Go Sensations website hacked

General conversations about Go belong here.
badukJr
Lives with ko
Posts: 289
Joined: Sat Jan 07, 2012 1:00 pm
Rank: 100
GD Posts: 100
Has thanked: 7 times
Been thanked: 42 times

Go Sensations website hacked

Post by badukJr »

The website got completely defaced today...
hermitek
Dies in gote
Posts: 27
Joined: Tue Jan 25, 2011 3:25 am
Rank: KGS 5k
GD Posts: 0
Has thanked: 14 times
Been thanked: 3 times

Re: Go Sensations website hacked

Post by hermitek »

It was already hacked on 21. february. I guess they don't care about security much.
Kaya.gs
Lives with ko
Posts: 294
Joined: Fri Aug 12, 2011 10:52 am
Rank: 6d
GD Posts: 0
KGS: Dexmorgan
Wbaduk: c0nanbatt
Has thanked: 25 times
Been thanked: 78 times
Contact:

Re: Go Sensations website hacked

Post by Kaya.gs »

Im actually quite surprised at this. Go4Go was affected the same way which can say this was pretty targeted.

Specially because there is really no motivation whatsoever to "hack" a site like GoSensations, which has absolutely no security value whatsoever.
Founder of Kaya.gs
uPWarrior
Lives with ko
Posts: 199
Joined: Mon Jan 17, 2011 1:59 pm
Rank: KGS 3 kyu
GD Posts: 0
Has thanked: 6 times
Been thanked: 55 times

Re: Go Sensations website hacked

Post by uPWarrior »

hermitek wrote:It was already hacked on 21. february. I guess they don't care about security much.

That's likely not the issue here.
This are go websites after all, so they are not run by professional web developers and big companies. I wouldn't be surprised if they didn't know how the attackers got those privileges on the first place.
badukJr
Lives with ko
Posts: 289
Joined: Sat Jan 07, 2012 1:00 pm
Rank: 100
GD Posts: 100
Has thanked: 7 times
Been thanked: 42 times

Re: Go Sensations website hacked

Post by badukJr »

Kaya.gs wrote:Im actually quite surprised at this. Go4Go was affected the same way which can say this was pretty targeted.

Specially because there is really no motivation whatsoever to "hack" a site like GoSensations, which has absolutely no security value whatsoever.


That's why security by obscurity is a failed idea. I hope that is considered for your website.
User avatar
RBerenguel
Gosei
Posts: 1585
Joined: Fri Nov 18, 2011 11:44 am
Rank: KGS 5k
GD Posts: 0
KGS: RBerenguel
Tygem: rberenguel
Wbaduk: JohnKeats
Kaya handle: RBerenguel
Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
Location: Barcelona, Spain (GMT+1)
Has thanked: 576 times
Been thanked: 298 times
Contact:

Re: Go Sensations website hacked

Post by RBerenguel »

Security by obscurity is not the issue here (and usually in most web attacks): any web page online can be hacked. My Google account could be compromised, my VPS server could be compromised. And there's no obscurity roaming around: I have a Google account (obviously), and my VPS runs Arch Linux (although I use a high entropy, long passphrase)
Geek of all trades, master of none: the motto for my blog mostlymaths.net
brodie
Dies in gote
Posts: 48
Joined: Mon May 02, 2011 3:10 pm
Rank: kgs 10 dgs 14
GD Posts: 15
KGS: brodie
DGS: brd
Location: taipei
Has thanked: 10 times
Been thanked: 9 times

Re: Go Sensations website hacked

Post by brodie »

For those that have said that x is likely not the issue here, what do you suppose the issue was? A hacker practicing, goofing off, or a kid that lost his last game on kgs by a half moku and was pissed at the go world?
User avatar
RBerenguel
Gosei
Posts: 1585
Joined: Fri Nov 18, 2011 11:44 am
Rank: KGS 5k
GD Posts: 0
KGS: RBerenguel
Tygem: rberenguel
Wbaduk: JohnKeats
Kaya handle: RBerenguel
Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
Location: Barcelona, Spain (GMT+1)
Has thanked: 576 times
Been thanked: 298 times
Contact:

Re: Go Sensations website hacked

Post by RBerenguel »

Brodie, it was probably someone running an automated server scanner probably tied to an automated hacking tool. If the server is unprotected, bam. No need for it to be a go player, know the site or anything: you just run it against a list of IPs and a bell rings when one server can be hacked.

Security by obscurity is a way to secure a site (or something) just not telling how it was done. For example, if you use a custom built operating system or webserver stack (one you did in your spare time), it is only secure because no-one has cared to look at how to crack it, not because it is top-notch secure.
Geek of all trades, master of none: the motto for my blog mostlymaths.net
User avatar
daal
Oza
Posts: 2508
Joined: Wed Apr 21, 2010 1:30 am
GD Posts: 0
Has thanked: 1304 times
Been thanked: 1128 times

Re: Go Sensations website hacked

Post by daal »

RBerenguel wrote: ...No need for it to be a go player...


'Cept that his hack included a message that he had also hacked a series of go-related websites.
Patience, grasshopper.
User avatar
RBerenguel
Gosei
Posts: 1585
Joined: Fri Nov 18, 2011 11:44 am
Rank: KGS 5k
GD Posts: 0
KGS: RBerenguel
Tygem: rberenguel
Wbaduk: JohnKeats
Kaya handle: RBerenguel
Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
Location: Barcelona, Spain (GMT+1)
Has thanked: 576 times
Been thanked: 298 times
Contact:

Re: Go Sensations website hacked

Post by RBerenguel »

It was a message in the RSS feeds/subsections. I thought that "hacked" was referring to these parts. Also afaik KGS has never been hacked.
Geek of all trades, master of none: the motto for my blog mostlymaths.net
brodie
Dies in gote
Posts: 48
Joined: Mon May 02, 2011 3:10 pm
Rank: kgs 10 dgs 14
GD Posts: 15
KGS: brodie
DGS: brd
Location: taipei
Has thanked: 10 times
Been thanked: 9 times

Re: Go Sensations website hacked

Post by brodie »

Seems to have happened again, but under the Tygem section, and this time with the signature of Anonymous. Unless, of course, this is an April Fool's joke by Go Sensations lampooning their security problems a little while back. I'm not sure, neither of them quite seem to make sense...
User avatar
balistic
Dies in gote
Posts: 44
Joined: Sun Dec 11, 2011 1:55 am
GD Posts: 0
Has thanked: 14 times
Been thanked: 5 times

Re: Go Sensations website hacked

Post by balistic »

It's a legit breach. The intruder claiming to be "anonymous" (what a joke) is actually some noob who is in effect using gosensations to generate money using a bitcoin javascript miner. :roll:


edit: effectively > in effect
Last edited by balistic on Mon Apr 02, 2012 9:29 pm, edited 2 times in total.
Grisalger
Beginner
Posts: 9
Joined: Mon Oct 24, 2011 11:06 am
Rank: 2 dan
GD Posts: 0
Has thanked: 1 time
Been thanked: 1 time

Re: Go Sensations website hacked

Post by Grisalger »

balistic wrote:It's a legit breach. The intruder claiming to be "anonymous" (what a joke) is actually some noob who is effectivly using gosensations to generate money using a bitcoin javascript miner. :roll:


Noob question: what does this mean? How can those "anonymus we are legion"-posts make money?
cata
Dies with sente
Posts: 72
Joined: Sun Sep 25, 2011 9:39 pm
Rank: KGS 2k
GD Posts: 0
KGS: cata
Has thanked: 1 time
Been thanked: 24 times

Re: Go Sensations website hacked

Post by cata »

They can't make money, it's FUD. This strategy would be less effective than changing the homepage to a Paypal link that says "please send me money, thanks."
Grisalger
Beginner
Posts: 9
Joined: Mon Oct 24, 2011 11:06 am
Rank: 2 dan
GD Posts: 0
Has thanked: 1 time
Been thanked: 1 time

Re: Go Sensations website hacked

Post by Grisalger »

So it is not effectively generating any money then?

I am still curious about what the strategy is. How does someone believe he will make money by posting on gosensations, I can't come up with a strategy that would work even in the imagination of the most delusional. I have no idea about any of this. It's as mysterious to me like ko to a 30 kyu.
Post Reply