Downtime

Odin

Carbon Dated and Proud
Admin
We've been hit with a bunch of attacks today and yesterday, as a result NMA has been sluggish or unavailable. A big thanks to our host Telefragged for fixing the problem.

Both RPGCodex and DAC are also under attack and this is the reason their sites are not available.
 
Yeah, Telefragged did a superb job of handling it. Unfortunately the source of the problem lies within phpBB.
 
Right... I noticed some other Phpbb fora dragging behing too, yesterday. Just a few though.

Good to know it's fixed.
 
Attack ? that's strange .. is it the original view.php highlight exploit (solved in phpBB 2.0.11 - I hope) ? That one used google to find its targets, and has been countered by the google guys.

So, what is it ? Can't recall a bugtraq entry about it ..
 
Not the new Santy variants?

Dubbed Santy.e, the worm differed significantly from its predecessors, said Russia-based Kaspersky Labs in an alert.

Rather than only target websites running phpBB -- software for creating internet forums using the PHP scripting language -- the worm could exploit any site left allowed arbitrary file inclusion into PHP scripts.

"This can only be prevented with decent, secure coding," said Kaspersky Labs. "Every site [that uses PHP] is potentially in danger."

Kaspersky noted it had already received reports of websites attacked by infected systems and that some servers have been compromised or dramatically slowed down as their loads climbed under constant probing.

Like earlier Santy variations, Santy.e uses Google to identify exploitable web pages written in PHP which use the vulnerable functions "include()" and "require()".

Santy.e, however, also throws Yahoo's and AOL's search engines into the mix, learning a lesson from the originals, which were stymied when Google blocked their searches.

Seems to be only an old version of PHP that can be targeted though...

This threads got quite a run down on what's been happening.

Virus Code: http://www.k-otik.com/exploits/20041225.PhpIncludeWorm.php
Symantec's Version: http://securityresponse.symantec.com/avcenter/venc/data/perl.lexac.html
 
The problem isn't as much the actual worm, but the amount of attacks taking place at one time. NMA was and is secure from these attacks, but when you get too many hits the server slows down.

RPGCodex got too many hits which resulted in the server crashing, DAC didn't and hence they could have that site up after some downtime. It was still under attack after they put it up tho.
 
so it was effectivly a DOS attack...

We need someone who can track them down, then we email any NMA memebers who live in that country and set up a paypal account to buy a big mother baseball bat to convince them of the error of their ways.

Friggin kiddie coding morons need some lead justice
 
Wild_qwerty said:
so it was effectivly a DOS attack...

We need someone who can track them down, then we email any NMA memebers who live in that country and set up a paypal account to buy a big mother baseball bat to convince them of the error of their ways.

Friggin kiddie coding morons need some lead justice

Im for it :twisted:
 
Ha, I can't help but laugh at your sig Exitium. I read it, I think of Volourn and I laugh.
 
Back
Top