Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Breaking: blog which exposed the Hamdania/Haditha incident is hacked
http://euphoricreality.com/ | 04/16/2008 | RaceBannon

Posted on 04/16/2008 8:38:48 PM PDT by RaceBannon

The site of Freeper EUPHORIADEV was hacked. She has lost over 2 years worth of data.

Euphoriadev was covering the Haditha and Hamdania incident extensively

she has lost over 2 years worth of data

we do NOT believe it is the people who are claiming the hack


TOPICS: Foreign Affairs; News/Current Events; War on Terror
KEYWORDS: enemedia; euphoriadev; hacked; hacker; hackers; hacking; haditha; hamdania; mediawar; stalinisttactics
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-73 next last
To: It Aint Easy

Yeah if this is an SQL injection hack (Which I suspect) any any posts are appearing as deleted.. trust me.. they are in there.

I had a few older PHPNuke sites hit with this till I locked them down and good.


21 posted on 04/16/2008 9:04:40 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 20 | View Replies]

To: woofie

I had nightly backups on two servers. All are gone.

I had offsite backups. They are gone.

They got in all the way to the cpanel and deleted databases under two domains. I am currently working to try and get back into the site enough to fix it.

And no. I don’t think it was Islamics. Here’s a list of the recent hits on my site:

Oceanside California United States
gate23-sandiego.nmci.usmc.mil (138.162.140.53)

Oceanside California United States
gate25-sandiego.nmci.usmc.mil (138.162.140.55)

Halifax Nova Scotia Canada
iusr5.gov.ns.ca

Washington District Of Columbia United States
weppsb02.northropgrumman.com (155.104.37.18)

Washington District Of Columbia United States
70.106.14.174

Dhahran Ash Sharqiyah Saudi Arabia
166.87.170.50

Amman Jordan
86.108.92.154

Colorado Springs Colorado United States
fwcluster.mda.mil (140.32.120.188)

Halethorpe Maryland United States
firewall.arinc.com (144.243.4.2)

Montgomery Alabama United States
proxy.maxwell.af.mil (132.60.240.80)

Springfield Missouri United States
unassigned.fema.gov (71.252.64.50) FEMA.GOV

Gaithersburg Maryland United States
roanoke.ncsl.nist.gov (129.6.101.38) NIST

Gaithersburg Maryland United States
rhine.ncsl.nist.gov (129.6.101.11) NIST

Also entries from guildassociates.com. GO to that site.

Anyone who has ANY of my old material on the Pendleton 8, please email me asap. kit.lange@gmail.com

Thanks so much.


22 posted on 04/16/2008 9:07:37 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 4 | View Replies]

To: It Aint Easy

Agreed - looks like the site data is still there...Seems almost like they changed the header.php and index.php files in the theme (which should be in /wp-content/themes/yourtheme/.


23 posted on 04/16/2008 9:09:52 PM PDT by Chameleon
[ Post Reply | Private Reply | To 20 | View Replies]

To: eXe

Actually, they deleted exactly two years’ worth of posts. Nothing more.

Which is interesting, because two years ago this month is when I started writing about the Pendleton 8.

The user database is gone as well, along with categories, tags, and anything else even remotely containing anything about the Pendleton 8.

And for those saying “didn’t she think of a backup?”...of course I did. This isn’t my first rodeo, ya know. ;) They GOT the backups. I have nightly ones done. They’re all gone, as I mentioned.


24 posted on 04/16/2008 9:13:28 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 21 | View Replies]

To: RaceBannon

Try the Internet Wayback machine.

http://www.archive.org/web/web.php


25 posted on 04/16/2008 9:13:52 PM PDT by Kirkwood (Ask me again tomorrow.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: euphoriadev

I did some digging and see that you are hosted at ThePlanet.. I know for a fact that they do nightly backup of their servers.. so while its going to cost a bit.. any way you can call them and get it restored back to say.. last night? At least the site would be back.

As to the hack.. its a pretty common problem with wordpress.. seems there is a hack that exploits the input validation error in the wp-login.php file when processing a specially crafted variable, can be used to manipulate the “Forgotten Password” option.

Can you still log into the back end of wordpress or did they change your password as well?

I hope you can get the site up and running again.. I cant stand hackers no matter who they are.


26 posted on 04/16/2008 9:14:40 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 22 | View Replies]

To: euphoriadev
Is this what you are looking for? Cached Cached Cached etc...
27 posted on 04/16/2008 9:15:40 PM PDT by It Aint Easy
[ Post Reply | Private Reply | To 22 | View Replies]

To: euphoriadev

Ahh ok so they got offsite backups as well.. Damn.. that stinks.


28 posted on 04/16/2008 9:16:21 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 24 | View Replies]

To: eXe

I was finally able to get into the backend of the cpanel and from there I just altered the user tables to get back in to WP. Now I can look at the extent of the damage...they freaking GUTTED my site. Pieces of @&*^@#. ANYWAY.

It’ll take a few days, but I’m sure I can get the site running again at least.

Can someone please take screenshots of it as is before I start cleaning the mess? I have no capability on this computer of doing that.


29 posted on 04/16/2008 9:16:55 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 26 | View Replies]

To: euphoriadev

Gimme a sec.. Ill take a screenshot of the main page and post it on one of my servers for you to download.


30 posted on 04/16/2008 9:18:51 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 29 | View Replies]

To: mojo114
Registrant:
Domains by Proxy, Inc. DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States

Registered through: GoDaddy.com, Inc.
(http://www.godaddy.com)
Domain Name: EUPHORICREALITY.COM
Created on: 07-Jun-05
Expires on: 07-Jun-09
Last Updated on: 06-Apr-08

Administrative Contact:
Private, Registration EUPHORICREALITY.COM@domainsbyproxy.com
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
(480) 624-2599

Technical Contact:
Private, Registration EUPHORICREALITY.COM@domainsbyproxy.com Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
(480) 624-2599

Domain servers in listed order:
NS183.HOSTGATOR.COM
NS184.HOSTGATOR.COM

----------------------------

EUPHORICREALITY.COM
Hosted at HOSTGATOR WEB HOSTING

31 posted on 04/16/2008 9:20:04 PM PDT by Buddy B (MSgt Retired-USAF)
[ Post Reply | Private Reply | To 15 | View Replies]

To: eXe

I’m online with the hosting company now. They are quite embarrassed. They’re also about to lose a lot of business, as all the sites I admin for are hosted there.


32 posted on 04/16/2008 9:24:04 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 30 | View Replies]

To: euphoriadev
Ok images of the site (I needed to do a few.. heh it was a long page) are located on my west coast hosting box at

http://www.exedor.net/pics/euphoriadev

Is that good enough.. or do ya need more?

33 posted on 04/16/2008 9:28:54 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 32 | View Replies]

To: euphoriadev

Hostgator is pretty good in my experience...Don’t be too hasty....But then, LiquidWeb has been the best I’ve used.

I would be very interested in knowing more about the attack, and the best ways to avoid such attacks.


34 posted on 04/16/2008 9:30:30 PM PDT by Chameleon
[ Post Reply | Private Reply | To 32 | View Replies]

To: euphoriadev

Here is a description of a PHP injection attack with PodPress:

http://www.yugatech.com/blog/the-internet/hack-attack-in-progress/

The script example shows how the exploit tries several possible methods of acquiring the web server’s user ID.


35 posted on 04/16/2008 9:37:25 PM PDT by HAL9000 ("If someone who has access to the press says something over and over again, people believe it"- B.C.)
[ Post Reply | Private Reply | To 32 | View Replies]

To: euphoriadev
Your HTML is on the server but the HTML is changed slightly at top of the page.

Here is one page...take a look...

The Halls’ Rebuttal- Updated

36 posted on 04/16/2008 9:45:00 PM PDT by Buddy B (MSgt Retired-USAF)
[ Post Reply | Private Reply | To 32 | View Replies]

To: euphoriadev; RaceBannon; freema; mdittmar; RedRover; ShadowAce; Database; Incorrigible; ...

Ping for any assistance and cached info ASAP.

A wing and a prayer for our heroes and those defending them.


37 posted on 04/16/2008 10:07:35 PM PDT by The Spirit Of Allegiance (Public Employees: Honor Your Oaths! Defend the Constitution from Enemies--Foreign and Domestic!)
[ Post Reply | Private Reply | To 22 | View Replies]

To: eXe

Perfect. You’re a doll.


38 posted on 04/16/2008 10:07:51 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 33 | View Replies]

To: RaceBannon

BTTT.


39 posted on 04/16/2008 10:28:39 PM PDT by TBP
[ Post Reply | Private Reply | To 1 | View Replies]

To: John Robinson

ping


40 posted on 04/16/2008 11:05:58 PM PDT by The Spirit Of Allegiance (Public Employees: Honor Your Oaths! Defend the Constitution from Enemies--Foreign and Domestic!)
[ Post Reply | Private Reply | To 37 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-73 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson