Ass Hat
Home
News
Events
Bands
Labels
Venues
Pics
MP3s
Radio Show
Reviews
Releases
Buy$tuff
Forum
  Classifieds
  News
  Localband
  Shows
  Show Pics
  Polls
  
  OT Threads
  Other News
  Movies
  VideoGames
  Videos
  TV
  Sports
  Gear
  /r/
  Food
  
  New Thread
  New Poll
Miscellaneous
Links
E-mail
Search
End Ass Hat
login

New site? Maybe some day.
Posting Anonymously login: [Forgotten Password]
returntothepit >> discuss >> I was hacked by the_reverend on May 11,2007 3:37pm
Add To All Your Pages!
toggletoggle post by the_reverend   at May 11,2007 3:37pm
Hell-0 all, i was hacked... I just wanted to make sure the_reverend checks his email out and fixes the holes in his site. Well, later all and stay metal!



toggletoggle post by the_reverend   at May 11,2007 3:48pm
yeah, I'm trying to fix that... I can't believe the hole that was found.. holy shit. site's going down.



toggletoggle post by the_reverend   at May 11,2007 4:13pm
try to fix things...



toggletoggle post by tha rev at May 11,2007 4:24pm
test



toggletoggle post by the_reverend   at May 11,2007 4:27pm
I can't believe the holes that this person found... wow.. really.. like wow..



toggletoggle post by AUTOPSY_666   at May 11,2007 4:39pm



toggletoggle post by menstrual_sweatpants_disco   at May 11,2007 4:54pm
Who was it?



toggletoggle post by the_reverend   at May 11,2007 5:18pm
idk who it is, but they emailed me what they did. people are probably going to have to log in again later on



toggletoggle post by Mess at May 11,2007 6:34pm



toggletoggle post by the_reverend   at May 11,2007 7:11pm
I checked out his (the hacker's) site and it seems like he's a turn uber leet haxxor in the truest sense of the word. I hope to converse with him more later.

he obviously loves metal... and wasn't malicious. I really can't believe the stupid username hack he found. it was the same one used to hack winXp update validation like 4 years ago.



toggletoggle post by ConquerTheBaphomet  at May 11,2007 7:19pm
the_reverend said:
it was the same one used to hack winXp update validation like 4 years ago.


Is he the same guy?



toggletoggle post by Mess at May 11,2007 7:22pm
i really wish i understood what's going on here



toggletoggle post by Dwellingsickness at May 11,2007 7:24pm
Me too



toggletoggle post by the_reverend   at May 11,2007 7:29pm
it's ok just banghead here X



toggletoggle post by Mess at May 11,2007 7:29pm
Dwellingsickness said:
Me too


just...
not much going on tonight. i'm just browsing youtube for now...
http://www.youtube.com/watch?v=UZVwMJs32WE



toggletoggle post by AUTOPSY_666   at May 11,2007 7:43pm



toggletoggle post by sxealex   at May 11,2007 7:44pm
post the hack after u fix it.



toggletoggle post by Dwellingsickness at May 11,2007 7:45pm
whoa that looked like it hurt.......alot



toggletoggle post by Mess at May 11,2007 7:47pm
hiiiiiyah! that's called the poker pig choke! haha



toggletoggle post by Mess at May 11,2007 7:52pm edited May 11,2007 7:52pm
sxealex said:
post the hack after u fix it.


yeah, let's e-beat his/her ass



toggletoggle post by xanonymousx at May 11,2007 8:22pm
Mess said:
Dwellingsickness said:
Me too


just...
not much going on tonight. i'm just browsing youtube for now...
http://www.youtube.com/watch?v=UZVwMJs32WE


this video came after this one
http://www.youtube.com/watch?v=kJ59rvPGe_4
just watch the beginning crazy people



toggletoggle post by the_reverend   at May 11,2007 8:28pm
it's 1/2 fixed. will post laterz.



toggletoggle post by xanonymousx at May 11,2007 8:47pm
at least the dude who did it respects you and did not destroy the site and wants you fix it.
but still it was wrong.



toggletoggle post by DeRtOxIa   at May 11,2007 9:23pm
i dont consider this type of hacking as wrong. it just makes things more secure. it would have been a little better if the dude just contact the rev and didnt make a public post about it but whatever. he didnt intend to fuck shit up. he just wanted to point out a vulnerability. most bugs would never be found if people didnt look for them and try to exploit them.



toggletoggle post by DeRtOxIa   at May 11,2007 9:23pm
i'm of course referring to the internet as a whole....not just this site.



toggletoggle post by sxealex   at May 11,2007 9:28pm
its not wrong its just illegal



toggletoggle post by sxealex   at May 11,2007 9:28pm
unless he has ur permission



toggletoggle post by the_reverend   at May 11,2007 9:29pm
I agree. he didn't do anything malicious that I know of. I can't believe the truck size hole.



toggletoggle post by xanonymousx at May 11,2007 9:30pm
did it happen when you moved to the faster server.



toggletoggle post by boine at May 11,2007 10:41pm
he probably posted a worm and where all gonna get it



toggletoggle post by the_reverend   at May 11,2007 11:16pm
not, these bugs have been here forever. I will paste what he said. I think it's scary, but cool of him.



toggletoggle post by boine at May 12,2007 12:47am
did you feel violated?



toggletoggle post by the_reverend   at May 12,2007 12:55am
a little.



toggletoggle post by the_reverend   at May 12,2007 3:43am
first hack,
open a browser to http://www.returntothepit.com

put this in the addressbar.
javascript:void(document.cookie="site_user=the_reverend");

refesh the page and you are logged in as the_reverend. that doesn't happen anymore. this was a old hack for the winxp authentication.



toggletoggle post by DaveFromTheGrave  at May 12,2007 3:48am
that is a big hole. or was.



toggletoggle post by the_reverend   at May 12,2007 3:54am
the other is a hell of a lot geeky. I need to try some more things before I post it.



toggletoggle post by menstrual_sweatpants_disco   at May 12,2007 1:21pm
God bless the white hats.



toggletoggle post by boine at May 12,2007 2:35pm
i like all the new dont hack the site warnings when you try that



toggletoggle post by blah? at May 14,2007 4:11pm
Did you fix them yet? E-mail me back and i'll tell you about a possible DoS using your own script. :p



toggletoggle post by menstrual_sweatpants_disco   at May 14,2007 4:35pm
This guy is awesome.



toggletoggle post by Mess at May 14,2007 5:46pm
i could only imagine who it could be?



toggletoggle post by the_reverend   at May 15,2007 11:02am
I guess I can post the other hack that the dude did...

http://www.returntothepit.com/cdreview.php...14,15,16,17,18%20FROM%20mysql.user/ *

it made a CD review with the contents of my mysql users and passwords for accessing the database.



toggletoggle post by blahman3000 at May 15,2007 12:54pm edited May 15,2007 1:16pm
Did you want me to send you an email with the new attack?






toggletoggle post by the_reverend   at May 15,2007 12:56pm
I see it.



toggletoggle post by blahman3000 at May 15,2007 12:57pm
Did you mean the DoS one or the one i just did like 3 seconds ago?



toggletoggle post by the_reverend   at May 15,2007 12:58pm
or you could just not do that...



toggletoggle post by the_reverend   at May 15,2007 12:58pm
what is the DoS one?



toggletoggle post by blahman3000 at May 15,2007 12:59pm
i'll email it to you because i don't want it to open public



toggletoggle post by Mess at May 15,2007 1:01pm
zomg!



toggletoggle post by Yeti at May 15,2007 1:01pm
pretty lame, Milhouse



toggletoggle post by blahman3000 at May 15,2007 1:03pm
Milhouse?



toggletoggle post by the_reverend   at May 15,2007 1:09pm
that's a pretty funny actually.



toggletoggle post by blahman3000 at May 15,2007 3:25pm
How do you like the CSRF one i just sent you?



toggletoggle post by the_reverend   at May 15,2007 3:42pm
I emailed back asking for an example..



toggletoggle post by blahman3000 at May 15,2007 3:43pm
i'm sorry, gmail must be slow, just look at my profile and click another link if you want to view an example now. YOu'll notice that after you navigate away from the profile you'll be logged out.



toggletoggle post by blahman3000 at May 15,2007 3:55pm
Got it, sent you one back with the info on how to do it.



toggletoggle post by the_reverend   at May 15,2007 3:56pm
ok, that's exactly what I thought when you sent the email.
you have 2 images so it only works with one of them, but that one is random so... it's a crap shoot which comes up.



toggletoggle post by the_reverend   at May 15,2007 3:57pm
oh, I fixed it before I got your email. I saw what you were talking about.



toggletoggle post by the_reverend   at May 15,2007 3:58pm
only you can see them when you click on "show all" to delete it.



toggletoggle post by blahman3000 at May 15,2007 4:01pm
Yeah, there were 2, i couldn't delete one of them because evertime i would try to remove it, the other image would load and log me off, lol.



toggletoggle post by the_reverend   at May 15,2007 4:09pm
yeah, did you click on the injection link with the cdid=99999 again? try it.



toggletoggle post by blahman3000 at May 15,2007 4:13pm
ROFL! ping of death!



toggletoggle post by the_reverend   at May 15,2007 4:16pm
no one seems to remember that one... too good for win 95's ip stack I guess.
my friend freaked out when I sent him that last night.
now he's trying injection on a bunch of conservative sites.



toggletoggle post by the_reverend   at May 15,2007 4:23pm
years and years ago (like 2002/3) I made my own pear/mysqli/pdo set of classes, but I didn't account for mysql injection. I recently made a bug tracking system and I'm working some of the perl db safe guards back now that I see the vulnerability.



toggletoggle post by immortal13 at May 15,2007 6:09pm edited May 15,2007 6:09pm



toggletoggle post by FuckIsMySignature at May 15,2007 6:23pm
you sunk my battleship



toggletoggle post by nights1 at May 15,2007 10:46pm
Btw man, the CSRF still works.



toggletoggle post by blahman3000 at May 16,2007 10:44am
I'll make another thread entitled "Don't Click or you will log out" and put the CSRF example in there. Anyone logged in that reads the forum shall theoretically get logged out and you won't realise it until you navigate away from the page/refresh/etc.. Also, i can send you an email on how to defend against such a thing, if you want.



toggletoggle post by the_reverend   at May 16,2007 10:47am
don't do that. I know about that already. I realized it on the way to a show last night.



toggletoggle post by sxealex   at May 16,2007 10:51am
yea but why is the password in the current cookie then?



toggletoggle post by blah3000 at May 16,2007 10:54am
hey reverend, if you want, put the sessid as a variable after logout, so logout=1&sess=x, then if the session doesn't match it won't log you out. This is how most people are defending against this.



toggletoggle post by the_reverend   at May 16,2007 11:20am
I'll do both of them.



Enter a Quick Response (advanced response>>)
Username: (enter in a fake name if you want, login, or new user)SPAM Filter: re-type this (values are 0,1,2,3,4,5,6,7,8,9,A,B,C,D,E, or F)
Message:  b i u  add: url  image  video(?)show icons
remember:typos add character
[default homepage] [print][5:47:42am Apr 20,2024
load time 0.05120 secs/12 queries]
[search][refresh page]