Home  |  Forums  |  914 Info  |  Blogs
 
914World.com - The fastest growing online 914 community!
 
Porsche, and the Porsche crest are registered trademarks of Dr. Ing. h.c. F. Porsche AG. This site is not affiliated with Porsche in any way.
Its only purpose is to provide an online forum for car enthusiasts. All other trademarks are property of their respective owners.
 

Welcome Guest ( Log In | Register )

3 Pages V < 1 2 3  
Reply to this topicStart new topic
> Somebody Redecorated our place
SirAndy
post Apr 14 2006, 10:56 AM
Post #41


Resident German
*************************

Group: Admin
Posts: 41,662
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



time for a little (IMG:style_emoticons/default/icon_bump.gif) to keep this floating on top (like a turd in a pool) ...

and yes, i'm feeling better now, thanks for asking!
(IMG:style_emoticons/default/chowtime.gif) Andy
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
r_towle
post Apr 14 2006, 11:00 AM
Post #42


Custom Member
***************

Group: Members
Posts: 24,584
Joined: 9-January 03
From: Taxachusetts
Member No.: 124
Region Association: North East States



A true operations guy...you are a glutton for punishment.

Keep up the good work..again I will help if you get pissed.

I found afew good, free firewalls for linux..
If you are on linux, let me know..they have good ratings.

Also, I could help with your router config...if that is allowed..

rich
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Apr 14 2006, 11:05 AM
Post #43


Resident German
*************************

Group: Admin
Posts: 41,662
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(r_towle @ Apr 14 2006, 10:00 AM) *

A true operations guy...you are a glutton for punishment.

Keep up the good work..again I will help if you get pissed.

I found afew good, free firewalls for linux..
If you are on linux, let me know..they have good ratings.

Also, I could help with your router config...if that is allowed..

rich



thank you sir!

right now, i'm pondering options and a hardware solution like one of the "cheaper" (note, i didn't say "cheap", i said "cheaper") Netscreen Firewalls is looking pretty good to me ...
(IMG:style_emoticons/default/type.gif) Andy
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
fiid
post Apr 14 2006, 11:14 AM
Post #44


Turbo Megasquirted Subaru Member
****

Group: Members
Posts: 2,827
Joined: 7-April 03
From: San Francisco, CA
Member No.: 530
Region Association: Northern California



QUOTE(SirAndy @ Apr 14 2006, 10:05 AM) *


thank you sir!

right now, i'm pondering options and a hardware solution like one of the "cheaper" (note, i didn't say "cheap", i said "cheaper") Netscreen Firewalls is looking pretty good to me ...
(IMG:style_emoticons/default/type.gif) Andy


We have some relationships with some firewall/ips companies - we might be able to score something for you. I have a really nice device on my home network. I'd really like to get more info on what happened - perhaps you could should me an email or IM?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Apr 14 2006, 12:55 PM
Post #45


Resident German
*************************

Group: Admin
Posts: 41,662
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(fiid @ Apr 14 2006, 10:14 AM) *

We have some relationships with some firewall/ips companies - we might be able to score something for you. I have a really nice device on my home network. I'd really like to get more info on what happened - perhaps you could should me an email or IM?


(IMG:style_emoticons/default/smilie_pokal.gif) that would be cool ...


simple:

hacker guy exploits bug in old BBS software and installs custom PHP script and runs it to get domain user acocunt info and other stuff off the machine. luckily, he didn't get any passwords.
he then adds some virus/backdoor/trojan code to the main BBS index page to attack members machines.
he then proceeds to run a "brute force" attack on the FTP and NetBios Ports, trying to crack the password and hack his way into the machine with domain admin access.

that's where we catched him and closed the door on him. that's why you see blue instead of green.
we updated the BBS software to the latest version and we upgraded PHP and mySQL as well.
the system *should* be safe now, just not green anymore.
but jeroen is working on that ...

(IMG:style_emoticons/default/givemebeer.gif) Andy
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Verruckt
post Apr 14 2006, 01:20 PM
Post #46


Senior Member
***

Group: Members
Posts: 716
Joined: 14-July 04
From: Midwest
Member No.: 2,348



QUOTE(SirAndy @ Apr 14 2006, 12:05 PM) *



right now, i'm pondering options and a hardware solution like one of the "cheaper" (note, i didn't say "cheap", i said "cheaper") Netscreen Firewalls is looking pretty good to me ...
(IMG:style_emoticons/default/type.gif) Andy


Netscreen ain't all that Andy... (IMG:style_emoticons/default/dry.gif)

Because I have WAAAAY too much shit in my basement as it is... If you want, I'll donate a Nokia IP440 firewall to the cause. Consider it my "membership fee". It was decomissioned at my work, but our bandwidth requirements are are alot more than here, so it should be MORE than adequate. Anywho, if you don't mind paying for shipping, it's yours. And I also have the latest os for it. Let me know.

Howz that for "cheaper" ?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Verruckt
post Apr 14 2006, 01:28 PM
Post #47


Senior Member
***

Group: Members
Posts: 716
Joined: 14-July 04
From: Midwest
Member No.: 2,348



I guess I should add..

Your box was rooted from an exploit in the software you were using. So no amount of firewalls would have protected from that. I'm not telling you your business, just the facts. A firewall would have only stopped a few of the things you menthioned. A firewall is not a replacement for patch management. Keep the box updated as much as possible.

A firewall will definitely help though, and the Nokia is yours if you want it.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Rand
post Apr 14 2006, 01:35 PM
Post #48


Cross Member
*****

Group: Members
Posts: 7,409
Joined: 8-February 05
From: OR
Member No.: 3,573
Region Association: None



QUOTE(SirAndy @ Apr 14 2006, 10:05 AM) *

right now, i'm pondering options and a hardware solution like one of the "cheaper" (note, i didn't say "cheap", i said "cheaper") Netscreen Firewalls is looking pretty good to me ...
(IMG:style_emoticons/default/type.gif) Andy


I use Netscreen firewalls, and have been very pleased with them. I started with a little 5xp several years ago before Juniper bought them out. I like the separate hardware unit better than running a software-based firewall on the server.

Just a heads-up (I'm sure you are already aware of, but just in case...) The subscription to keep them updated is not cheap.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Apr 14 2006, 01:55 PM
Post #49


Resident German
*************************

Group: Admin
Posts: 41,662
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(Verruckt @ Apr 14 2006, 12:28 PM) *

I guess I should add..

Your box was rooted from an exploit in the software you were using. So no amount of firewalls would have protected from that. I'm not telling you your business, just the facts. A firewall would have only stopped a few of the things you menthioned. A firewall is not a replacement for patch management. Keep the box updated as much as possible.

A firewall will definitely help though, and the Nokia is yours if you want it.


yes, never said it would. there's another thread here somewhere where i go more into detail. i've been around this stuff for a while. firewall DOES help protecting against the "brute force" attacks he was running, at least on the NetBios Port as there is NO reason to share this one with the world.

i'll gladly pay shipping! you rock ...
(IMG:style_emoticons/default/smilie_pokal.gif) Andy
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Apr 14 2006, 01:58 PM
Post #50


Resident German
*************************

Group: Admin
Posts: 41,662
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(Verruckt @ Apr 14 2006, 12:28 PM) *

Keep the box updated as much as possible.


no problem there either. box has always been up to date with everything, EXCEPT the BBS software.
as said before, the reason behind that is/was the TONS of custom code that went into our old BBS.
all of that is lost now and has to be re-created ... (IMG:style_emoticons/default/type.gif)

and no, i'm not just talking about downloading some pre-made skin from invision ...
(IMG:style_emoticons/default/rolleyes.gif) Andy
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Verruckt
post Apr 14 2006, 02:00 PM
Post #51


Senior Member
***

Group: Members
Posts: 716
Joined: 14-July 04
From: Midwest
Member No.: 2,348



QUOTE(SirAndy @ Apr 14 2006, 02:55 PM) *

QUOTE(Verruckt @ Apr 14 2006, 12:28 PM) *

I guess I should add..

Your box was rooted from an exploit in the software you were using. So no amount of firewalls would have protected from that. I'm not telling you your business, just the facts. A firewall would have only stopped a few of the things you menthioned. A firewall is not a replacement for patch management. Keep the box updated as much as possible.

A firewall will definitely help though, and the Nokia is yours if you want it.


yes, never said it would. there's another thread here somewhere where i go more into detail. i've been around this stuff for a while. firewall DOES help protecting against the "brute force" attacks he was running, at least on the NetBios Port as there is NO reason to share this one with the world.

i'll gladly pay shipping! you rock ...
(IMG:style_emoticons/default/smilie_pokal.gif) Andy


I never saw that other thread? What was the title? I'd like to read it.

This nokia is a 4u. I'm not sure what your hosting arrangement is, but just know that it's big. PM me and we can get down to brass tacks.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Rand
post Apr 14 2006, 02:03 PM
Post #52


Cross Member
*****

Group: Members
Posts: 7,409
Joined: 8-February 05
From: OR
Member No.: 3,573
Region Association: None



QUOTE(Verruckt @ Apr 14 2006, 12:28 PM) *

Your box was rooted from an exploit in the software you were using. So no amount of firewalls would have protected from that.


Good points Kurt. And very cool to offer the firewall! (IMG:style_emoticons/default/smilie_pokal.gif)

The guys know what they are doing... they know a hole in the old board software was exploited. Hence the upgrade at the cost of a ton of customization work. The firewall would have been a huge protection for things like the port 139 attack that was happening after the site was compromised.
[edit: never mind, my post was slow (IMG:style_emoticons/default/smile.gif) ]

On skins...
Admins: Will multiple skins be supported now? Are you cool with people building some custom skins that could be submitted for approval and added to the list of choices?

This post has been edited by Rand: Apr 14 2006, 02:07 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Apr 14 2006, 02:18 PM
Post #53


Resident German
*************************

Group: Admin
Posts: 41,662
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(Verruckt @ Apr 14 2006, 01:00 PM) *

This nokia is a 4u. I'm not sure what your hosting arrangement is, but just know that it's big. PM me and we can get down to brass tacks.


got plenty of space left, more than half a rack ...

i'm going to lunch now, i'll PM you when i get back ...
(IMG:style_emoticons/default/chowtime.gif) Andy
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Apr 14 2006, 02:19 PM
Post #54


Resident German
*************************

Group: Admin
Posts: 41,662
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(Verruckt @ Apr 14 2006, 01:00 PM) *

I never saw that other thread? What was the title? I'd like to read it.


i'll have to look for it. maybe that was on the bird board? alzheimers ...
(IMG:style_emoticons/default/confused24.gif) Andy
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
McMark
post Apr 14 2006, 02:46 PM
Post #55


914 Freak!
***************

Group: Retired Admin
Posts: 20,179
Joined: 13-March 03
From: Grand Rapids, MI
Member No.: 419
Region Association: None



QUOTE(Rand @ Apr 14 2006, 01:03 PM) *

On skins...
Admins: Will multiple skins be supported now? Are you cool with people building some custom skins that could be submitted for approval and added to the list of choices?


It's a possibility. (It always was)

Jeroen is in charge of look and feel. He'll have to answer this question.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
markb
post Apr 14 2006, 03:23 PM
Post #56


914less :(
*****

Group: Members
Posts: 5,449
Joined: 22-January 03
From: Nipomo, CA
Member No.: 180
Region Association: Central California



QUOTE(Jeroen @ Apr 13 2006, 01:05 PM) *

ewwwww... ugly standar look (IMG:style_emoticons/default/biggrin.gif)
well good thing we have a long weekend ahead
instead of painting easter eggs I'll throw some paint around here (IMG:style_emoticons/default/wink.gif)

oh... and thanks Andy/Mark for all the hard work and getting the site up and runnin' again!



(IMG:style_emoticons/default/agree.gif)

And a big thanks to you, too, Jeroen, for all the work you will be putting in.

I'm with Jen, it's good to have our "home" back, even if it is a bit different for a while.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
ClayPerrine
post Apr 14 2006, 06:37 PM
Post #57


Life's been good to me so far.....
***************

Group: Admin
Posts: 15,490
Joined: 11-September 03
From: Hurst, TX.
Member No.: 1,143
Region Association: NineFourteenerVille



QUOTE(SirAndy @ Apr 14 2006, 02:55 PM) *

QUOTE(Verruckt @ Apr 14 2006, 12:28 PM) *

I guess I should add..

Your box was rooted from an exploit in the software you were using. So no amount of firewalls would have protected from that. I'm not telling you your business, just the facts. A firewall would have only stopped a few of the things you menthioned. A firewall is not a replacement for patch management. Keep the box updated as much as possible.

A firewall will definitely help though, and the Nokia is yours if you want it.


yes, never said it would. there's another thread here somewhere where i go more into detail. i've been around this stuff for a while. firewall DOES help protecting against the "brute force" attacks he was running, at least on the NetBios Port as there is NO reason to share this one with the world.

i'll gladly pay shipping! you rock ...
(IMG:style_emoticons/default/smilie_pokal.gif) Andy



Andy... just a curiosity quesiton....

Why is the netbios protocol enabled? I doubt it is needed for this BBS. Turn it off and block netbios at the router.

My DNS server is NT 4.0. It has not been hacked. Of course the ONLY port allowed to it is port 53.


User is online!Profile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Apr 14 2006, 07:51 PM
Post #58


Resident German
*************************

Group: Admin
Posts: 41,662
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(ClayPerrine @ Apr 14 2006, 05:37 PM) *

Why is the netbios protocol enabled? I doubt it is needed for this BBS. Turn it off and block netbios at the router.

My DNS server is NT 4.0. It has not been hacked. Of course the ONLY port allowed to it is port 53.


first, no router. straight into the OCR pipe. well, of course there IS a router somewhere, but it doesn't belong to us (me) ...

second, NetBios is (was) enabled because the server is one of many in the colo and i have used it in the past for backups from other machines.
easiest way, set up a (password protected of course) network share and run a script at 3 am that does your backup.
werks like a charm and wouldn't be any problem at all if the 914club box was behind a firewall ...

i have netbios turned off right now until we get a firewall in front of this box ...
(IMG:style_emoticons/default/ph34r.gif) Andy
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

3 Pages V < 1 2 3
Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



- Lo-Fi Version Time is now: 29th May 2024 - 02:41 AM