OK
 
CULTURE : DRIVE : ENVIRONMENT : MEDIA : NEIGHBORHOODS : POWER : L.A.VISION :: [FAQ] .
LAVoice.org
. user.php .
Santiveri
.
  Welcome, !   Mar 15, 2010 - 05:50 AM  
.
   Login to
COMMENT or POST
.




 


 Log in Problems?
 New User? Sign Up!
.
   SEARCH
.
Google
Web lavoice.org

.
   Main Menu
.
.
   Who's Online
.
There are 30 unlogged users and 0 registered users online.

You can log-in or register for a user account here.
.
   LAVoice Archives
.
CULTURE
DRIVE
ENVIRONMENT
MEDIA
NEIGHBORHOODS
POWER
.
   Past Articles
.
Older articles
.
.
 
  POST 1000! ~ Hack Attack Cracked - Let's Party!*
2759 Reads
 
 
UPDATED BELOW

This post - our 1,000th since LAVoice.org launched back in the depths of winter '03 - proves that change is the only constant. Just when you think you have the world figured out, something big knocks it off its fine, jeweled bearings and you're staggering around trying to find your feet.

Post 1000 was supposed to be a rousing cheer for the community that's made LAVoice what it is today. I figured I'd invite all our faithful voices and readers downtown for a booze 'n' munchies party in a couple of weeks to celebrate.

I'll get to that in a minute. But first there's the matter of "spykids ownz you" - the black eye that a passel of vandals just laid on this site and everyone who cares about it ...
MEDIA
As near as I can make out, a malicious Brazilian hacker crew - or more likely, their hackbots - destroyed our homepage and shut us down for close to an entire day after three simple homepage-erasing runs a few days earlier.

Thanks to the patient expertise of Orange County security expert Jim McMurry, we sorted it out in pretty short order. We upgraded the server software, reloaded all the databases and content and lit up the site again late this morning. There's no guarantee we won't get hacked in the future, but the ship's tighter now, and we know the drill.

(Update: Jim mentioned that spykids are probably "script kiddies." Google says they're the sort of petty vandals whom true hackers regard as lower than pond scum since they do nothing to advance the "art" of hacking.)

I'm still running around fussing over little piles of debris - the topic icons like "Media" shouldn't have those nasty hover-borders - (dadgum idiot kids, look at this mess) - but the good news is that not a single one of your posts was lost.

Since the site is based in PostNuke, and "spykids" are notorious for defacing sites worldwide, I thought I'd share what we learned:

As near as Jim can make out, they search for PHP-driven sites that are vulnerable - perhaps by bot. Recent reports have them attacking sites running phpBB, others report they got in via awstats - no matter. They're making it their mission to attack PHP platforms that are asking for it.

In our case, LAVoice was running an older version of PostNuke (I've no one to blame but myself for leaving the site vulnerable by not upgrading regularly). The hackers appear to have found an exploit in the Admin section of the site, and ran a SQL injection, changing every single page in my directory with the name index.html, index.php or index.html to display their graffito.

They then set up a script that intercepts any requests to the database for index pages.

In other words, when you (or I) tried to download the home page at http://lavoice.org/index.php the script redirected the request to one of the graffiti pages. About as elegant as a stiletto in the ribs. I'm grateful it wasn't a baseball bat to the head: They had access to my directories, and could have wiped out everything or done worse.

For anyone else running PHP-based sites - Nuke variants, Moveable Type, WordPress - make sure you've upgraded your server apps and keep on top of the security patches. And backup, backup, backup. It's the only reason there's anything left of LAVoice.org today.

Now then: Where were we?

Oh, yeah - a party! Save the night of Sept. 8 - the Thursday after Labor Day.

I'm working to arrange a venue right now with the help of the gracious Celia, and we'll be sure to augment the cash bar setup with some good L.A. grub.

Why celebrate? LAVoice has pulled together a cool, very engaged and savvy community in its brief lifetime. The contributions of our writers (and now artists in L.A. VISION) and readers who post impassioned, sharp and funny comments have made this an online home for Angelenos who want a say in how Los Angeles evolves.

Some people have posted excellent series' of articles, from Rogan's CrackHouse Diaries to Dave's brilliant Gilded Age/Google Maps mashup.

What I've really enjoyed is that no one's shy with their feelings :

We've heard authentic cries of defiance from the worlds of working-stiff actors and under-appreciated prisoners of cubicle-land.

Posters have declared their exasperation with the new mayor's inaction, their disgust with mansionization, their hopes for free speech.

And with last week's launch of multimedia-blogging via the L.A.VISION topic, artists have started posting views of L.A. that go beyond mere words.

So hell yes, let's celebrate: here's to the next 1,000 posts at LAVoice, and the next 50 of our readers who take the plunge and click SUBMIT NEWS .

-- mack


Send this story to someone  
 
 
Posted by: Mack_Reed on Wednesday, August 17, 2005 - 03:29 PM  
 
POST 1000! ~ Hack Attack Cracked - Let's Party!* | Log-in or register a new user account | Comments
  
Comments are statements made by the person that posted them.
They do not necessarily represent the opinions of the site editor.
.
   Advertisements
.

blog advertising is good for you

.
   Blogs Beyond
.
.
   RSS
.

Add to My Yahoo!
FeedBurner
.
.
. . .



You can syndicate our news by linking to the file backend.php

Feedback on the contents of LAvoice.org
should be submitted by clicking "comments" on the pertinent story.

Terms of Use | Privacy Policy | |

Creative Commons License
All words and images on LAvoice.org
are licensed under a Creative Commons License.
LAVoice.org was created at factoid labs

PUBLISHERS: Ryan Knoll and Scott Olin Schmidt (2007 - ); Mack Reed, 2002-2007

This web site was made with PostNuke, a web portal system written in PHP.
PostNuke is Free Software released under the GNU/GPL license.