Additional Information on Downtime

   / Additional Information on Downtime #1  

Muhammad

Administrator
Moderator
Joined
Mar 21, 1998
Messages
20,336
Location
San Diego, CA
Tractor
None currently
Greetings,

As you may have experienced, TractorByNet.com and CountryByNet.com were out of service from around 5PM EST yesterday, through today at around 12:00PM EST. Such a prolonged outage is rare for our websites, and in this case I'll explain the cause.

At 5:00PM EST yesterday, an unauthorized person gained access to our server through a security hole, and installed alien programs that further compromised the server.

This type of attack is not targeted at us, but rather a random hack that happened to find our server's hole.

We discovered the breech approximately 60 seconds after it happened, and closed all upload scripts to prevent any major problems.

We took immediate action to secure our server, and had a new hard drive installed with a fresh operating system, which fixed the security hole through which access was gained to the server. The majority of the downtime was a result of having to recreate the entire drive on a new one. Nonetheless, we were able to straighten things out this morning.

Based on our analysis of the server logs, this has virtually no chance of having any effect on you as a user. Your accessing of this website does not expose you to any risks of being hacked or anybody gaining access to your computer.

We do not store any personal data on our server, for these very reasons. All passwords are encrypted. All purchases made through our online store are not stored on the server. The classifieds section operates on a separate server and was not subject to this particular security breech.

We have identified the origin point of where this person came from, and are still investigating to discover their identity. If we are able to find that out, all appropriate authorities and law enforcement agencies will be notified.

Every day, thousands of websites are hacked. Considering the potential problems a hacker can cause, we feel very fortunate that the problems were minor and isolated.

Again, we have secured the server and will be taking regular precautionary measures to prevent future security breeches.

As usual, I'd like to thank you all for being cooperative and helping us during this service outage.

Regards,
 
   / Additional Information on Downtime #2  
Muhammad,

When I click on reply, quote or edit under the forum New/Discussions and downtime 2-19 the buttons don't work. I also notice when I clik on to that forum there is an X on the box to the left??

Murph
 
   / Additional Information on Downtime
  • Thread Starter
#3  
Yes that's because I closed the thread from posting.
 
   / Additional Information on Downtime #4  
Hope you're able to identify and prosecute the sorry character who did it.
 
   / Additional Information on Downtime #5  
Frustrating isn't it Muhammad? /forums/images/graemlins/frown.gif

Like you had nothing better to do than spend a good portion of the day and night fixing something that someone else "broke" just for fun...it happended to me a few times, and I wanted to grab whoever did it by the neck and thrash them about a bit...but unfortunately I never knew who or why.... /forums/images/graemlins/mad.gif
 
   / Additional Information on Downtime #6  
Muhammad,

I just want you to know that I appreciated you staying up and diligently working on the problem like you did. I am not kidding when I got home last night and couldn't get on TBN I just didn't know what to do.

Anyway one question, and remember, I am new here, but ealier here I posted trouble trying to reply to a post and you told me you stopped that thread. Again, I am new, could not find anything in the FAQ's, but why and when do you stop threads?

Murph
 
   / Additional Information on Downtime #7  
THANKS for the quick fix. your site is so realible that when i could not get to it i thought my brand spankin new computer was at fault.
 
   / Additional Information on Downtime
  • Thread Starter
#8  
In this case I closed it because I started a new thread on the same topic.

In more common scenarios, we'll close threads when they are extremely long or just get repetitive and counter-productive.
 
   / Additional Information on Downtime #9  
I.m treasurer of a large helicopter group and we use Linux/Unix for our server system. I always thought the linux/unix was bullet proof against these type problems. This certainly is a wake up call for me.
 
   / Additional Information on Downtime #10  
IMARBUR,

Linux is certainly more secure than Windws. However, NOTHING is totally secure from a determined hacker. Not so long ago, most all hackers were highly skilled with computers and coding. Today, there are tools available for free at many places on the web, which can be used by anyone.

These "script kiddies" run automated scripts for hours, until they find a vulnerablity, and "poof" they're in. What happens next, depends... /forums/images/graemlins/frown.gif

You should visit The CERT web site CERT. The CERT Coordination Center (CERT/CC) is a center of Internet security expertise, located at the Software Engineering Institute, a federally funded research and development center operated by Carnegie Mellon University.

The info there is exhaustive, tons of links, and all the insight your team could want or need to "batten down the hatches" (as tight as possible). Guarding against hackers is considerably more problematic than it was even 18 months ago.
 
 
Top