Friday, April 06, 2007

We've been 'hacked.' Part I of ongoing saga

So I was chatting on Instant messenger with James last night and I asked him if he had seen some of the recent changes that I had made on one of our projects under development when he gave me the worst news of my web nerd life...

"Germans Have Hacked Our Site!" <-- Turns out that they are Turkish not German, thanks "Dr" (see 1st comment)

"That's B.S." was my initial reaction but I asked him more about it and then went to check it out myself and sure enough there it was, a most heinous message:








THOSE JERKS!




Now, I have to say that I honestly do not understand what would possess any decent human being to do something like this.

Now to deflate the egos of these low lifes, I would like to draw your attention to the quotation marks on the word hacked in the title of this post. Why? Because these guys, I am willing to bet, have not really hacked our site. And I will explain that , while chewing them out, in the rest of this post. But first:

  1. I want everyone to know that the search engine has in no way been effected. And it will not be.
  2. Likewise the hot search archive is completely fine as well.
"So then," you ask, "what did they hack into? Where is that message popping up?

Well, it is on "Nipponster Entertainment" a separate site that we have been working on that has content like live tv broadcasts, aggregated news, video clips, and pictures etc. (If you don't know what aggregated means don't worry, it is nerd-speak). The site is not really ready yet as we are still working on a lot of it; it's still pre-release. But it appears in the results of hot searches for "Japanese tv online" etc, which are pretty popular and many of our users enjoy. To see what the hackers have done click here and wait a few seconds until it refreshes and switches to their site. See?! That is why I am very upset!


So why do I say that they didn't really hack us?
I am fairly certain that they found our site by googling "phpizabi" which is the name of the CMS (content management system; kind of like software) we are using for that site. That is my guess, because I know that others using phpizabi have had that problem. Once they find your site they take advantage of some known problem with phpizabi's admin (administrator) settings to do their dirty work. I am pretty sure that is what happened although I have not gone to fix it yet and I do not think that it will be a problem to fix. But it is REALLY annoying!

I am going to check and see if there is a hotfix (a download that fixes a problem with the site) that I might have forgotten to add.

But for now I want to show you what these jerks have been doing to other hapless webmasters, it is truly sad and repulsive.
Below is the link to a search I did on google for "[Name of Hackers]" (from the URL of the hacker message):

[re-editted to admit the name]

And sure enough I found amongst the results other sites using phpizabi so I am sure that is why they targeted us as well. ARRRGH!

But on the bright side I see that the webmasters of that site were able to fix it.
I am going to contact them and hear about their experience. Hopefully we can keep others from being victimised.

AND I want to say something to you hackers (if you are reading this):

Am I going to get back at you? Am I going to find some why to punish you for your deeds by stooping to your level?

No, ... I'm going to forgive you... Because it is better
But I am going to continue this topic in future posts to let others know how to protect themselves against hackers, how to report their activity to those who can stop them, and to update you with conversations I have with other victims of these same hackers.

AND that is the end of that.
Good night!

p.s.
I originally made some sensational and regrettable remarks in this post. I'd like to take this opportunity to apologise for those remarks. I am sorry. That said, having part of your site hacked can make you act rather emotional and stupid.

Labels: ,

3 Comments:

Blogger Innova448 said...

They're Turkish mate.

6:10 AM  
Blogger Nipponster Staff said...

Thank Dr.

wow. I should really change that title then. And apologise for a few things.

I just assumed James recognised their writing as German.

I should have been more cautious about what I was posting on the blog and I usually am. I think this whole situation has upset me and I am not thinking straight.

1:24 PM  
Anonymous Anonymous said...

I had a phpizabi site hacked too. I know that they are the most hacked wesites out there. I wasnt able to get a hotfix or anything from PHPIZABI to fix it. What I ended up having to do was to CHMOD my entire Admin directories to read only, and I CHMOD them back anytime I want to edit the site again

3:49 AM  

Post a Comment

Subscribe to Post Comments [Atom]

<< Home