Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Breaking: blog which exposed the Hamdania/Haditha incident is hacked
http://euphoricreality.com/ | 04/16/2008 | RaceBannon

Posted on 04/16/2008 8:38:48 PM PDT by RaceBannon

The site of Freeper EUPHORIADEV was hacked. She has lost over 2 years worth of data.

Euphoriadev was covering the Haditha and Hamdania incident extensively

she has lost over 2 years worth of data

we do NOT believe it is the people who are claiming the hack


TOPICS: Foreign Affairs; News/Current Events; War on Terror
KEYWORDS: enemedia; euphoriadev; hacked; hacker; hackers; hacking; haditha; hamdania; mediawar; stalinisttactics
Navigation: use the links below to view more comments.
first 1-5051-73 next last
The site of Freeper EUPHORIADEV was hacked. She has lost over 2 years worth of data.

Euphoriadev was covering the Haditha and Hamdania incident extensively

she has lost over 2 years worth of data

we do NOT believe it is the people who are claiming the hack

1 posted on 04/16/2008 8:38:49 PM PDT by RaceBannon
[ Post Reply | Private Reply | View Replies]

To: RaceBannon; stowaway; jjm2111; Mrs.LoneGOPinCT; underbyte; badbackman; Bigfitz; mcswan; ...

We do NOT believe it is the people who are claiming to have done it


2 posted on 04/16/2008 8:42:37 PM PDT by RaceBannon (Innocent until proven guilty; The Pendleton 8: We are not going down without a fight)
[ Post Reply | Private Reply | To 1 | View Replies]

To: RaceBannon

I assume you have everything backed up in a secure hard drive?


3 posted on 04/16/2008 8:43:44 PM PDT by Carling (It's Danny, Sir)
[ Post Reply | Private Reply | To 2 | View Replies]

To: RaceBannon

no off site backup?


4 posted on 04/16/2008 8:44:02 PM PDT by woofie
[ Post Reply | Private Reply | To 1 | View Replies]

To: RaceBannon; euphoriadev

Damn! Does she have any of her data saved to a back up system? How much of her data was posted here?


5 posted on 04/16/2008 8:44:20 PM PDT by Grizzled Bear ("Does not play well with others.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: RaceBannon

No off site backup or simple hardware backup?

If not, no soup for you.


6 posted on 04/16/2008 8:45:07 PM PDT by stravinskyrules (Why is it that whenever I hear a piece of music I don't like, it's always by Villa-Lobos?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: RaceBannon

I was also hoping there’s a backup. Also, if not, if any freepers might have any of it stored on their computers?


7 posted on 04/16/2008 8:45:21 PM PDT by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: RaceBannon
"she has lost over 2 years worth of data"

She never considered a backup?

8 posted on 04/16/2008 8:45:30 PM PDT by KoRn (CTHULHU '08 - I won't settle for a lesser evil any longer!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Carling; All

No, due to outside circumstances, the backups were not done for the last 2 months

and the backups that WERE done are hacked and destroyed


9 posted on 04/16/2008 8:47:37 PM PDT by RaceBannon (Innocent until proven guilty; The Pendleton 8: We are not going down without a fight)
[ Post Reply | Private Reply | To 3 | View Replies]

To: RaceBannon

So who’s claiming to have done it, and if they didn’t really do it, why do you think who you think is responsible is responsible? This is terrible news.


10 posted on 04/16/2008 8:48:30 PM PDT by rockinqsranch (Dems, Libs, Socialists...call 'em what you will...They ALL have fairies livin' in their trees.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: RaceBannon; All

Any WORDPRESS assistance is appreciated


11 posted on 04/16/2008 8:50:13 PM PDT by RaceBannon (Innocent until proven guilty; The Pendleton 8: We are not going down without a fight)
[ Post Reply | Private Reply | To 9 | View Replies]

To: RaceBannon

OK couple of things..

First off judging by the menus and the way the site was hacked.. this simply looks like an SQL injection hack. I’m assuming that site is run off wordpress or some other blog software. Its MIGHT not be a total loss. Get someone who knows SQL and let them look at your database.

Second.. I run a hosting company.. Our colo facility backs up our data nightly.. so if I were to be hacked, while costly I could get all my stuff back.. See if the site host that is hosting the site has a similar backup.

Let me know if I can help ya.. I’m no SQL guru but I might be able to give you some pointers.


12 posted on 04/16/2008 8:50:47 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 1 | View Replies]

To: eXe; euphoriadev

Your help is appreciated, please stand by! :)


13 posted on 04/16/2008 8:52:07 PM PDT by RaceBannon (Innocent until proven guilty; The Pendleton 8: We are not going down without a fight)
[ Post Reply | Private Reply | To 12 | View Replies]

To: RaceBannon

K Ill be up for a little bit longer.. Ill look at the site and see if I can figure anything out from just looking at it.


14 posted on 04/16/2008 8:53:24 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 13 | View Replies]

To: RaceBannon

Perhaps one of our wizards on FReeRepublic will be able to help and we have some fine ones.Nothing on computers is really lost. Let’s try to to contact some of them tomorrow. Please don’t worry too much someone will come up with something.


15 posted on 04/16/2008 8:54:11 PM PDT by mojo114
[ Post Reply | Private Reply | To 9 | View Replies]

To: RaceBannon

If you goto google and search the domain name with omitted results, you should be able to pull up the cached pages. I see there is quite a bit of cached text.


16 posted on 04/16/2008 8:55:42 PM PDT by It Aint Easy
[ Post Reply | Private Reply | To 1 | View Replies]

To: RaceBannon

http://web.archive.org/web/*/http://euphoricreality.com/

If it helps.


17 posted on 04/16/2008 8:57:46 PM PDT by perfect stranger (Nobama)
[ Post Reply | Private Reply | To 13 | View Replies]

To: RaceBannon

Keep me informed - I know a thing or two about Wordpress and will help however I can...


18 posted on 04/16/2008 8:59:16 PM PDT by Chameleon
[ Post Reply | Private Reply | To 1 | View Replies]

To: RaceBannon

Sorry to hear about this.

It looks like the site is hosted at a server farm that is running an old version of Apache web server with FrontPage extensions. Not advisible, in my opinion.


19 posted on 04/16/2008 8:59:24 PM PDT by HAL9000 ("If someone who has access to the press says something over and over again, people believe it"- B.C.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: It Aint Easy

Erm, looks like all the posts are actually there on the site still, they just included a post and their pic and text to it.

The database should be fine if a backup is made likely.

You might be able to delete everything, format the site, and re-upload the database (with their post removed) and it should be back to normal possibly.


20 posted on 04/16/2008 9:01:38 PM PDT by It Aint Easy
[ Post Reply | Private Reply | To 16 | View Replies]

To: It Aint Easy

Yeah if this is an SQL injection hack (Which I suspect) any any posts are appearing as deleted.. trust me.. they are in there.

I had a few older PHPNuke sites hit with this till I locked them down and good.


21 posted on 04/16/2008 9:04:40 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 20 | View Replies]

To: woofie

I had nightly backups on two servers. All are gone.

I had offsite backups. They are gone.

They got in all the way to the cpanel and deleted databases under two domains. I am currently working to try and get back into the site enough to fix it.

And no. I don’t think it was Islamics. Here’s a list of the recent hits on my site:

Oceanside California United States
gate23-sandiego.nmci.usmc.mil (138.162.140.53)

Oceanside California United States
gate25-sandiego.nmci.usmc.mil (138.162.140.55)

Halifax Nova Scotia Canada
iusr5.gov.ns.ca

Washington District Of Columbia United States
weppsb02.northropgrumman.com (155.104.37.18)

Washington District Of Columbia United States
70.106.14.174

Dhahran Ash Sharqiyah Saudi Arabia
166.87.170.50

Amman Jordan
86.108.92.154

Colorado Springs Colorado United States
fwcluster.mda.mil (140.32.120.188)

Halethorpe Maryland United States
firewall.arinc.com (144.243.4.2)

Montgomery Alabama United States
proxy.maxwell.af.mil (132.60.240.80)

Springfield Missouri United States
unassigned.fema.gov (71.252.64.50) FEMA.GOV

Gaithersburg Maryland United States
roanoke.ncsl.nist.gov (129.6.101.38) NIST

Gaithersburg Maryland United States
rhine.ncsl.nist.gov (129.6.101.11) NIST

Also entries from guildassociates.com. GO to that site.

Anyone who has ANY of my old material on the Pendleton 8, please email me asap. kit.lange@gmail.com

Thanks so much.


22 posted on 04/16/2008 9:07:37 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 4 | View Replies]

To: It Aint Easy

Agreed - looks like the site data is still there...Seems almost like they changed the header.php and index.php files in the theme (which should be in /wp-content/themes/yourtheme/.


23 posted on 04/16/2008 9:09:52 PM PDT by Chameleon
[ Post Reply | Private Reply | To 20 | View Replies]

To: eXe

Actually, they deleted exactly two years’ worth of posts. Nothing more.

Which is interesting, because two years ago this month is when I started writing about the Pendleton 8.

The user database is gone as well, along with categories, tags, and anything else even remotely containing anything about the Pendleton 8.

And for those saying “didn’t she think of a backup?”...of course I did. This isn’t my first rodeo, ya know. ;) They GOT the backups. I have nightly ones done. They’re all gone, as I mentioned.


24 posted on 04/16/2008 9:13:28 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 21 | View Replies]

To: RaceBannon

Try the Internet Wayback machine.

http://www.archive.org/web/web.php


25 posted on 04/16/2008 9:13:52 PM PDT by Kirkwood (Ask me again tomorrow.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: euphoriadev

I did some digging and see that you are hosted at ThePlanet.. I know for a fact that they do nightly backup of their servers.. so while its going to cost a bit.. any way you can call them and get it restored back to say.. last night? At least the site would be back.

As to the hack.. its a pretty common problem with wordpress.. seems there is a hack that exploits the input validation error in the wp-login.php file when processing a specially crafted variable, can be used to manipulate the “Forgotten Password” option.

Can you still log into the back end of wordpress or did they change your password as well?

I hope you can get the site up and running again.. I cant stand hackers no matter who they are.


26 posted on 04/16/2008 9:14:40 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 22 | View Replies]

To: euphoriadev
Is this what you are looking for? Cached Cached Cached etc...
27 posted on 04/16/2008 9:15:40 PM PDT by It Aint Easy
[ Post Reply | Private Reply | To 22 | View Replies]

To: euphoriadev

Ahh ok so they got offsite backups as well.. Damn.. that stinks.


28 posted on 04/16/2008 9:16:21 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 24 | View Replies]

To: eXe

I was finally able to get into the backend of the cpanel and from there I just altered the user tables to get back in to WP. Now I can look at the extent of the damage...they freaking GUTTED my site. Pieces of @&*^@#. ANYWAY.

It’ll take a few days, but I’m sure I can get the site running again at least.

Can someone please take screenshots of it as is before I start cleaning the mess? I have no capability on this computer of doing that.


29 posted on 04/16/2008 9:16:55 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 26 | View Replies]

To: euphoriadev

Gimme a sec.. Ill take a screenshot of the main page and post it on one of my servers for you to download.


30 posted on 04/16/2008 9:18:51 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 29 | View Replies]

To: mojo114
Registrant:
Domains by Proxy, Inc. DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States

Registered through: GoDaddy.com, Inc.
(http://www.godaddy.com)
Domain Name: EUPHORICREALITY.COM
Created on: 07-Jun-05
Expires on: 07-Jun-09
Last Updated on: 06-Apr-08

Administrative Contact:
Private, Registration EUPHORICREALITY.COM@domainsbyproxy.com
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
(480) 624-2599

Technical Contact:
Private, Registration EUPHORICREALITY.COM@domainsbyproxy.com Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
(480) 624-2599

Domain servers in listed order:
NS183.HOSTGATOR.COM
NS184.HOSTGATOR.COM

----------------------------

EUPHORICREALITY.COM
Hosted at HOSTGATOR WEB HOSTING

31 posted on 04/16/2008 9:20:04 PM PDT by Buddy B (MSgt Retired-USAF)
[ Post Reply | Private Reply | To 15 | View Replies]

To: eXe

I’m online with the hosting company now. They are quite embarrassed. They’re also about to lose a lot of business, as all the sites I admin for are hosted there.


32 posted on 04/16/2008 9:24:04 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 30 | View Replies]

To: euphoriadev
Ok images of the site (I needed to do a few.. heh it was a long page) are located on my west coast hosting box at

http://www.exedor.net/pics/euphoriadev

Is that good enough.. or do ya need more?

33 posted on 04/16/2008 9:28:54 PM PDT by eXe (Si vis pacem, para bellum)
[ Post Reply | Private Reply | To 32 | View Replies]

To: euphoriadev

Hostgator is pretty good in my experience...Don’t be too hasty....But then, LiquidWeb has been the best I’ve used.

I would be very interested in knowing more about the attack, and the best ways to avoid such attacks.


34 posted on 04/16/2008 9:30:30 PM PDT by Chameleon
[ Post Reply | Private Reply | To 32 | View Replies]

To: euphoriadev

Here is a description of a PHP injection attack with PodPress:

http://www.yugatech.com/blog/the-internet/hack-attack-in-progress/

The script example shows how the exploit tries several possible methods of acquiring the web server’s user ID.


35 posted on 04/16/2008 9:37:25 PM PDT by HAL9000 ("If someone who has access to the press says something over and over again, people believe it"- B.C.)
[ Post Reply | Private Reply | To 32 | View Replies]

To: euphoriadev
Your HTML is on the server but the HTML is changed slightly at top of the page.

Here is one page...take a look...

The Halls’ Rebuttal- Updated

36 posted on 04/16/2008 9:45:00 PM PDT by Buddy B (MSgt Retired-USAF)
[ Post Reply | Private Reply | To 32 | View Replies]

To: euphoriadev; RaceBannon; freema; mdittmar; RedRover; ShadowAce; Database; Incorrigible; ...

Ping for any assistance and cached info ASAP.

A wing and a prayer for our heroes and those defending them.


37 posted on 04/16/2008 10:07:35 PM PDT by The Spirit Of Allegiance (Public Employees: Honor Your Oaths! Defend the Constitution from Enemies--Foreign and Domestic!)
[ Post Reply | Private Reply | To 22 | View Replies]

To: eXe

Perfect. You’re a doll.


38 posted on 04/16/2008 10:07:51 PM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 33 | View Replies]

To: RaceBannon

BTTT.


39 posted on 04/16/2008 10:28:39 PM PDT by TBP
[ Post Reply | Private Reply | To 1 | View Replies]

To: John Robinson

ping


40 posted on 04/16/2008 11:05:58 PM PDT by The Spirit Of Allegiance (Public Employees: Honor Your Oaths! Defend the Constitution from Enemies--Foreign and Domestic!)
[ Post Reply | Private Reply | To 37 | View Replies]

To: woofie
As soon as you host it online, you have uploaded it “offsite” from your home. The provider has no backups of their network?

The provider has no responsibility for their network against hacked attacks?

41 posted on 04/16/2008 11:49:48 PM PDT by weegee (Religion is the opiate of the masses MARX1843 They get bitter, they cling to...religion OBAMA2008)
[ Post Reply | Private Reply | To 4 | View Replies]

To: eXe; euphoriadev
euphoriadev:

I noticed those screen shots show what appears to be Arabic.


A quick google search turned up this
(below is a firebug HTML copy/paste from the above link)


black.scorpion


Registered user # 13942
Your web site: http://www.13x17.org
Your e-mail address: amirianvahid@yahoo.com
Yahoo! Messenger ID: amirianvahid
MSN Messenger: vahid.amirian@hotmail.com
Location: IRAN

Signature:
:: Black Scorpion ::

User's current status: Off-line.

[ Send private message black.scorpion ]

Last 10 comments by black.scorpion:


Last 10 news submissions by black.scorpion:


The website of the 'black.scorpion' mentioned on hackinthebox.org seems to be entirely in Arabic.

So there are 4 major possibilities:

The person responsible is this 'black.scorpion' person
The person responsible is copying this 'black.scorpion' person
The person responsible is framing this 'black.scorpion' person
The 'black.scorpion' person is totally unrelated to the person who hacked your site.


So the question is, who would have a motive?
42 posted on 04/17/2008 12:10:47 AM PDT by Fichori (Truth is non-negotiable.)
[ Post Reply | Private Reply | To 33 | View Replies]

To: RaceBannon; 1stbn27; 2111USMC; 2nd Bn, 11th Mar; 68 grunt; A.A. Cunningham; ASOC; AirForceBrat23; ..

43 posted on 04/17/2008 2:53:21 AM PDT by freema (Proud Marine Niece, Daughter, Wife, Friend, Sister, Cousin, Mom and FRiend)
[ Post Reply | Private Reply | To 1 | View Replies]

To: freema

http://euphoricreality.com/


44 posted on 04/17/2008 2:58:57 AM PDT by freema (Proud Marine Niece, Daughter, Wife, Friend, Sister, Cousin, Mom and FRiend)
[ Post Reply | Private Reply | To 43 | View Replies]

To: Jim Robinson; kristinn; tgslTakoma; Doctor Raoul

ping


45 posted on 04/17/2008 3:00:49 AM PDT by freema (Proud Marine Niece, Daughter, Wife, Friend, Sister, Cousin, Mom and FRiend)
[ Post Reply | Private Reply | To 1 | View Replies]

To: RaceBannon
Innocent until proven guilty; The Pendleton 8: We are not going down without a fight

46 posted on 04/17/2008 3:13:59 AM PDT by freema (Proud Marine Niece, Daughter, Wife, Friend, Sister, Cousin, Mom and FRiend)
[ Post Reply | Private Reply | To 2 | View Replies]

To: freema; RaceBannon

UPDATE: They did it again. I had the site half back to normal (although missing two years’ of posts), and they freaking did it again.

On my way to the day job now...no time to fix. GUess it’s gotta stay this way for a bit.


47 posted on 04/17/2008 3:28:56 AM PDT by euphoriadev (http://euphoricreality.com - hosting The Front Line with Kit Lange)
[ Post Reply | Private Reply | To 45 | View Replies]

To: euphoriadev; RaceBannon; stowaway; jjm2111; Mrs.LoneGOPinCT; underbyte; badbackman; Bigfitz; ...
TO ALL:

THIS IS A LIST FROM EUPHORIADEV AS TO WHAT WAS DONE AND WHO RECENTLY VISITEDD HER SITE. NOTE ALL THE MILITARY SITES THAT VISITED HER SITE RECENTLY

I had nightly backups on two servers. All are gone.

I had offsite backups. They are gone.

They got in all the way to the cpanel and deleted databases under two domains. I am currently working to try and get back into the site enough to fix it.

And no. I don’t think it was Islamics. Here’s a list of the recent hits on my site:

Oceanside California United States
gate23-sandiego.nmci.usmc.mil (138.162.140.53)

Oceanside California United States
gate25-sandiego.nmci.usmc.mil (138.162.140.55)

Halifax Nova Scotia Canada
iusr5.gov.ns.ca

Washington District Of Columbia United States
weppsb02.northropgrumman.com (155.104.37.18)

Washington District Of Columbia United States
70.106.14.174

Dhahran Ash Sharqiyah Saudi Arabia
166.87.170.50

Amman Jordan
86.108.92.154

Colorado Springs Colorado United States
fwcluster.mda.mil (140.32.120.188)

Halethorpe Maryland United States
firewall.arinc.com (144.243.4.2)

Montgomery Alabama United States
proxy.maxwell.af.mil (132.60.240.80)

Springfield Missouri United States
unassigned.fema.gov (71.252.64.50) FEMA.GOV

Gaithersburg Maryland United States
roanoke.ncsl.nist.gov (129.6.101.38) NIST

Gaithersburg Maryland United States
rhine.ncsl.nist.gov (129.6.101.11) NIST

Also entries from guildassociates.com. GO to that site.

Anyone who has ANY of my old material on the Pendleton 8, please email me asap. kit.lange@gmail.com

Thanks so much.

48 posted on 04/17/2008 4:30:33 AM PDT by RaceBannon (Innocent until proven guilty; The Pendleton 8: We are not going down without a fight)
[ Post Reply | Private Reply | To 22 | View Replies]

To: euphoriadev

How did they access your offsite backups?


49 posted on 04/17/2008 4:42:20 AM PDT by Tribune7 (How is inflicting pain and death on an innocent, helpless human being for profit, moral?)
[ Post Reply | Private Reply | To 22 | View Replies]

To: euphoriadev
UPDATE: They did it again. I had the site half back to normal (although missing two years’ of posts), and they freaking did it again.

Anyway to tell who the last visit was from this time? If so, does it match any of the last visits from your previous list?

50 posted on 04/17/2008 4:55:08 AM PDT by tsmith130
[ Post Reply | Private Reply | To 47 | View Replies]


Navigation: use the links below to view more comments.
first 1-5051-73 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson