<?xml version="1.0"?>
<rss version="2.0">
	<channel>
		<title>Hacked by CyberLord</title>
		<link>http://www.allegro.cc/forums/view/587102</link>
		<description>Allegro.cc Forum Thread</description>
		<webMaster>matthew@allegro.cc (Matthew Leverton)</webMaster>
		<lastBuildDate>Tue, 22 Aug 2006 07:18:23 +0000</lastBuildDate>
	</channel>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Well I found one of my sites hacked tonight. The config.php file had been overwritten with &quot;</p><h1>Hacked by CyberLord</h1><p>&quot;. What I&#39;m trying to figure out is the extent and type of the attack. From the looks of it, it was a scripted attack. Nothing else was hit but that one, very common, file. So at first it seems like a harmless, non-personal attack.<br />But, the site is entirely coded by me, and there is no part of it that could lead to someone overwriting a file. For that there&#39;d need to be some file writing mechanism or something that uses system commands, of which there are none. Now I do have WordPress installed, related to that site, but it is in a different directory. How could a script have gone from that directory to the other? And why were no other config files touched? I&#39;ve got a beta version of that site setup in another directory with the exact same layout of files, but it&#39;s untouched.<br />One small mistake on my part is that the config.php file had 777 file permissions (rsync problem). Perhaps that has something to do with it. If the script searched for all config files and tried to overwrite them this would be the only config file it could have overwritten.</p><p>In any case, I highly suspect WordPress being the culprit. Does anyone have any info on vulnerabilities in WordPress? I installed it about a month ago. Or any info in general about what may have caused this.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Billybob)</author>
		<pubDate>Fri, 18 Aug 2006 14:03:47 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>&quot;Your WebSite died because it wasn&#39;t pretty enough.&quot;
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (GullRaDriel)</author>
		<pubDate>Fri, 18 Aug 2006 14:07:25 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Looks like he&#39;s been a busy fellow:<br /><a href="http://www.google.com/search?client=safari&amp;rls=en&amp;q=hacked+by+cyberlord&amp;ie=UTF-8&amp;oe=UTF-8">link</a><br />Pete
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Peter Hull)</author>
		<pubDate>Fri, 18 Aug 2006 14:25:59 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>
It was for a good cause though. <img src="http://www.allegro.cc/forums/smileys/smiley.gif" alt=":)" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Richard Phipps)</author>
		<pubDate>Fri, 18 Aug 2006 15:03:38 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>One of the Google entries said Cyberlord was here for Islam. His religion told him to hack a website? Cool... <img src="http://www.allegro.cc/forums/smileys/smiley.gif" alt=":)" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (James Stanley)</author>
		<pubDate>Fri, 18 Aug 2006 18:43:02 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Which site was that? I&#39;d like to take a look, if you don&#39;t mind. Is the config file the only one with 777 privileges?
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Elverion)</author>
		<pubDate>Fri, 18 Aug 2006 19:07:07 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Probably some retard 13 year old using on old hole and a tool.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Thomas Fjellstrom)</author>
		<pubDate>Fri, 18 Aug 2006 19:40:09 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Is register globals on? If so, Wordpress is vulnerable to bad cookies.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Matthew Leverton)</author>
		<pubDate>Fri, 18 Aug 2006 19:45:46 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>if PhpBB is used, theres all sorts of bugs that let people replace index files with messages. Lots of PHP software is like that for somereason. Can&#39;t quite fathom why <img src="http://www.allegro.cc/forums/smileys/rolleyes.gif" alt="::)" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Thomas Fjellstrom)</author>
		<pubDate>Fri, 18 Aug 2006 21:49:41 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>ML: Yes, I believe it is ON for WordPress. I disable it on my custom sites, but I don&#39;t have a global htaccess installed yet for every site. What kind of vulnerability is that? Does it apply to a month old version and allow the execution of shell commands?
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Billybob)</author>
		<pubDate>Sat, 19 Aug 2006 01:02:09 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Actually most of them say something about Islam...  Your website must be a victim of the jihad. <img src="http://www.allegro.cc/forums/smileys/shocked.gif" alt=":o" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Michael Jensen)</author>
		<pubDate>Sat, 19 Aug 2006 01:36:21 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p><a href="http://www.securiteam.com/unixfocus/5BP0G00GLK.html">http://www.securiteam.com/unixfocus/5BP0G00GLK.html</a>
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Matthew Leverton)</author>
		<pubDate>Sat, 19 Aug 2006 01:56:41 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>ML: Thank you for the link. I stopped keeping up on BugTraq a long time ago. Too much work.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Billybob)</author>
		<pubDate>Sat, 19 Aug 2006 03:18:42 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Me too, I just typed &quot;Wordpress exploit&quot; in google. (And pressed the search button.)
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Matthew Leverton)</author>
		<pubDate>Sat, 19 Aug 2006 03:56:58 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>You could also press enter.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (BAF)</author>
		<pubDate>Sat, 19 Aug 2006 03:58:00 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>In fact, google suggests that <img src="http://www.allegro.cc/forums/smileys/tongue.gif" alt=":P" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Thomas Fjellstrom)</author>
		<pubDate>Sat, 19 Aug 2006 04:35:13 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><div class="quote_container"><div class="title">Quote:</div><div class="quote"><p>
(And pressed the search button.)
</p></div></div><p>
Genius!
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Billybob)</author>
		<pubDate>Sat, 19 Aug 2006 09:27:43 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>I always get stuck with submit buttons.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (James Stanley)</author>
		<pubDate>Sat, 19 Aug 2006 20:07:39 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>I <b>only</b> use the feeling lucky button, I&#39;m just that good.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (ImLeftFooted)</author>
		<pubDate>Sun, 20 Aug 2006 01:24:28 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>I never use the &quot;im feeling lucky button&quot;. I dont even understand the point of it really. Are people so lazy they cant be bothered to click &quot;search&quot; and then click on the first link? I like to see all my options( at least the first page ) before clicking on something.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (kazzmir)</author>
		<pubDate>Sun, 20 Aug 2006 01:27:21 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><div class="quote_container"><div class="title">Quote:</div><div class="quote"><p>
Are people so lazy they cant be bothered to click &quot;search&quot; and then click on the first link?
</p></div></div><p>

Just asking such questions shows you don&#39;t know how lazy people can get. <img src="http://www.allegro.cc/forums/smileys/grin.gif" alt=";D" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Michael Faerber)</author>
		<pubDate>Sun, 20 Aug 2006 01:53:05 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>If I want to feel lucky, I enter my search term into Firefox&#39;s address bar and let FF do the dirty work for me. I&#39;m just that much better than you. <img src="http://www.allegro.cc/forums/smileys/grin.gif" alt=";D" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (BAF)</author>
		<pubDate>Sun, 20 Aug 2006 03:00:12 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>I only use the im feeling lucky feature in konqueror. typing a couple words into (or sometimes a non url) the address bar goes to I&#39;m Feeling Lucky. so it has its uses, sometimes. though that feature doesn&#39;t work all that well anymore.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Thomas Fjellstrom)</author>
		<pubDate>Sun, 20 Aug 2006 04:39:19 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>For the longest time I thought the &quot;I&#39;m feeling lucky&quot; button was some sort of advert, and never clicked it. I figured it was some gambling-related site or something <img src="http://www.allegro.cc/forums/smileys/tongue.gif" alt=":P" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (CGamesPlay)</author>
		<pubDate>Sun, 20 Aug 2006 05:15:57 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>I use I&#39;m Feeling Lucky if I know which site I want to go to, but not the domain/URL of it... It just means less clicking and waiting.</p><p>Though, the only problem with IFL is if the websites&#39; popularity changes...
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Archon)</author>
		<pubDate>Sun, 20 Aug 2006 06:19:43 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><div class="quote_container"><div class="title">Quote:</div><div class="quote"><p>
For the longest time I thought the &quot;I&#39;m feeling lucky&quot; button was some sort of advert, and never clicked it. I figured it was some gambling-related site or something <img src="http://www.allegro.cc/forums/smileys/tongue.gif" alt=":P" />
</p></div></div><p>

So did I.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (James Stanley)</author>
		<pubDate>Mon, 21 Aug 2006 13:58:42 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>This is why I try things <img src="http://www.allegro.cc/forums/smileys/tongue.gif" alt=":P" /></p><p>Many people ask me how I know so much (which I admit isn&#39;t much at all) about things like Office and what not, and all I can say is its because I explore the interface and see what things do. Then theres the people who are afraid of hitting buttons as if its going to blow up their house. Somewhat like you guys <img src="http://www.allegro.cc/forums/smileys/tongue.gif" alt=":P" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Thomas Fjellstrom)</author>
		<pubDate>Tue, 22 Aug 2006 05:21:46 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>I&#39;m kind of like Tomasu. A lot of times I click stuff just for the hell of it.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (BAF)</author>
		<pubDate>Tue, 22 Aug 2006 05:26:52 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><div class="quote_container"><div class="title">Quote:</div><div class="quote"><p>
its because I explore the interface and see what things do
</p></div></div><p>

I was very surprised when I learned that most people don&#39;t do this.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (LennyLen)</author>
		<pubDate>Tue, 22 Aug 2006 07:10:03 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Oh, I try plenty. I remember the good old days of me hitting every single configuration option in Windows 98. Taught me a lot about how computers work. Nowadays I try things in my areas of expertise, but try to get help on other issues. Which is why I bug my contacts for sysadmin help <img src="http://www.allegro.cc/forums/smileys/smiley.gif" alt=":)" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (CGamesPlay)</author>
		<pubDate>Tue, 22 Aug 2006 07:14:41 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Most people only look at the center of the screen. That&#39;s why I like the &lt;marquee&gt; tag so much.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Matthew Leverton)</author>
		<pubDate>Tue, 22 Aug 2006 07:18:23 +0000</pubDate>
	</item>
</rss>
