Explaining Our Downtime

Discussion in 'Announcements' started by Tweaker, Aug 8, 2009.

    As you may have noticed, Sonic Retro has been down the past few days. We figure we owe you guys an explanation, so here's the scoop:

    At about 11:20AM EST Thursday morning, we found ourselves under attack by an unknown hacker. He deleted the entirety of the forum's post database, deleted the front page news entries, and proceeded to slowly edit the main page to be branded as a site called "REALLY Sonic." The page that replaced the site's main index can be seen here; one of our various retaliation pages can be found <a href="!%20ZOMBIES!%20AHEAD!!!%20Final.htm" target="_blank">here.</a>

    After several hours of us deliberating in the staff IRC channel sifting through Apache logs, FTP access logs, and various other logs full of raw numbers and timestamps, we eventually found our culprit—a member by the name of Shibunoa. In addition to his IP being found in the access logs for the server, his useragent—and his apparent use of NetBSD—also helped concrete his involvement in the attack. We don't know if anyone else was ever involved, but it can be safely assumed that the actual attack was his responsibility.

    Once we found out how he got in, we worked on fixing the exploit. This was drx's job, as the vulnerability was a result of the nature of his "Sonic Dev FTP" service, in addition to Apache's apparent sentient access over the files on this server. He changed the password to the FTP, but he also made a small oversight—since Shibunoa also knew the URL for the HTTP section of the FTP, he was also able to get the new password listed on this page. While the FTP has since been deleted, the damage was soon to hit us harder than it did the first time.

    After restoring backups of all of our lost data, we got hit a second time at the same exact time of day as the first. This time, though, we weren't as lucky—not only did he delete the SQL for the forums and the wiki, but he also wiped the images directory, taking literally thousands of files hosted on our wiki with it. Normally this wouldn't be a problem—after all, we had been in the process of making more backups for such an occasion—but Scarred Sun hadn't finished making a full backup, and only had 1,000 or so of the 10,000+ files that were originally in the directory. In addition, the uploads directory on the forum suffered the same fate. As of now, we've managed to re-obtain about 1,500 of the lost files.

    In order to combat this potential staggering loss, GerbilSoft stepped up to the plate and downloaded an image of the entire CulTNET HDD, running several diagnostic tools that would hopefully be able to scan the drive for any deleted files that might have still existed on the disc. After hours upon hours of downloading, transferring, and analyzing the disc image, however, it appeared that none of the deleted files existed on the drive any longer. Despite this, however, GerbilSoft's willingness, effort, and expertise have culminated in him becoming the newest Sonic Retro administrator.

    Here's the bright side to all this—while the WordPress posts no longer exist outside of the realms of Google cache, we have lost absolutely no forum posts or wiki pages. In terms of textual data, everything is still completely intact and will remain so.

    Members are encouraged to simply re-upload any avatars or photos that were once present in the uploads directory on the forum, and they are also encouraged—with an ingenious method that Gerbil himself devised—to scan their hard drives for any files that may have once been present on the wiki. More information will be available in a separate announcements thread soon as to how exactly you can help the wiki restoration effort.

    Here are the people you should thank for helping get this place back online:
    • Xkeeper, who worked his ass off from the start to help combat the hack as it happened and sifted through logs upon logs to help find the culprit.
    • drx, who provided a ton of insight and used the access he had to help us figure out what happened and how it happened.
    • Saz, who came in to save the day and deliver the exact logs we needed to ultimately identify Shibunoa as the hacker
    • Scarred Sun, who had thankfully just made full SQL backups the night before for both the forum and wiki, allowing us to come out completely unscathed when it comes to forum and wiki text.
    • nineko, who did his absolute best to help us with both his technical and legal expertise, and whose diligent work on the wiki—and the upcoming restore effort—in both this situation and past situations, has been extremely invaluable.
    • GerbilSoft, who worked his ass off—and still is—to help us keep everything as intact as possible, and for being more than willing to help provide technical advisory when we need it.
    • GeneHF, for talking as much shit as ever and keeping our spirits up.
    • Myself, for beating the shit out of people in #retro and trying to explore as many possibilities as possible in working this situation out. I don't like tooting my own horn, though, so I'll let the others speak for me if they want...
    All in all, this whole debacle has been completely ridiculous and unnecessary, and we all would have been better off not going through it. Still, we plan on sticking things through and not letting this phase us. With your help, Sonic Retro will come out of this situation completely unscathed—now and in the future.

    And for Shibunoa... well, we only have one thing to say to you:

    <div align='center'>[​IMG]</div>

    Keep it classy, Retro! :thumbsup:
    I have to say, good job to all of you for getting things back up. I can't begin to say how amazed I am with how well you guys did.

    Also, seeing as Gerbil is now Admin, we have all collectively lost the game. :v: In other words, congrats

    As for Shibby, well... embedded music FTW.
    I'm going to laugh if we somehow get struck a third time.
    Shibunoa should really hack something worthwhile like a bank or such. At the end of the day, you've just disrupted a Sonic the Hedgehog website. I mean FFS, grow up and leave the house sometime.
    Thank fuck this is over.
    It's good that SS made a backup a few days ago, it's unfortunate over the images situation yet it's cool that GerbilSoft is able to fix the stuff. I don't like shit going down the drain.
    Oh and Shibunoa, fuck you too.
    Dang! Why would anyone want to attack Sonic Retro like that? That's just messed up.

    Good job for everyone that helped bring Sonic Retro back to life. I am impressed.
    The way Shibunoa was pretty despicable too. Without going into specifics, he got in using something I gave out in good faith, to my own users, to help the community progress. He took advantage of it (in a pretty dumb way, btw). This is not hacking, this is just lame (IMO even worse than being a script kiddie). So don't go thinking he's some kind of great hacker for taking Retro down. A more appropriate (albeit a bit archaic) word would be 'lamer'.

  8. I hope this never happens again. Congrats to you, GS, on becoming an admin.. Thanks all who helped to get the site back on track.
    Do we know the exact purpose of this hack, though? It seems random.. Oh well, it's back, and that's what matters.

    You've done it now. Daily rick/duckrolls, jokes about hitler, endless techno-babble. I hope you're happy. :colbert:

    But in all seriousness, thanks to all the admins and sysops that made sure this wasn't more of a disaster than it already was.
    Haha, as a couple other people have said before in various places, why try to co-opt an existing site like this? Why not create your own.

    I will never fully understand the motivation of the people who do this (well, I assume it's based around a certain level of self-importance, but I mean that it's ridiculously irrational).

    In any case, seems like some grumpy people won't have anything to do with the site any more, so they don't have to worry about the atmosphere around here anyway.
  11. Congrats to all who got us out of that rut. I hope it never happens again.

    And a bigger Congrats to Gerbil for his new status. :thumbsup:
  12. In relation to the site this "Shibunoa" made...

    What the HELL kind of a name is "REALLY Sonic"?
    Start from the top rather than in a cave with a box of scraps.
    Shibouna... I can't believe that I was friends with him on MSN, years ago (he was Tails92 then). I had no idea he could program. Heck, he even made me an admin on his own forum, for some reason. Sonic Team Fans, I think it was called. Damn that betrayer and hacker. If only they used hacking for good...
    This is the most horrible coincidence and friendly memory, EVER. :(
    I searched for the forum, nothing. There is another forum he made as well, something to-do with Pokemon.
    Good luck on punishing that moron, Admins, and keeping this site safer.
    Fuck it Member
    My point was more that it was tried before and in the end deemed a failure.
    I'm not very mad at Shibunoa. Not that much was lost, and the whole affair is pretty DIRTY, VULGAR LANGUAGE hilarious.
    Quiet you, I was making an Iron Man reference.
    Utterly shocking behavior. I also question the motive, I doubt it was anything to do with the administration, just jealousy and a destructive nature. Hacking (using that term as loosly as possible) the site was bad enough, but deleting the images folder, I mean really?

    Congratulations to GerbilSoft on becoming Administrator. Very imaginative idea of pulling down the whole disk image to analyze.

    Also, Hello everyone :)
    Ah hell. Images.
    Well, I guess my heavy use of filters and non-optimisation is sort of vindicated now. :v:

