![]() |
|
|
|
#93 | |
|
Senior LCF Member
Join Date: Mar 2007
Location: Austin, TX
Posts: 288
Gallery: LChottie07
Stats: Maintaining and adjusting
WOE: God's Way
Start Date: October 2, 2006
|
Quote:
what a day... ok... so #1 I tried to get on early this morning, however the site wanted me to re-register w/ a new username/password and I didn't think it was prudent to do that so I left... so NO I was never logged into the site. So far... the admins who's user names and profiles that have been used (that I know of) are Mary (Cartbabe), Jimmy, and now I guess myself... (What is the common denominator between all those people??? I wonder... ) This is just getting downright irritating and creepy. ![]() On another note.... I need for anyone who is a member or former member of KK that lives in the San Diego COUNTY to please contact John at the email address listed in The Kimkins Lawsuit Blog (you do not have to even be a member of the lawsuit yet). This is important, so he needs to hear from you as quickly as possible. Thanks everyone for your hard work!!!
__________________
The Road Less Traveled is its own Journey that we take, one step at a time, and it doesn't end on a number. LC Hottie - Christin D.I.E.T Discover your triggers; Invent new ways of thinking; Extinguish your old perceptions; Transform your life |
|
|
|
|
|
#95 | |
|
Senior LCF Member
Join Date: Oct 2006
Location: New Egypt, NJ
Posts: 824
Gallery: Barbara B
WOE: Dr. Richard Bernstein
|
Quote:
|
|
|
|
|
|
#96 | |
|
Senior LCF Member
Join Date: Oct 2006
Location: New Egypt, NJ
Posts: 824
Gallery: Barbara B
WOE: Dr. Richard Bernstein
|
Quote:
|
|
|
|
|
|
#97 | |
|
Senior LCF Member
Join Date: May 2004
Location: The Great Lakes State
Posts: 567
Gallery: jeanessa
Stats: 289.6/289.6/???
WOE: Atkins
Start Date: 4/19/08
|
Quote:
Calling San Diego County… Kimkinslawsuit’s Weblog |
|
|
|
|
|
#98 | |
|
Senior LCF Member
Join Date: Oct 2006
Location: New Egypt, NJ
Posts: 824
Gallery: Barbara B
WOE: Dr. Richard Bernstein
|
Quote:
![]() |
|
|
|
|
|
#99 |
|
MAJOR LCF POSTER!
Join Date: Sep 2007
Location: Alabama
Posts: 1,364
Gallery: Mayberryfan
Stats: 255/204/150
WOE: PPLP
Start Date: June 6, 2007
|
Christin!Hope a former KK member from San Diego turns up soon. And, thanks for letting us know what John needs. You know we'll try our best to get it for him. |
|
|
|
|
#100 |
|
MAJOR LCF POSTER!
Join Date: Sep 2007
Location: Alabama
Posts: 1,364
Gallery: Mayberryfan
Stats: 255/204/150
WOE: PPLP
Start Date: June 6, 2007
|
Former KK members
It might not be a bad idea to go ahead and change your passwords if you use the same one or a very similar one to your Kk login.
It can't hurt! |
|
|
|
|
#102 | |
|
Senior LCF Member
Join Date: Jul 2006
Location: San Diego, CA
Posts: 393
Gallery: vernswifevickie
Stats: 216/200/150
WOE: Making Low Carb a Lifestyle
Start Date: September 2005
|
Quote:
|
|
|
|
|
|
#103 | |
|
Blabbermouth!!!
Join Date: Jul 2004
Location: NJ
Posts: 5,889
Gallery: Mariasol
Stats: 138/124/125
WOE: LC
Start Date: 2/04
|
Quote:
I have a high speed connection and still after 3 minutes the page is not fully loaded. Perhaps that's your problem. |
|
|
|
|
|
#104 | |
|
Blabbermouth!!!
Join Date: Jul 2004
Location: NJ
Posts: 5,889
Gallery: Mariasol
Stats: 138/124/125
WOE: LC
Start Date: 2/04
|
Quote:
IP address country: ip address flag Canada IP address state: Quebec IP address city: Montreal IP postcode: h1w1g4 IP address latitude: 45.500000 IP address longitude: -73.583298 ISP of this IP [?]: Groupe iWeb Technologies Organization: iWeb Dedicated HD Host of this IP: [?]: ip-64-15-129-25.static.privatedns.com [Whois] Local Time of this IP country: 2008-04-09 10:00 |
|
|
|
|
|
#105 | |
|
Senior LCF Member
Join Date: Oct 2006
Location: New Egypt, NJ
Posts: 824
Gallery: Barbara B
WOE: Dr. Richard Bernstein
|
Quote:
![]() |
|
|
|
|
|
#106 |
|
Junior LCF Member
|
I think the mechanism for attack was that he had an unprotected version of the open source phpbb board installed on his site, which had the feature enabled to allow files to be attached to a posting (early 2.2 versions of this mod and early betas of the 3.0 version had this vulnerability... although in subsequent issues of both it is resolved ). When I first went to his site (after seeing the alert here), I saw that there was a php exploit file attached in the post about marijuana. My virus alert mechanism (avira) warned me immediately that the php file attached there had a known exploit. I started to download it (just to see the code, but I decided against it... because I have seen enough of them to know how they work). Php files are programs which will run on your server (when addressed through any remote browser), unless there are protections inside of the file upload and display directories to prevent execution. I am sure his system admin has found all that now and knows the particulars of how to prevent it. Apparently, the hacker used the php file attachment feature in a post and then after it was attached, he simply clicked on the file name (with the php extension) running that program on the server. It more than likely is designed to ransack the database downloading (or maybe printing to the screen) all of the admin names and passwords, plus all the members' email addresses (hence the spam virus attack). Then the attacker could have simply signed in as an admin and deleted everything and did his emailing with other types of virus attachments to attempt to get information from your personal machines. .
So, my guess it that this is not based on a compromise of passwords provided to another site (like Kimkins), but a simple exploit, similar to what phpbb boards all over the world are experiencing (the evil doers search with robots to find phpbb boards with this vulnerability). So, I think you can put the "big conspiracy" theory to rest, but, of course, it was still a wicked act, just the same. I have several private phpbb boards on my servers and have experienced many attacks over the years. I finally separated out all file attachment features on my boards to upload to separate locations, (because of this weakness) although from what I understand, the latest mods (available from the phpbb site) are totally secure and stop any future exploits.
__________________
All my posts in one place: http://samredman.com/kimkinsposts Last edited by samredman : 04-09-2008 at 01:40 PM. |
|
|
|
|
#108 |
|
Junior LCF Member
|
Awakened --
My guess is that Jimmy did what a lot of people do... used the same login and password for his private email and paypal, as he did for his admin access. When I first looked at his site and glanced at his post... it showed (sort of like a signature) all the info for all the admins right there for anyone to see, which is a pretty good indication that this was probably done with the mechanism I described. Everyone on that admin list... which I still have probably somewhere in my cache (as does everyone who peeked at the site before it was closed off) should change all usernames and passwords on anything with personal information. Last edited by samredman : 04-09-2008 at 01:37 PM. |
|
|
|
|
#110 | |
|
Senior LCF Member
|
Quote:
I mostly lurk on here and on Jimmy's site. I had the same experience as Christin. Scary. Keep up the good works, ducks. I am in awe of all the work you have done. Mary |
|
|
|
|
|
#112 |
|
Junior LCF Member
|
Any qualified system administrator (guy or gal certified on server management) would figure this out in literally less than 30 seconds. They don't need advice (I can assure you). This is what guys like me talk about on tech boards.
Last edited by samredman : 04-09-2008 at 01:50 PM. |
|
|
|
|
#113 | |||
|
Committed to Succeed
Join Date: Jan 2004
Location: Emerald City
Posts: 14,583
Gallery: Magicsmom
Stats: 282/212.5/140
WOE: Seeing a nutritionist who believes in low carb!
Start Date: Off & On (mostly on) since January 2004
|
Quote:
![]() Quote:
Quote:
![]() ![]() ![]() |
|||
|
|
|
|
#114 | |
|
MAJOR LCF POSTER!
|
Quote:
Return-Path: <lcc@hd-t3246cl.privatedns.com> Received: from hd-t3246cl.privatedns.com (ip-64-15-129-25.static.privatedns.com [64.15.129.25]) by mx.google.com with ESMTP id e17si103632qbe.1.2008.04.09.05.30.25; Wed, 09 Apr 2008 05:30:29 -0700 (PDT) Received-SPF: pass (google.com: domain of lcc @ hd-t3246cl.privatedns.com designates 64.15.129.25 as permitted sender) client-ip=64.15.129.25; Authentication-Results: mx.google.com; spf=pass (google.com: domain of lcc @ hd-t3246cl.privatedns.com designates 64.15.129.25 as permitted sender) smtp.mail=lcc @ hd-t3246cl.privatedns.com Received: from lcc by hd-t3246cl.privatedns.com with local (Exim 4.63) (envelope-from <lcc @ hd-t3246cl.privatedns.com>) id 1JjZRF-0007I6-P2; Wed, 09 Apr 2008 08:30:05 -0400 what I gather is the hacker used JM's own system to send these so they will be traced back to him...
__________________
Kimkins Scam Kimkins Class Action Lawsuit Diary of a Mad Housewife Back Across The Line my personal blog Last edited by BamaGal : 04-09-2008 at 02:39 PM. |
|