Morrowind

Hacker

  • Comment
Hi folks,

Over the past few weeks TESSource has been "under attack" from a Chinese hacker who targetted certain areas of the site in an attempt to infect visitors with multiple trojan viruses. This basically involved injecting code into the database of the site via an external site.

While it is unfortunate to have your work sullied by such a pathetic individual, the actions of this hacker have forced me to upgrade the site more, adding in more security checks and hack-proof additions that can only be good for the future of the site.

On Thursday, when it became apparent to the hacker that the holes he was using were being plugged up, he made some last ditch attempts to infect as many people on the site as possible. He changed all the author names in the file database, and all the download names in the database, to a nasty script call. This is the reason why many author names and download names have been lost.

I'm relatively confident that most of the holes have now been plugged and we should not be seeing a repeat of this problem any time soon. However, please remain vigilant of any suspicious areas on the site and report anything you find out of the ordinary to me.

An old backup for the author names and download names had to be used, so if you have recently uploaded or updated your files on the site you might want to check that everything is as it should be. I've also coded a small new feature that lets you change the name of the individual files you have uploaded, so you don't have to remove and reupload your files just to get the file name back.

If you are an Internet Explorer user and have visited this site regularly over the past few weeks then I strongly recommend running a full virus scan of your system, just to be sure.

I'd like to thank all the folks over at the official forums for their support and help.

16 comments

  1. ninja_lord666
    ninja_lord666
    • BANNED
    • 24 kudos
    Those communists are always getting into trouble.

    Anyway, if I ended up becoming a hacker, I'd hack the hackers and destroy their comps <img class=">


    You would destroy your own computer, unless you're defending web sites.

    There's jobs like that. People hack for reasons of good. Like maybe a police station has someone hack into a computer of a suspect in a case to see if there is anything on it.
  2. dipodrsc
    dipodrsc
    • member
    • 2 kudos
    You know (and pardon my language a bit here), but it's f**king b**tards like this g*ddamn hacker that really make my blood boil ><img class="> . What exactly is it that these hackers get out of creating havoc and chaos for no g*ddamn reason? It's extremely low when someone decides to use their knowledge for f**king stunts like this, especially when it really serves them no purpose whatsoever to do so.

    I know that some hackers do what they do for the same reasons that murderers murder, or thieves steal, or rapists rape - self gratification (and maybe for a little self enrichment, and perhaps maybe even to define themselves). But I honestly don't see ANY purpose whatsoever in hacking into a website just for the f**k of it. It makes absolutely no f**king sense.

    I am glad to hear he's been snubbed, and I hope it's permanent (well, maybe not permanent, since hackers are ALWAYS trying to find a way into a website, no matter HOW many layers of security it may have). Anyway, if I ended up becoming a hacker, I'd hack the hackers and destroy their comps <img class=">


    It might be an act of revenge from someone who got banned, or might just be to prove to someone else that he can hack, but whatever reason it is I also am glad to hear that he's been taken care of, especially seeing as my computer screwed up after going on tessource while he was hacking it.
  3. cryocry
    cryocry
    • member
    • 6 kudos
    Those communists are always getting into trouble.

    Anyway, if I ended up becoming a hacker, I'd hack the hackers and destroy their comps <img class=">


    You would destroy your own computer, unless you're defending web sites.
  4. ResidentWeevil2077
    ResidentWeevil2077
    • supporter
    • 20 kudos
    You know (and pardon my language a bit here), but it's f**king b**tards like this g*ddamn hacker that really make my blood boil ><img class="> . What exactly is it that these hackers get out of creating havoc and chaos for no g*ddamn reason? It's extremely low when someone decides to use their knowledge for f**king stunts like this, especially when it really serves them no purpose whatsoever to do so.

    I know that some hackers do what they do for the same reasons that murderers murder, or thieves steal, or rapists rape - self gratification (and maybe for a little self enrichment, and perhaps maybe even to define themselves). But I honestly don't see ANY purpose whatsoever in hacking into a website just for the f**k of it. It makes absolutely no f**king sense.

    I am glad to hear he's been snubbed, and I hope it's permanent (well, maybe not permanent, since hackers are ALWAYS trying to find a way into a website, no matter HOW many layers of security it may have). Anyway, if I ended up becoming a hacker, I'd hack the hackers and destroy their comps <img class=">
  5. jr2nd
    jr2nd
    • member
    • 20 kudos
    its sad to see someone would want to screw around with tess i mean its free.. its here to help.. its a nice community so why be an ass and destroy it? some people can be retarded.. and a waste of human life -.-

    i personally noticed the attempts myself my antivirus kept kicking in alerts every few days or so, hence why i emailed+pics about this.. even though i got no replyyyy <img class="> but well i hope it did help.. <img class=">

    long live TESSOURCE!

    and to the guys who fixed it.. as they say in oblivion

    Well met! <img class=">
  6. BobDoe313
    BobDoe313
    • member
    • 1 kudos
    Hackers always hack for self gain (whether it be service or downloads), profit, or havoc. If your wondering profit, it probably will steal your credit card or something the next time you type it in <img class="> KEYLOGGERS!! Anyway, glad this happened while i was on vacation (--') <img class="> Also glad the system is safe again VIVA TES!!!
  7. Switch
    Switch
    • premium
    • 43 kudos
    Or he just did it for kicks, who knows. <img class="> At least it's helped to show vulnerabilities in the site code. Good to hear he's been stopped for now anyway. ^^ Nice work.
  8. Marre_pro
    Marre_pro
    • member
    • 0 kudos
    Hmm....The hacker had prob nothing at all against TESsource at all , People who do this often works for Computer security software companies to get people to buy their little programms. Or he simply was frustrated because His oblivion lagged big time.
  9. martinb
    martinb
    • member
    • 7 kudos
    I got some trojans... I use Firefox 2.0.0.4, and AVG reported trojans few times.

    They were in few places, but one was in system volume restore (or whatever). I had problems with that before, so in case someone doesn't know how to solve this here's the procedure:

    right click on my computer and go to properties, system restore and check Turn off system restore. This will delete backup of your configuration (which is infected btw.) and the trojan will be gone.

    After that, uncheck turn off system restore to create new backup.


    I found that on some forum, it was pretty useful to me.
  10. Sativarg
    Sativarg
    • BANNED
    • 42 kudos
    Thanks Dark0ne this answers my other question Where are the names of my files?

    I will get started renaming them.

    This may be unrelated but now any use of ' or or / results in duplication of the // that precedes a / to be printed as is. example //////quoted text/////. I am using the ``for a , one` for a ' and \ as replacements for now.