Parent: NET-72-242-0-0-1
NetType: Reassigned
Comment:
RegDate: 2006-06-06
Updated: 2006-06-06

RTechHandle: ITCDE1-ARIN
RTechName: ITC Deltacom
RTechPhone: +1-800-374-2350
RTechEmail: john.atkins@deltacom.com

OrgAbuseHandle: INAC-ARIN
OrgAbuseName: IP Network ABUSE Center
OrgAbusePhone: +1-800-874-2350
OrgAbuseEmail: mike.ivey@deltacom.com
__________________
I was raised on TV,
Like so many of you I see around me.
Nothing to live or die for;
No religion too.
Vainamoinen is online now   Reply With Quote
Old 05-13-2008, 01:13 PM  
gm9
*
 
gm9's Avatar
 

Posts: 162
Photos: (0)

Default Re: Everyone using EQDKP

Quote:
Originally Posted by Kenji View Post
So the person hacking the sites was doing everyone a favor and that makes it okay?

I understand what gm9 and Pinski are saying, but I also understand where Flayedskin is coming from.
Quote:
Originally Posted by Pinski View Post
No, the person posting the PoC code is the one doing everybody a favor fucking moron. The person hacking the sites is a complete retard, but unless he did serious damage to you, you're a fucking moron for wanting to take him to a court.
What he said.
__________________
Quote:
Originally Posted by Pryz View Post
this site went through a huge decline when it went from a place for endgame players to exchange information and flames into a full on pathetic casual gangbang with e-friends.
gm9 is offline   Reply With Quote
Old 05-13-2008, 01:54 PM  
Visitor
 
Character: Mogaba
Guild: Disciples of Destiny
Server: Najena

Posts: 38
Photos: (0)

Default Re: Everyone using EQDKP

Quote:
Originally Posted by Pinski View Post
No, the person posting the PoC code is the one doing everybody a favor fucking moron. The person hacking the sites is a complete retard, but unless he did serious damage to you, you're a fucking moron for wanting to take him to a court.
So it boils down to a matter of perception. Fair enough.
Kenji is offline   Reply With Quote
Old 05-13-2008, 05:45 PM  
There is nothing to beer, but beer itself
 
Vainamoinen's Avatar
 
Server: Najena

Posts: 2,042
Photos: (15)

Default Re: Everyone using EQDKP

Just cause yer from Arab (Alabama), it doesn't make you a terrorist.

__________________
I was raised on TV,
Like so many of you I see around me.
Nothing to live or die for;
No religion too.
Vainamoinen is online now   Reply With Quote
Old 05-13-2008, 08:29 PM  
Visitor
 
Character: Ambarta
Guild: Nexus
Server: Najena

Posts: 48
Photos: (2)

Default Re: Everyone using EQDKP

Quote:
Originally Posted by Flayedskin View Post

LFG this post should be deleted and Vortfu banned because its a direct violation of your site rules. Nothing good will come of this subject post.
I dunno.. retarded statements like this are pretty good.
You think the hacking only started after Vortfu posted this?
This exploit has been around for a long time. People have been dabbling in other guilds eq2dkp pages for quite a bit of time. If you used the same password for other things.. like guild forums... they have been there too. Same password for your EQ Account maybe? Oh noooes Chinese hackers got into my computer, found my password and sold all my gear!
And you want to ban Vortfu for bringing it to everyones attention?
And delete the thread that is warning them?
Fuckwit.
__________________
http://www.thorongil.net/media/sigs/ambarta.jpg
Ambarta is offline   Reply With Quote
Old 05-13-2008, 08:41 PM  
a walrus
 
Snark's Avatar
 
Character: Snarkw
Guild: The Kraken
Server: Nagafen

Posts: 3,362
Photos: (12)

Send a message via AIM to Snark Send a message via MSN to Snark
Default Re: Everyone using EQDKP

I would have done it but I cant search users by IP's =(
Snark is offline   Reply With Quote
Old 05-13-2008, 08:58 PM  
/meow
 
Character: vortfu
Server: Retired

Posts: 23
Photos: (0)

Default Re: Everyone using EQDKP

Quote:
Originally Posted by Flayedskin View Post
LFG this post should be deleted and Vortfu banned because its a direct violation of your site rules. Nothing good will come of this subject post.
Other than shit and giggles (which is always good)?

Firstly, the OP does not violate the site rules ... my post with the meth recipe and how to build an atomic bomb ... maybe =p

But so far you've been informed about a vulnerability in a piece of software which you use blindly out of the box ... and you've even got a patch for the bug right here in the thread (even though it would be better to just sanitize the $user variable in the SQL query to future proof any other code that calls session->create).

That's good right? (not as good as ninja pics ... but still better than nothing)

The other alternative would be for people to NOT know that there's a vulnerability in their systems and thus have nfi on how to fix it. Ignorance isn't always bliss... unless that chick from last weekend really was a man, then you just dont want to know.

Quote:
I'd like to thank Vortfu for pointing out a security flaw, thus allowing everybody to fix their eqdkp or move on to a still maintained product (at least I'm not sure whether eqdkp is still being developed).
By the looks of things no, EQDKP is not being actively developed. There's an occasional update here and there but it's far from being actively developed / supported... thus getting the original grats on being retarded in the OP.

Everyone else seems to fall into the other two gratsed categories.

vortfu
vortfu is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Sponsor Ads


All times are GMT -4. The time now is 04:59 AM.


Design By: Miner Skinz.com Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0