<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ugh!!'s Greymatter Honeypot &#187; cruelcard</title>
	<atom:link href="http://www.u-g-h.com/tag/cruelcard/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.u-g-h.com</link>
	<description>Distracting the Mind with Information Overload</description>
	<lastBuildDate>Wed, 08 Feb 2012 23:39:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Cruelcard Post-mortem: How my Joomla site got hacked</title>
		<link>http://www.u-g-h.com/2008/09/08/cruelcard-post-mortem-how-my-joomla-site-got-hacked/</link>
		<comments>http://www.u-g-h.com/2008/09/08/cruelcard-post-mortem-how-my-joomla-site-got-hacked/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 18:26:17 +0000</pubDate>
		<dc:creator>Owen</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[cruelcard]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Joomla]]></category>

		<guid isPermaLink="false">http://www.u-g-h.com/?p=2489</guid>
		<description><![CDATA[So, I decided to have a play with Joomla a couple of weeks ago as one of the first websites I ever built Cruelcard needed to be moved away from my Windows host and had to be rebuilt in something other than ASP. I&#8217;ve been wanting an excuse to play with Joomla and well, here [...]]]></description>
			<content:encoded><![CDATA[<div style="float:right;margin-left:5px;"><a  title="hacker" rel="nofollow" href="http://www.flickr.com/photos/35034345551@N01/241180672/" target="_blank"><img src="http://farm1.static.flickr.com/84/241180672_704377ffc2_m.jpg" border="0" alt="hacker" /></a></div>
<p>So, I decided to have a <a  href="http://www.u-g-h.com/2008/08/03/playing-with-joomla/">play with Joomla</a> a couple of weeks ago as one of the first websites I ever built <a  href="http://www.cruelcard.com">Cruelcard</a> needed to be moved away from my Windows host  and had to be rebuilt in something other than ASP. I&#8217;ve been wanting an excuse to play with <a  href="http://www.joomla.org/">Joomla</a> and well, here it was. I built the site, put up the plugins I wanted, themed it and lo and behold had a brand spanking new website. Everything was good .. the sun was shining etc .. until last night ..</p>
<p>Last night I logged in to find that the site had been defaced. I should have taken a screenshot to show you, but I just overwrite the message with a &#8220;Will be back soon&#8221; message. I left everything as it was so that I could find out exactly how the hackers broke into my site. Today I had some time, so I went through my logs and this is what I learnt:</p>
<ul>
<li>The hacker was from <a  href="http://en.wikipedia.org/wiki/Turkey">Turkey</a>. Well, I knew that as the defacement was in Turkish but his IP address (85.110.114.98) confirmed that.</li>
<li>He was specifically looking for Joomla sites to target. The first referrer I have is: <strong>http://go.mail.ru/search?&amp;q=Powered+by+Joomla%21.+Valid+XHTML+and+CSS&amp;no_morph=n&amp;sf=480</strong>. You can see exactly what he was looking for, but seeing I&#8217;m on page 49, he must have gone through quite a few other sites first.</li>
<li>He gained access to the site by resetting the admin password. I actually found the <a  href="http://www.milw0rm.com/exploits/6234">exploit in Milworm</a> (possibly this one anyway). This coupled by the fact that the sequence of commands were all placed in under a minute suggests that this was a scripted attack.</li>
<li>Once the admin password was changed, the hacker went straight to the admin site and did whatever he needed to do.</li>
<li>The hacker also seems to have uploaded some media using the Media Manager which suggests I need a proper rebuild of the whole thing.</li>
</ul>
<p>It was pretty interesting to follow the <a  href="http://en.wikipedia.org/wiki/Hacker_(computer_security)">hacker</a>&#8216;s footsteps. I will need to rebuild with a newer version of the software that blocks that hole, but I am partly responsible because I didn&#8217;t change the default administrator&#8217;s name. If I had done that, I might have had a bit of protection. I&#8217;m not going to abandon Joomla just because of this but it has certainly highlighted the importance of <a  href="http://askowen.info/2008/06/creating-a-disaster-recovery-plan-for-your-wordpress-blog/">backups</a> to me!</p>
<p>If anyone&#8217;s interested, you can read through the log: <a  href="http://www.u-g-h.com/wp-content/uploads/2008/09/cruelcardcom-hack.txt">cruelcardcom-hack</a></p>
<p><em>Note to self: Read more about <a  href="http://www.milw0rm.com/">Milw0rm</a> and don&#8217;t watch so much <a  href="http://www.imdb.com/title/tt0247082/">CSI</a></em></p>
<p><a  class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.u-g-h.com%2F2008%2F09%2F08%2Fcruelcard-post-mortem-how-my-joomla-site-got-hacked%2F&#038;title=Cruelcard%20Post-mortem%3A%20How%20my%20Joomla%20site%20got%20hacked" id="wpa2a_2"><img src="http://www.u-g-h.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.u-g-h.com/2008/09/08/cruelcard-post-mortem-how-my-joomla-site-got-hacked/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cruelcard gets an update</title>
		<link>http://www.u-g-h.com/2008/08/15/cruelcard-gets-an-update/</link>
		<comments>http://www.u-g-h.com/2008/08/15/cruelcard-gets-an-update/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 15:44:38 +0000</pubDate>
		<dc:creator>Owen</dc:creator>
				<category><![CDATA[websites]]></category>
		<category><![CDATA[cruelcard]]></category>
		<category><![CDATA[launch]]></category>
		<category><![CDATA[website]]></category>

		<guid isPermaLink="false">http://www.u-g-h.com/?p=2244</guid>
		<description><![CDATA[Cruelcard.com was one of the first websites I&#8217;ve ever built. It was my way of teaching myself ASP (VBScript) and well, one way to have fun. It consists of a number of eCards with a specific theme. Some may say they are funny, some may say they are too cruel; but they&#8217;re bound to get [...]]]></description>
			<content:encoded><![CDATA[<div style="float:right;margin-left:5px;"><span id="pa_57414"><a  id="pa_57414" href="http://www.picapp.com/PublicSite/ViewDetails.aspx?ImageId=10033"><img src="http://www.picapp.com/ftp/Preview/0057/cruel_Picapp_57414.jpg" alt="Mouse being held by the tail" oncontextmenu="return false;"></a><br/><font size="-2"></font></span><script type="text/javascript" src="http://pis.picapp.com/IamProd/javascript/imageV2.js?p=5113&#038;i=57414&#038;w=234&#038;h=357&#038;adH=25&#038;adS=3&#038;fv=picviewerv2_1.swf&#038;pv=http://pis.picapp.com/IamProd/FlashSite/en/&#038;u=http://pis.picapp.com/IamProd/ImageServing.aspx&#038;sp=true&#038;n=1"></script> </div>
<p><a  href="http://cruelcard.com">Cruelcard.com</a> was one of the first websites I&#8217;ve ever built. It was my way of teaching myself ASP (<a  href="http://en.wikipedia.org/wiki/VBScript">VBScript</a>) and well, one way to have fun. It consists of a number of eCards with a specific theme. Some may say they are funny, some may say they are too cruel; but they&#8217;re bound to get a reaction.</p>
<p>Anyway, the site&#8217;s been looking dated for the last 3 years or so, so I finally got around to giving it a make-over. However, instead of recoding it, I&#8217;ve decided to use it to explore the capabilities of <a  href="http://www.joomla.org/">Joomla</a>, an open-source CMS package. So I installed Joomla, found plugins to accomplish what I wanted, found a theme, and voila, the site is now live. I&#8217;ve added all the old cards in and should really look around for some more. Would love one linked to <a  href="http://www.blind9golf.com/">golf hats</a> for example. But in the meantime, all the older ones would have to do.</p>
<p>Check it out: <a  href="http://www.cruelcard.com">Send a CruelCard today</a></p>
<div style="text-align:center;"><span id="pa_57415"><a  id="pa_57415" href="http://www.picapp.com/PublicSite/ViewDetails.aspx?ImageId=26657"><img src="http://www.picapp.com/ftp/Preview/0057/cruel_Picapp_57415.jpg" alt="Girl being bullied" oncontextmenu="return false;"></a><br/><font size="-2"></font></span><script type="text/javascript" src="http://pis.picapp.com/IamProd/javascript/imageV2.js?p=5113&#038;i=57415&#038;w=234&#038;h=156&#038;adH=25&#038;adS=3&#038;fv=picviewerv2_1.swf&#038;pv=http://pis.picapp.com/IamProd/FlashSite/en/&#038;u=http://pis.picapp.com/IamProd/ImageServing.aspx&#038;sp=true&#038;n=1"></script> </div>
<p><a  class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.u-g-h.com%2F2008%2F08%2F15%2Fcruelcard-gets-an-update%2F&#038;title=Cruelcard%20gets%20an%20update" id="wpa2a_4"><img src="http://www.u-g-h.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.u-g-h.com/2008/08/15/cruelcard-gets-an-update/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

