[ARCHIVED] "The Hack List"

Status
Not open for further replies.

RAF

Onyx user!
Reputation
0
Earlier today, a thread was released on another competitors site requesting for RuneGear.net to be hacked and defaced. Obviously there seems to be no existence of mutual respect between this site and ours on their behalf, considering no action was played upon any of RG Management's part. We are seen as a threat (as it seems) being the 2nd biggest RS hacking site online, and one of the fastest growing RS communities. Rune Gear has continuously upheld and maintained a reasonable relationship with competitors, never having any serious trouble until now. Competition is healthy, destroying it is not.

Anyway, you may be wondering why I'm posting this thread. I'm sure many of you know the site of which I'm discussing. This site is known for many famous hacks within the RS-'business'. They have been credited for large hacks and take-downs of popular sites. Well, that's beyond the point. This thread isn't to succumb to the pressure. Many sites get hacked... Many large sites get hacked, and when they do, most will continue, some fall. Being threatened by this catalyst of conflict, I'd like to state the following - Rune Gear is as secure as it can possibly be, in the possibility of a breach, the natural, logical security measures will be taken as always. Find the problem, patch the issue, run security checks, carry on as normal. We do not retaliate, we never have. We've faced countless hack attempts (and successful ones too), strong DDOS attacks, and many more. We haven't faltered, only continued on and grown with our heads held high. Retaliation is futile, I'd rather continue steady growth, instead of focusing on taking down competition.

Ultimately, we haven't been hacked, and there is no reason to believe yet that we're vulnerable. I appreciate everyone's support and hope that they carry on happily. Thanks.

- The Elite

Update: http://runegear.net/showthread.php?tid=58933&pid=500265#pid500265
 
RE: "The Hack List"

I remember when it was RunescapeForums, and Carbon was setting up a irc and he said his password and someone delete RSF :L

Anyways, glad to hear we're more of a respectful site than others.
 
RE: "The Hack List"

Ask mike, I check RG monthly for a vulns.

Proper backups and updates will keep any site safe, it's just up to the bluefaces to keep it like that.
 
RE: "The Hack List"

Haters gonna hate
 
RE: "The Hack List"

Platinum Sif said:
I remember when it was RunescapeForums, and Carbon was setting up a irc and he said his password and someone delete RSF :L

Anyways, glad to hear we're more of a respectful site than others.

That never happened, RSF's cpanel and $super_admin had a 40+ char password.
 
RE: "The Hack List"

Carbon said:
That never happened, RSF's cpanel and $super_admin had a 40+ char password.

Well then you trolled everyone, because I'm pretty sure I TV'd Jeterfan as he did it.
 
RE: "The Hack List"

Yeah, Toil can be an arsehole sometimes.

I'm assuming that's the site you're on about.
 
RE: "The Hack List"

Platinum Sif said:
Well then you trolled everyone, because I'm pretty sure I TV'd Jeterfan as he did it.

Nawp you must be thinking of something else, maybe the irc itself because that did happen but it was a free IRC and the password was localised to just the IRC.
 
RE: "The Hack List"

Carbon said:
Nawp you must be thinking of something else, maybe the irc itself because that did happen but it was a free IRC and the password was localised to just the IRC.

Oh, maybe, anyways, thanks for letting us know to prepare for ddos again. I remember who it was the last time, and how much it sucked to browse RG.
 
RE: "The Hack List"

Lol, I don't thinking doing anything to Runegear.com will affect us.
 
RE: "The Hack List"

They big skiddie from hackforums, they rob my tuts from russia boards and post in there little shit.

Just allow only root to write to the document root, change ssh port & setup iptables ( Because this skiddie like to bruteforce ssh & play super mega udp flood game)
 
RE: "The Hack List"

>Not setting up a honeypot and sniffing traffic
 
RE: "The Hack List"

LONG LIVE RUNEGEAR!!!!!

Well said TE, we shouldn't stoop to others' levels. Don't hate, Appreciate.

~Ven0m
 
RE: "The Hack List"

Easy fix.

- Make sure anyone with ACP/MySQL/SSH access has very strong passwords. Non-dictionary 12+ character passwords
- Deny access to profile for guests. Blocks majority of automated tools. You could also block the search feature for guests.
- Deny from all except said IPs (htaccess) for sensitive areas (ACP & whatever you use to manage mysql)
- Change the directory that the ACP is under. Make is very random.
- The emails connected to sensitive (ACP/mod) accounts should ONLY be used for these accounts. They should never be revealed.
- Implement an IP block for RBL'd/detected proxies IPs. That is what Hackforum does and it eliminates sooo many problems. Search around for a php script that automatically negates access if proxied IP is detected.

That eliminates a lot of future problems. Whoever is targeting RG... I guarantee that they aren't a threat. Just skids.
 
RE: "The Hack List"

gfxer said:
Easy fix.

- Make sure anyone with ACP/MySQL/SSH access has very strong passwords. Non-dictionary 12+ character passwords
- Deny access to profile for guests. Blocks majority of automated tools. You could also block the search feature for guests.
- Deny from all except said IPs (htaccess) for sensitive areas (ACP & whatever you use to manage mysql)
- Change the directory that the ACP is under. Make is very random.
- The emails connected to sensitive (ACP/mod) accounts should ONLY be used for these accounts. They should never be revealed.
- Implement an IP block for RBL'd/detected proxies IPs. That is what Hackforum does and it eliminates sooo many problems. Search around for a php script that automatically negates access if proxied IP is detected.

That eliminates a lot of future problems. Whoever is targeting RG... I guarantee that they aren't a threat. Just skids.

Great post mate. Respect+.
 
RE: "The Hack List"

I've been asked about this issue as well. I said not to worry about it. I find the list bogus in my honest opinion. If they cannot get the domain right they wont be able to discuss....
 
Status
Not open for further replies.
Back
Top