Post
Topic
Board Legal
Re: Is TradeFortress breaking the law?
by
scotaloo
on 18/07/2013, 15:34:53 UTC
Here is a sneak preview from our upcoming website: minecraft.exe

TF will know what that means. Wink

And check out this hilarious IRC chatlog from #ubuntu-server on IRC:

Quote
TradeFortress   I believe my server has being compromised. Apache access.log and error.log is missing Jan 12th   01:04
=== Malediction_ is now known as Malediction
TradeFortress   How do I see if someone actually logged onto my server? access.log has a lot of disconnects from an IP in china   01:07
=== ejnahc_ is now known as ejnahc
ikonia   TradeFortress: then they have not logged in   01:12
TradeFortress   ok, thanks. is there any reason for missing Jan 12th in Apache logs? other than an attacker removed them?   01:13
patdk-lap   isn't the default only weekly rotates?   01:13
PryMar56   TradeFortress, see if they are parsing for php* (blogs,wordpress,sql) setup config files... they will try to get credentials   01:14
TradeFortress   ahh, I'm not running a custom script, I'm running a self developed one (which was hacked)   01:15
ikonia   TradeFortress: if you have any reason to suspect comrpomise, re-install your whole OS resetting all passwords   01:15
TradeFortress   ikonia: I'll do that, but then I'll get attacked again.. can't see how they did it with the logs.   01:16
ikonia   TradeFortress: no,   01:16
patdk-lap   the longs won't show much   01:16
ikonia   TradeFortress: you seem to know what it was already, your script   01:16
patdk-lap   and it might show 1 issue, but not all issues you have   01:16
patdk-lap   expecially if they used POST requests   01:17
TradeFortress   okay, but the attacker somehow got root access..   01:17
ikonia   TradeFortress: delete your OS - re-install   01:18
ikonia   TradeFortress: that is the answer   01:18
patdk-lap   if they got root access you have many levels of issues to correct   01:18
patdk-lap   and the logs won't show that   01:18
TradeFortress   thanks everyone, I'm going to reinstall & look for a pentester

Even phunnier, here is his reply:

Try hacking inputs.io or coinlenders actually.

Oh wait Cheesy

FYI, that's not actually for any of my projects, but I'll let you think whatever you want.

The community trusts this anonymous person (who isn't so anonymous after all! Wink) with approximately $2million in BTC. Dafuq is going on here?