General Car Related Discussion. To discuss anything that is related to cars and automotive technology that doesnt naturally fit into another forum catagory.

Fiestaturbo.com

Thread Tools
 
Search this Thread
 
Old 18-08-2004, 10:26 AM
  #1  
Chris 2i
Virgin
Thread Starter
 
Chris 2i's Avatar
 
Join Date: May 2004
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Default Fiestaturbo.com

I didn't realise I was registered on here!

Anyway, Fiestaturbo.com's forums have just been hacked and it looks as though the same board is used here. Just to forewarn you, the guys username was Zerohack...
Old 18-08-2004, 11:06 AM
  #2  
lee3105
Wahay!! I've lost my Virginity!!
 
lee3105's Avatar
 
Join Date: Jun 2004
Location: london
Posts: 58
Likes: 0
Received 0 Likes on 0 Posts
Default

I wondered what was wrong with it this morning i thought it was just my computer. Hope they sort it out and get on-line again. What a dickhead this guy must be .
Old 18-08-2004, 11:12 AM
  #3  
Chris 2i
Virgin
Thread Starter
 
Chris 2i's Avatar
 
Join Date: May 2004
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Default

I just hope the board was backed up recently, by the looks of it he's deleted it...

First there was a post in the main forum, then a new forum called ZEROHACK, then the colour scheme went. After a few 'how childish are you?' posts in there, the whole board went...

He was apparantly using some sort of loophole in version 2 of the phpBB which gives a user admin rights...

If anyone knows anything more please let us know

Thanks.
Old 18-08-2004, 12:15 PM
  #4  
adamS2RST
15K+ Super Poster!!
 
adamS2RST's Avatar
 
Join Date: May 2003
Location: Bucks
Posts: 17,976
Likes: 0
Received 0 Likes on 0 Posts
Default

for Stu and Pet hope Pet has this site well locked down?
Old 18-08-2004, 12:48 PM
  #5  
SassyRS
Little Miss...

 
SassyRS's Avatar
 
Join Date: Apr 2004
Location: up north a little lol
Posts: 21,125
Likes: 0
Received 3 Likes on 3 Posts
Default

Old 18-08-2004, 01:22 PM
  #6  
Spiky
Professional Waffler
iTrader: (1)
 
Spiky's Avatar
 
Join Date: May 2003
Location: Cardiff
Posts: 26,931
Likes: 0
Received 0 Likes on 0 Posts
Default

up for mods
Old 18-08-2004, 01:41 PM
  #7  
Big G
PassionFord Post Whore!!

 
Big G's Avatar
 
Join Date: Jun 2003
Location: Manchestoh
Posts: 8,463
Received 23 Likes on 22 Posts
Default

If a hacker wanted to hack here then they would, its just a game of cat and mouse to them.
There are sites like this for hackers where they have games between themselves to hack sites/forum's, whatever flicks your switch IMO.
Old 18-08-2004, 01:52 PM
  #8  
Chris 2i
Virgin
Thread Starter
 
Chris 2i's Avatar
 
Join Date: May 2004
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Default

I think he was an amateur, he posted a link to where he found the information on the loophole, and the main site itself is untouched.

http://www.fiestaturbo.com/phpBB/index.php

as you can see, he also hasn't left his mark saying he's hacked it.

Probably some teenager who hates Fiesta's and tried to be clever.
Old 18-08-2004, 01:52 PM
  #9  
B19-TRB
Professional Waffler
 
B19-TRB's Avatar
 
Join Date: May 2003
Location: Bristol
Posts: 25,180
Likes: 0
Received 0 Likes on 0 Posts
Default

I have informed stu about this!
Old 18-08-2004, 02:03 PM
  #10  
kartracer69
Virgin
 
kartracer69's Avatar
 
Join Date: Aug 2004
Posts: 9
Likes: 0
Received 0 Likes on 0 Posts
Default

Hi fellas i'm on fiestaturbo.com, just came on here to find out what's going on with it. I was on at the exact time it got hacked and the guy said we had version 2.0.0. this means f.a. to me but it might be of interest to here! our forum has been killed by some twat who posted that 'this IS my life!' (when told, get a fuckin life). Name is zerohack. and the link he set up on FT.com was to download the latest anti-hack stuff, basically a big 'i told you so'! as some guy put (think it was chris2i), its like breaking into your car to show you u need an alarm! take it easy guys, this is a wicked site as well i've never noticed it before
James
Old 18-08-2004, 02:08 PM
  #11  
Jim Galbally
20K+ Super Poster.
 
Jim Galbally's Avatar
 
Join Date: May 2003
Location: Ramsgate, Kent Drives: E39 530D Touring
Posts: 20,599
Likes: 0
Received 0 Likes on 0 Posts
Default

Powered by phpBB 2.0.6 Š 2001, 2002 phpBB Group

PassionFord.com by: Petrucci
Old 18-08-2004, 02:10 PM
  #12  
kartracer69
Virgin
 
kartracer69's Avatar
 
Join Date: Aug 2004
Posts: 9
Likes: 0
Received 0 Likes on 0 Posts
Default

well at least its not the same, if this matters i'm not sure
Old 18-08-2004, 02:12 PM
  #13  
Chris 2i
Virgin
Thread Starter
 
Chris 2i's Avatar
 
Join Date: May 2004
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by kartracer69
Hi fellas i'm on fiestaturbo.com, just came on here to find out what's going on with it. I was on at the exact time it got hacked and the guy said we had version 2.0.0. this means f.a. to me but it might be of interest to here! our forum has been killed by some twat who posted that 'this IS my life!' (when told, get a fuckin life). Name is zerohack. and the link he set up on FT.com was to download the latest anti-hack stuff, basically a big 'i told you so'! as some guy put (think it was chris2i), its like breaking into your car to show you u need an alarm! take it easy guys, this is a wicked site as well i've never noticed it before
James
He said we have version 2.0.0.0.0 or whatever and the admin should upgrade to 2.0.0.0.1 or something to stop it happening again - I'm not quite sure how because two minutes later he deleted the admin accounts...

He was rather childish in his approach and obviously hadn't thought it through properly as he contradicted himself with what I said above, and also he created a forum only to delete the board minutes later.

It just doesn't make sense - some people need to get a life
Old 18-08-2004, 02:14 PM
  #14  
Chris 2i
Virgin
Thread Starter
 
Chris 2i's Avatar
 
Join Date: May 2004
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Jim Galbally
Powered by phpBB 2.0.6 Š 2001, 2002 phpBB Group

PassionFord.com by: Petrucci
looks like you're safe here then. FT was definitely plain old version 2
Old 18-08-2004, 02:14 PM
  #15  
kartracer69
Virgin
 
kartracer69's Avatar
 
Join Date: Aug 2004
Posts: 9
Likes: 0
Received 0 Likes on 0 Posts
Default

childish yes but look what happened! he didn't really create a forum, he did that topic, changed the colours and killed it! but this site is heaving with info etc. But want FT back!
Old 18-08-2004, 02:15 PM
  #16  
Big G
PassionFord Post Whore!!

 
Big G's Avatar
 
Join Date: Jun 2003
Location: Manchestoh
Posts: 8,463
Received 23 Likes on 22 Posts
Default

Just an average day in an average hackers life then
Old 18-08-2004, 02:15 PM
  #17  
Chris 2i
Virgin
Thread Starter
 
Chris 2i's Avatar
 
Join Date: May 2004
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by kartracer69
childish yes but look what happened! he didn't really create a forum, he did that topic, changed the colours and killed it! but this site is heaving with info etc. But want FT back!
he did create a forum. It was called ZEROHACK and was at the bottom of the group with the main forum, Robs memorial forum etc.
Old 18-08-2004, 02:16 PM
  #18  
kartracer69
Virgin
 
kartracer69's Avatar
 
Join Date: Aug 2004
Posts: 9
Likes: 0
Received 0 Likes on 0 Posts
Default

'fraid so. Don't think he took my 'do you ever meet women' post too lightly though...
Old 18-08-2004, 02:17 PM
  #19  
Petrucci
PassionFord Post Whore!!
 
Petrucci's Avatar
 
Join Date: Dec 2002
Location: Toulon, France
Posts: 6,013
Likes: 0
Received 0 Likes on 0 Posts
Default

don't worry, our version is BASED on the 2.0.6 and heavily rewritten, secured, tweaked and protected by myself... be confident, mates
Old 18-08-2004, 02:19 PM
  #20  
kartracer69
Virgin
 
kartracer69's Avatar
 
Join Date: Aug 2004
Posts: 9
Likes: 0
Received 0 Likes on 0 Posts
Default

good to hear dude, should hold up! now i can browse on this cool site
Old 18-08-2004, 02:20 PM
  #21  
Big G
PassionFord Post Whore!!

 
Big G's Avatar
 
Join Date: Jun 2003
Location: Manchestoh
Posts: 8,463
Received 23 Likes on 22 Posts
Default

Originally Posted by Petrucci
don't worry, our version is BASED on the 2.0.6 and heavily rewritten, secured, tweaked and protected by myself... be confident, mates
Is that the arrow pointing to Poobaru board's with the quote "These lot called you a knob Jockey"
Old 18-08-2004, 02:21 PM
  #22  
Chris 2i
Virgin
Thread Starter
 
Chris 2i's Avatar
 
Join Date: May 2004
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by kartracer69
'fraid so. Don't think he took my 'do you ever meet women' post too lightly though...
lol everyone took the piss, Ollie found a spelling mistake in his rant at the top - decided not to answer much though did he?

twat.

Glad to see the board here's safe though
Old 18-08-2004, 02:21 PM
  #23  
Petrucci
PassionFord Post Whore!!
 
Petrucci's Avatar
 
Join Date: Dec 2002
Location: Toulon, France
Posts: 6,013
Likes: 0
Received 0 Likes on 0 Posts
Default

not at all mate, it's just reality, i don't speak about other sites, i speak about mine
Old 18-08-2004, 02:26 PM
  #24  
Project ST
Too many posts.. I need a life!!
 
Project ST's Avatar
 
Join Date: May 2003
Location: Portsmouth
Posts: 863
Likes: 0
Received 0 Likes on 0 Posts
Default

Bit more info on what's happened to FT here.

Exploit was allegedly un-resolved until phpBB v 2.0.10, according to the link helpfully posted by ft's hacker.

Nowt to worry too much about folks

/Munk
Old 18-08-2004, 02:30 PM
  #25  
zvhturbo
PassionFord Post Troll
 
zvhturbo's Avatar
 
Join Date: Apr 2004
Location: Kent
Posts: 2,865
Likes: 0
Received 0 Likes on 0 Posts
Default

2.0.0 tp 2.0.9 That inclused us then!!!
Old 18-08-2004, 02:31 PM
  #26  
Petrucci
PassionFord Post Whore!!
 
Petrucci's Avatar
 
Join Date: Dec 2002
Location: Toulon, France
Posts: 6,013
Likes: 0
Received 0 Likes on 0 Posts
Default

as above, read what I said.
Old 18-08-2004, 02:31 PM
  #27  
Chris 2i
Virgin
Thread Starter
 
Chris 2i's Avatar
 
Join Date: May 2004
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Project ST
Bit more info on what's happened to FT here.

Exploit was allegedly un-resolved until phpBB v 2.0.10, according to the link helpfully posted by ft's hacker.

Nowt to worry too much about folks

/Munk
Has he deleted the board? Thanks for the info mate
Old 18-08-2004, 02:45 PM
  #28  
Project ST
Too many posts.. I need a life!!
 
Project ST's Avatar
 
Join Date: May 2003
Location: Portsmouth
Posts: 863
Likes: 0
Received 0 Likes on 0 Posts
Default

Chris, nope As the article says, it's just the plug that's been pulled.
Old 18-08-2004, 02:49 PM
  #29  
Superal
Wahay!! I've lost my Virginity!!
 
Superal's Avatar
 
Join Date: Sep 2003
Location: North London
Posts: 53
Likes: 0
Received 0 Likes on 0 Posts
Default

Roll on FT3
Old 18-08-2004, 02:52 PM
  #30  
OllieTF
Wahay!! I've lost my Virginity!!
 
OllieTF's Avatar
 
Join Date: Jul 2003
Posts: 88
Likes: 0
Received 0 Likes on 0 Posts
Default

Reports | Privilege Escalation Vulnerability on phpBB 2.0.0
{2nd Aug 2002}


On August 25th 2002 Rootsecure.net discovered a privilege escalation vulnerability in "phpBB 2.0.0" (Powered by phpBB 2.0.0 Š 2001 phpBB Group) which allows any person with a "user" level account to escalate their privileges to that of "administrator" level, and therefore gain full unrestrictive control of a forum.

A coding error exists in the admin_ug_auth.php script (used to set permissions), so although admin rights are needed to view the page, anyone can post data back to it "no questions asked”. Therefore, if you already know what kind of response the board is looking for, you can go straight ahead and tell it directly that you want to give admin rights to a specific account.

Update: Modified/hacked versions of phpBB (e.g. the phpbbnuke port for phpnuke55/56) are also thought to be open to Rootsecure.net's phpBB exploit.

See securityfocus.com for details.

Note: phpBB versions above 2.0.0 are not vulnerable.
Old 18-08-2004, 02:54 PM
  #31  
Chris 2i
Virgin
Thread Starter
 
Chris 2i's Avatar
 
Join Date: May 2004
Posts: 10
Likes: 0
Received 0 Likes on 0 Posts
Default

bloody amateur

cheers to everyone
Old 18-08-2004, 03:13 PM
  #32  
Project ST
Too many posts.. I need a life!!
 
Project ST's Avatar
 
Join Date: May 2003
Location: Portsmouth
Posts: 863
Likes: 0
Received 0 Likes on 0 Posts
Default

Ahhh, Ollie, didn't realise that as I thought someone (perhaps our new best Hacking mate ) advised an upgrade to PHP x.10.

(cor, I'm not wrong again am I? That would be unusual.... not )
Old 18-08-2004, 03:15 PM
  #33  
kartracer69
Virgin
 
kartracer69's Avatar
 
Join Date: Aug 2004
Posts: 9
Likes: 0
Received 0 Likes on 0 Posts
Default

Project, the link he slapped on was to download the upgrade to stop ppl like him doing it, i don't think it was an amateur, it was as if he was advertising the download (you get me?
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
mk3modda
Fiesta RS1800/RS Turbo
12
04-04-2007 11:26 PM
paceo
General Car Related Discussion.
23
19-04-2006 07:47 PM



Quick Reply: Fiestaturbo.com



All times are GMT. The time now is 02:23 AM.