It is currently Wed May 07, 2025 12:39 pm

All times are UTC - 8 hours [ DST ]




Post new topic Reply to topic  [ 18 posts ] 
Author Message
Offline
 Post subject: Go Sensations website hacked
Post #1 Posted: Wed Mar 14, 2012 9:27 pm 
Lives with ko

Posts: 289
Liked others: 7
Was liked: 42
Rank: 100
GD Posts: 100
The website got completely defaced today...

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #2 Posted: Thu Mar 15, 2012 1:00 am 
Dies in gote

Posts: 27
Liked others: 14
Was liked: 3
Rank: KGS 5k
It was already hacked on 21. february. I guess they don't care about security much.

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #3 Posted: Thu Mar 15, 2012 12:02 pm 
Lives with ko

Posts: 294
Liked others: 25
Was liked: 78
Rank: 6d
KGS: Dexmorgan
Wbaduk: c0nanbatt
Im actually quite surprised at this. Go4Go was affected the same way which can say this was pretty targeted.

Specially because there is really no motivation whatsoever to "hack" a site like GoSensations, which has absolutely no security value whatsoever.

_________________
Founder of Kaya.gs

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #4 Posted: Thu Mar 15, 2012 12:11 pm 
Lives with ko

Posts: 199
Liked others: 6
Was liked: 55
Rank: KGS 3 kyu
hermitek wrote:
It was already hacked on 21. february. I guess they don't care about security much.

That's likely not the issue here.
This are go websites after all, so they are not run by professional web developers and big companies. I wouldn't be surprised if they didn't know how the attackers got those privileges on the first place.

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #5 Posted: Thu Mar 15, 2012 12:14 pm 
Lives with ko

Posts: 289
Liked others: 7
Was liked: 42
Rank: 100
GD Posts: 100
Kaya.gs wrote:
Im actually quite surprised at this. Go4Go was affected the same way which can say this was pretty targeted.

Specially because there is really no motivation whatsoever to "hack" a site like GoSensations, which has absolutely no security value whatsoever.


That's why security by obscurity is a failed idea. I hope that is considered for your website.

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #6 Posted: Thu Mar 15, 2012 12:18 pm 
Gosei
User avatar

Posts: 1585
Location: Barcelona, Spain (GMT+1)
Liked others: 577
Was liked: 298
Rank: KGS 5k
KGS: RBerenguel
Tygem: rberenguel
Wbaduk: JohnKeats
Kaya handle: RBerenguel
Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
Security by obscurity is not the issue here (and usually in most web attacks): any web page online can be hacked. My Google account could be compromised, my VPS server could be compromised. And there's no obscurity roaming around: I have a Google account (obviously), and my VPS runs Arch Linux (although I use a high entropy, long passphrase)

_________________
Geek of all trades, master of none: the motto for my blog mostlymaths.net

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #7 Posted: Mon Mar 19, 2012 1:14 am 
Dies in gote

Posts: 48
Location: taipei
Liked others: 10
Was liked: 9
Rank: kgs 10 dgs 14
GD Posts: 15
KGS: brodie
DGS: brd
For those that have said that x is likely not the issue here, what do you suppose the issue was? A hacker practicing, goofing off, or a kid that lost his last game on kgs by a half moku and was pissed at the go world?

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #8 Posted: Mon Mar 19, 2012 2:45 am 
Gosei
User avatar

Posts: 1585
Location: Barcelona, Spain (GMT+1)
Liked others: 577
Was liked: 298
Rank: KGS 5k
KGS: RBerenguel
Tygem: rberenguel
Wbaduk: JohnKeats
Kaya handle: RBerenguel
Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
Brodie, it was probably someone running an automated server scanner probably tied to an automated hacking tool. If the server is unprotected, bam. No need for it to be a go player, know the site or anything: you just run it against a list of IPs and a bell rings when one server can be hacked.

Security by obscurity is a way to secure a site (or something) just not telling how it was done. For example, if you use a custom built operating system or webserver stack (one you did in your spare time), it is only secure because no-one has cared to look at how to crack it, not because it is top-notch secure.

_________________
Geek of all trades, master of none: the motto for my blog mostlymaths.net

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #9 Posted: Mon Mar 19, 2012 3:15 pm 
Oza
User avatar

Posts: 2508
Liked others: 1304
Was liked: 1128
RBerenguel wrote:
...No need for it to be a go player...


'Cept that his hack included a message that he had also hacked a series of go-related websites.

_________________
Patience, grasshopper.

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #10 Posted: Mon Mar 19, 2012 4:06 pm 
Gosei
User avatar

Posts: 1585
Location: Barcelona, Spain (GMT+1)
Liked others: 577
Was liked: 298
Rank: KGS 5k
KGS: RBerenguel
Tygem: rberenguel
Wbaduk: JohnKeats
Kaya handle: RBerenguel
Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
It was a message in the RSS feeds/subsections. I thought that "hacked" was referring to these parts. Also afaik KGS has never been hacked.

_________________
Geek of all trades, master of none: the motto for my blog mostlymaths.net

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #11 Posted: Sun Apr 01, 2012 12:02 pm 
Dies in gote

Posts: 48
Location: taipei
Liked others: 10
Was liked: 9
Rank: kgs 10 dgs 14
GD Posts: 15
KGS: brodie
DGS: brd
Seems to have happened again, but under the Tygem section, and this time with the signature of Anonymous. Unless, of course, this is an April Fool's joke by Go Sensations lampooning their security problems a little while back. I'm not sure, neither of them quite seem to make sense...

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #12 Posted: Sun Apr 01, 2012 6:55 pm 
Dies in gote
User avatar

Posts: 44
Liked others: 14
Was liked: 5
It's a legit breach. The intruder claiming to be "anonymous" (what a joke) is actually some noob who is in effect using gosensations to generate money using a bitcoin javascript miner. :roll:


edit: effectively > in effect


Last edited by balistic on Mon Apr 02, 2012 9:29 pm, edited 2 times in total.
Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #13 Posted: Sun Apr 01, 2012 11:19 pm 
Beginner

Posts: 9
Liked others: 1
Was liked: 1
Rank: 2 dan
balistic wrote:
It's a legit breach. The intruder claiming to be "anonymous" (what a joke) is actually some noob who is effectivly using gosensations to generate money using a bitcoin javascript miner. :roll:


Noob question: what does this mean? How can those "anonymus we are legion"-posts make money?

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #14 Posted: Mon Apr 02, 2012 1:24 am 
Dies with sente

Posts: 72
Liked others: 1
Was liked: 24
Rank: KGS 2k
KGS: cata
They can't make money, it's FUD. This strategy would be less effective than changing the homepage to a Paypal link that says "please send me money, thanks."

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #15 Posted: Mon Apr 02, 2012 2:02 am 
Beginner

Posts: 9
Liked others: 1
Was liked: 1
Rank: 2 dan
So it is not effectively generating any money then?

I am still curious about what the strategy is. How does someone believe he will make money by posting on gosensations, I can't come up with a strategy that would work even in the imagination of the most delusional. I have no idea about any of this. It's as mysterious to me like ko to a 30 kyu.

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #16 Posted: Mon Apr 02, 2012 2:14 am 
Dies with sente

Posts: 72
Liked others: 1
Was liked: 24
Rank: KGS 2k
KGS: cata
The strategy is running code on your browser to slowly mine bitcoins, but if you don't already understand the idea of Bitcoin, be prepared to spend some time figuring it out. It's ineffective because the processing power of all the computers visiting the hacked page isn't likely to amount to a penny worth of bitcoins.

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #17 Posted: Mon Apr 02, 2012 2:35 am 
Beginner

Posts: 9
Liked others: 1
Was liked: 1
Rank: 2 dan
I see, thanks for the explanation. This thing got me wondering enough to actually make a post here, even though discussing go was of course my original intention when I first registered.

Top
 Profile  
 
Offline
 Post subject: Re: Go Sensations website hacked
Post #18 Posted: Fri Sep 07, 2012 6:42 am 
Gosei
User avatar

Posts: 1449
Liked others: 1562
Was liked: 140
Rank: KGS 6k
GD Posts: 892
Kaya.gs wrote:
Im actually quite surprised at this. Go4Go was affected the same way which can say this was pretty targeted.

Specially because there is really no motivation whatsoever to "hack" a site like GoSensations, which has absolutely no security value whatsoever.


Just went to go4go, and found a spam post there, but found no way to report it.

_________________
a1h1 [1d]: You just need to curse the gods and defend.
Good Go = Shape.
Associação Portuguesa de Go

Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 18 posts ] 

All times are UTC - 8 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group