PDA

View Full Version : APUG server hacked ?


Bertram2
12-31-2005, 03:25
Hi,

Just tried to contact the APUG forum, got a message that my account has expired and I should call the billing dept. :-))

Now the server is completely down, seems somebody does not like that forum ?
Maybe the digital Mafia ? :D

bertram

Socke
12-31-2005, 03:42
No, looks real. The domain apug.org is registrated by domainsbyproxy.com and the nameservers are ns7.rwhmax.info and ns8.rwhmax.info. So this looks as if somebody made an accounting error :-)

smudwhisk
12-31-2005, 04:21
I'm just getting redirected to msn search, suggesting that the name cannot be resolved. I suppose it's possible that the host of the forum has changed its IP address and this hasn't refreshed through properly?? Have seen it happen before.

Bertram2
12-31-2005, 04:49
"www.apug.org could not be found" is what I still get . The "expired account" site was a fake I suppose and to do that , in my understanding somebody must have got into the webserver , through the firewall. Stupid , I did not note which server was shown for the fake message, it wasn't APUG.

bertram

markinlondon
12-31-2005, 04:51
This is what I'm getting.

http://molly.rwhmax.info/suspended.page/?f=13

Someone's domain account has expired, but whether that's APUG or there's a redirect going on is hard to say.

Mark

Bertram2
12-31-2005, 04:51
I'm just getting redirected to msn search, suggesting that the name cannot be resolved. I suppose it's possible that the host of the forum has changed its IP address and this hasn't refreshed through properly?? Have seen it happen before.

Not with a fake message before shut down happened I suppose ? :)

bertram

Socke
12-31-2005, 04:54
Exactly Mark, rwhmax.info has the nameservers for apug.org so they are very probably apugs hoster.
They didn't pay their bill, no hacking required.

Bertram2
12-31-2005, 04:58
This is what I'm getting.

http://molly.rwhmax.info/suspended.page/?f=13

Someone's domain account has expired, but whether that's APUG or there's a redirect going on is hard to say.

Mark

molly.rwhmax isn't a site from the apug.org server, I'd say. So how is the redirection done if not by hacking the firewall ? Strange. thing.

bertram

smudwhisk
12-31-2005, 05:02
Could just be that rwhmax.info name servers are down, not that they haven't paid their bill! Since rwhmax.info will be where other name servers forward to resolve apug.org, if they are down and nobody has it cached, then you won't be able to resolve the name and get to them! Most name servers are set to only cache for a very short period, otherwise it slows down name resolution because of the number of lookups they would do from their cache prior to forwarding to other name servers! I think that make's sense, or that's the official microsoft style exam answer for how it works - if memory serves me correctly! rwhmax.info may well not be on a windows server, but other operating systems are generally set the same.

Bertram2
12-31-2005, 05:04
Exactly Mark, rwhmax.info has the nameservers for apug.org so they are very probably apugs hoster.
They didn't pay their bill, no hacking required.

Ahh, now I see first what you meant, it's the provider's server answering ! I see now WHO is the one who did not pay ! A bit embarrassing , to get the powerline cut publicly. ;)
Bertram

"Oooch, Herr Günzelsen, Sie ham ja aufgeleeecht !??"

markinlondon
12-31-2005, 05:08
Well, it doesn't appear to be the worst case scenario.

http://www.geonet.org.nz/recent_quakes.html

Nothing near Auckland or even anywhere big enough.

Mark

smudwhisk
12-31-2005, 05:09
Could simply be corruption on their names database which has replicated to their second name server, thus causing all resolution to stop. Not unusual since most servers are set to replicate regularly.

But then I prefer the "failed to pay the electricity bill" scenario, more fun!

Socke
12-31-2005, 05:10
This is what I get

markinlondon
12-31-2005, 05:13
Could simply be corruption on their names database which has replicated to their second name server, thus causing all resolution to stop. Not unusual since most servers are set to replicate regularly.

But then I prefer the "failed to pay the electricity bill" scenario, more fun!

This happened to a customer I had some years ago. We were called in in the early hours because their web-based booking service had gone off line. After some hours of investigation, not to mention abuse from the customer someone thought to call British Telecom. We were then informed that the customer had failed to pay the bill on their leased line. Oh, how we laughed.

Mark

traveller
12-31-2005, 07:58
Online again :D

Happy New Year to all of you

John