Notices
928 Forum 1978-1995
Sponsored by:
Sponsored by: 928 Specialists

Devek website hacked

Thread Tools
 
Search this Thread
 
Old Sep 12, 2004 | 02:23 AM
  #1  
Bill51sdr's Avatar
Bill51sdr
Thread Starter
Fleet of Foot
Rennlist Member
 
Joined: Aug 2003
Posts: 10,780
Likes: 51
From: We are there!(San Diego)
Default Devek website hacked

Marc, Susan... Some idiot has hacked into your website rendering it inaccessable. I was trying to show a friend of mine a car for sale on your site and...
Reply
Old Sep 12, 2004 | 02:37 AM
  #2  
Steve J.'s Avatar
Steve J.
Addict
Rennlist Member

 
Joined: Jul 2001
Posts: 1,319
Likes: 2
From: Irving, TX
Default

whoa!... bummer!
Reply
Old Sep 12, 2004 | 02:44 AM
  #3  
SharkSkin's Avatar
SharkSkin
Rennlist Member
 
Joined: Jan 2004
Posts: 12,620
Likes: 8
From: Boulder Creek, CA
Default

Whoops... Apache/1.3.14 is a pretty old version. Obviously a bit too old....
Reply
Old Sep 12, 2004 | 03:12 AM
  #4  
Nicole's Avatar
Nicole
Cottage Industry Sponsor
Lifetime Rennlist
Member
20 Year Member
 
Joined: Oct 2001
Posts: 25,818
Likes: 167
From: SF Bay Area, CA
Default

Ouch! That's pretty nasty...
Reply
Old Sep 12, 2004 | 03:25 AM
  #5  
Ron_H's Avatar
Ron_H
928 Barrister
Rennlist Member

20 Year Member
 
Joined: Sep 2002
Posts: 4,772
Likes: 6
From: Sunnyvale, CA
Default

Pardon me. I must be naive. Would someone please tell me why the **** anyone would do this?
Reply
Old Sep 12, 2004 | 03:32 AM
  #6  
Tony's Avatar
Tony
Addict
Lifetime Rennlist
Member
20 Year Member
 
Joined: May 2001
Posts: 14,697
Likes: 598
From: Las Vegas
Default

OMG!! Thats sucks...i cant even imagine how you fix it?

Makes you want to go and check your bank account as well!
Reply
Old Sep 12, 2004 | 03:43 AM
  #7  
Big Dave's Avatar
Big Dave
928 Engine Re-Re-Rebuild Specialist
Rennlist Member
20 Year Member
 
Joined: Oct 2001
Posts: 7,972
Likes: 34
From: Brighton, MI
Default

Stupidity! WTF is wrong with people???
Reply
Old Sep 12, 2004 | 04:38 AM
  #8  
SharkSkin's Avatar
SharkSkin
Rennlist Member
 
Joined: Jan 2004
Posts: 12,620
Likes: 8
From: Boulder Creek, CA
Default

Originally Posted by Ron_H
Pardon me. I must be naive. Would someone please tell me why the **** anyone would do this?
Mostly it's an ego thing. Some kid found a way to break into stuff and they want to show off that they could do it. It really requires very little brains and a lot of time on one's hands. What it boils down to is this:

1) Some very smart computer scientist types whose main purpose is investigate security of computer systems finds a security hole.
2) The security hole is pointed out to the software manufacturer, and they set about fixing it. Sometimes the issue is made public early in this process, sometimes late.
3) Vendors vary in their response. Microsoft took many months to respond to a recent security hole involving buffer overflows. A similar hole was found in Apache and a fix was available in two days. In any case the hole is eventually made public; at the very least information is provided with the software update, describing the problem the update is intended to fix.
4) This is 1/2 of the key -- RESPONSIBLE system administrators keep their software up-to-date with the latest security patches... though the uptake can be slow, especially in the case of MS where the fixes often introduce more bugs than they fix. Generally significant time is spent testing to see that the updates don't break anything else, and this testing can delay imlementation for days or weeks depending on many factors.
5) This is the other half of the key point... Many systems are floating around on the net with inadequately patched out-of-date software that is vulnerable, and have been in such a state for far too long. The present case is a perfect example. Examples of how to exploit security holes are distributed of necessity... System administrators use this information to ensure that their systems are fixed.

So what I have described above is the mechanism by which systems are supposed to be made more secure. Unfortunately, this same information is eventually made available to the public. Someone with a bit of computer savvy packages up the exploit with some simple instructions. This may or may not be done in the interest of making life easier for system admins who need to test their systems.

Now this package is picked up by what is called a "script kiddie", a general term implying a person with (relatively)little computer expertise who picks up these packaged scripts and runs them against various systems they want to compromise.

Any web server can be made to divulge what software it is running, and what version that software is at. It's a trivial thing to create a script that would increment through public IP addresses finding web servers and reporting their software and revision. http://www.netcraft.com will report this info for any given web server(one at a time). I've never looked into the specific details of how to do this exact thing, but I bet with a little help from Google I could duplicate Netcraft's "What's that site running?" functionality here at home on my UNIX box in 30 minutes. Another 10 minute's tweaking and I could have that script iterate through all public IP addresses and report on web servers it finds. With this I could discover what web server runs at www.devek.net without ever knowing that the devek.net domain even exists. Truth be told, I could probably find an example already written in less time than it would take to write it myself.

So anyway, what we seem to have here is a script kiddie with an agenda, who found a crack for an old version of Apache, searched around and eventually found a web server running a version of Apache that they could compromise. They may have never seen the content of the website, may never have known that it was devek.net. Quite frankly, in a case like this where the software is so horribly out of date, this sort of thing is simply inevitable.

I'm going to assume that the webhosting service, apparently NetWizards, Inc., has made appropriate backups of the data and/or Devek has their own backups and based on that say it's only a minor nuisance. But it's a perfectly avoidable nuisance, and it's unfortunate that the Thomases seem to have been let down. They know 928s, not Web servers and they can't be expected to know all this stuff. Script kiddies suck, but they are a fact of life and one must take precautions if one is to maintain a web presence. But for the people in whose care they left their site, I offer the following:



Disclaimer: While my day job is all about breaking high-end corporate enterprise software, security is not what I focus on. But if I can educate myself a little about how to secure public systems, then there is no damn excuse for someone whose main job is maintaining public servers not to do so, and no excuse not to implement basic best practices.
Reply
Rennlist Stories

The Best Porsche Posts for Porsche Enthusiasts

story-0

2026 Porsche 911 Club Coupe is Spectacular, And Everything Wrong with the Porsche Market

 Joe Kucinski
story-1

Talos Takes Your 991 Porsche 911 GT3 to the Next Level for a Cool $1.13 Million

 Verdad Gallardo
story-2

9 Vehicles Porsche Helped Engineer that Aren't Porsches

 Verdad Gallardo
story-3

9 Features and Characteristics That Only Porsche People Understand

 Verdad Gallardo
story-4

I've Written 500 Rennlist Articles: Here's How Porsche Has Changed Along the Way

 Joe Kucinski
story-5

10 Most Unnecessary Porsches Ever Built (And Why We Love Them)

 Verdad Gallardo
story-6

Porsche 911 GT3 S/C vs 718 Spyder RS: 10 Categories, One Winner

 Joe Kucinski
story-7

This Builder Is Turning Heads With Its Slantnose 911 Creation

 Verdad Gallardo
story-8

Porsche 911 GT3 Artisan Edition Pays Homage to Japanese Culture

 Verdad Gallardo
story-9

Porsche Reveals Coupe Variant of the Electric Cayenne With a Fresh Look

 Verdad Gallardo
Old Sep 12, 2004 | 08:57 AM
  #9  
Thaddeus's Avatar
Thaddeus
Deer Slayer
Lifetime Rennlist
Member
 
Joined: May 2001
Posts: 25,565
Likes: 4
Default

Probably a real good idea for people not to go look at the Devek site. There may be programming on it now that will compromise your PC if it's not patched.
Reply
Old Sep 12, 2004 | 10:31 AM
  #10  
FlyingDog's Avatar
FlyingDog
Nordschleife Master
 
Joined: Sep 2004
Posts: 9,429
Likes: 6
From: Not close enough to VIR.
Default

It's probably just a bunch of jealous ricers.
Reply
Old Sep 12, 2004 | 10:44 AM
  #11  
Big Dave's Avatar
Big Dave
928 Engine Re-Re-Rebuild Specialist
Rennlist Member
20 Year Member
 
Joined: Oct 2001
Posts: 7,972
Likes: 34
From: Brighton, MI
Default

In case anyone wants to see the crap (it's apparently someone who knows little English or an adolescent)...here it is.
Attached Images
File Type: jpg
hacked.JPG (27.5 KB, 382 views)
Reply
Old Sep 12, 2004 | 12:36 PM
  #12  
Giovanni's Avatar
Giovanni
Race Car
 
Joined: Jun 2002
Posts: 4,269
Likes: 25
From: Alabama
Default

Definetly a looser trying to show off. Marc, can't you reload your last back up copy?
Reply
Old Sep 12, 2004 | 12:54 PM
  #13  
Thaddeus's Avatar
Thaddeus
Deer Slayer
Lifetime Rennlist
Member
 
Joined: May 2001
Posts: 25,565
Likes: 4
Default

They need to assume the box is completely compromised and rebuild from scratch. Somebody not nice has root on that box. If you just restore the files for the website, the O/S still belongs to somebody else.
Reply
Old Sep 12, 2004 | 01:01 PM
  #14  
rixter's Avatar
rixter
928 OB-Wan
Rennlist Member
 
Joined: Apr 2004
Posts: 4,999
Likes: 2
From: Zebulon, NC
Default

if you run a search for
All # hackingcenter crews dal.net
you will see these guys have hacked literally hundreds of sites...
Reply
Old Sep 12, 2004 | 01:46 PM
  #15  
Mark's Avatar
Mark
Addict
Rennlist Member

 
Joined: Jan 2003
Posts: 3,537
Likes: 1
From: Mountains of GA!
Default

Any chance we can re-instate public floggings? Maybe some caneings?

OR - We take one of Andy's blown sharks...tie a rope from the rear crossmember to one of the hackers legs...do the same to the other leg with one of Carl's...and have a drag race with the cars running in opposite directions??

This is SOOO pointless. Best of luck in getting things back to normal for Marc, Susan and the DEVEK team.
Reply



All times are GMT -3. The time now is 11:11 AM.

story-0
2026 Porsche 911 Club Coupe is Spectacular, And Everything Wrong with the Porsche Market

Slideshow: The 2026 Porsche 911 Club Coupe is being resold $150K above sticker and that is a real problem.

By Joe Kucinski | 2026-05-21 11:52:54


VIEW MORE
story-1
Talos Takes Your 991 Porsche 911 GT3 to the Next Level for a Cool $1.13 Million

Slideshow: Talos Vehicles has transformed the Porsche 911 GT3 RS into a carbon-bodied, race-inspired machine that costs well over $1 million before the donor car is even included.

By Verdad Gallardo | 2026-05-19 13:39:04


VIEW MORE
story-2
9 Vehicles Porsche Helped Engineer that Aren't Porsches

Slideshow: Long before engineering consulting became trendy, Porsche was quietly helping other automakers build everything from supercars to economy hatchbacks.

By Verdad Gallardo | 2026-05-15 12:44:44


VIEW MORE
story-3
9 Features and Characteristics That Only Porsche People Understand

Slideshow: Some brands build cars. Porsche builds traditions, obsessions, and a few habits that stopped making sense decades ago but somehow became part of the charm.

By Verdad Gallardo | 2026-05-13 18:46:13


VIEW MORE
story-4
I've Written 500 Rennlist Articles: Here's How Porsche Has Changed Along the Way

Slideshow: Six years and 500 Rennlist articles later, these are the biggest changes at Porsche.

By Joe Kucinski | 2026-05-11 09:52:55


VIEW MORE
story-5
10 Most Unnecessary Porsches Ever Built (And Why We Love Them)

Slideshow: Some Porsches exist for very specific reasons-others feel like they were built just to see if anyone would notice.

By Verdad Gallardo | 2026-05-06 18:00:32


VIEW MORE
story-6
Porsche 911 GT3 S/C vs 718 Spyder RS: 10 Categories, One Winner

Slideshow: Choosing between the 911 GT3 S/C and 718 Spyder RS in 10 key categories to determine one surprising winner.

By Joe Kucinski | 2026-05-05 12:51:46


VIEW MORE
story-7
This Builder Is Turning Heads With Its Slantnose 911 Creation

Slideshow: A small Polish tuner has reimagined the Porsche 911 Slantnose for the modern era, blending 1980s nostalgia with widebody tuning culture and serious performance upgrades.

By Verdad Gallardo | 2026-05-01 10:49:43


VIEW MORE
story-8
Porsche 911 GT3 Artisan Edition Pays Homage to Japanese Culture

Slideshow: Porsche has created a Japan-only 911 GT3 Artisan Edition that blends track-ready hardware with design cues inspired by traditional Japanese craftsmanship.

By Verdad Gallardo | 2026-04-28 19:37:40


VIEW MORE
story-9
Porsche Reveals Coupe Variant of the Electric Cayenne With a Fresh Look

Slideshow: Porsche's latest electric Cayenne Coupe blends dramatic styling with supercar acceleration, turning the brand's midsize SUV into a 1,139-horsepower flagship.

By Verdad Gallardo | 2026-04-27 19:39:30


VIEW MORE