Sift Was Hacked

Apologies for the downtime. We were hacked this weekend and wanted to make sure we got all of the malicious code out. I will be posting some updates as I learn more about the exploit, and will hopefully get you guys some information about how to patch your machines.


For those who are curious the exploit in question was mpack.


It's also worth noting that this exploit only targeted users with unpatched machines so as always it is prudent to keep your machine up to date.


Update: After some reviews of our logs and data we tracked the incident to approximately 6:30 pm EST Monday night. We took the site off line around 10 am EST so the exploit was live for around 16 hours. We've contacted the abuse email for the IP in question, but chances are that it was just a compromised PC. I'd like to personally apologize for this lapse in security, and let you guys know that we are taking measures to reduce our liability in the future.


grspec says...

shit happens James, The key is to minimize the impact and the loss of data which you appear to have done. It's difficult to keep a machine up to date against exploits that haven't even been patched yet. Thanks for the update and good job.

MINK says...

i am super mega interested to know how they hacked...
did they get in to the server thru the back door or did they go thru the website and exploit some ajax or php type thing?

sorrry if i just said something completely nonsensical. i am dangerously semitechnical.

I mean... was it the videosift app that let them in, or something else on the server?

btw... macs rule.

drattus says...

Are we sure the site is clean? I checked the log for eTrust Pest Patrol, it quarantined Emusaffil A at 1:12 pm, about the time I first checked in here today. I'm checking some other things and ways now to make sure that's it, caught it before it could install so I'm ok there.

The eTrust page shows that as a high risk one, if many others have it we might want to front page a scan and fix for that and whatever else turns up.

joedirt says...

if you are running IE then you deserve any infections you get from malicious webpages. Use firefox and you don't have to worry about visiting a webpage will hose your computer.

Guys, I don't know what kind of sysadmin you are doing. Here's what you need to type:

sudo cat /var/log/auth.log | /dev/siftbot -mode overlord

karaidl says...

I KNEW something was giving me viruses! I just ran a McAfee scan last night and found 49 detections. Couldn't figure out what it could possibly be. Wasn't opening up strange email or going to bad sites.

Mostly these weird DS/Downloader Trojans that kept showing up in my Temporary Internet Files.

James Roe says...

Sylvester_Ink

It appears they executed a script inside of our server that targeted all php and html files with the words:

"admin, login, index, footer, header, and options"

Then their script inserted an iframe. You can just go to you root html directory and type

grep IFRAME */* and see if anything shows up.

drattus says...

Firefox here, but according to what was posted above Firefox might not be safe either if it has an outdated IE plugin, or perhaps through Quicktime or other plugins as well. It's a world above IE in general for security though.

karaidl says...

Well karaidl you use AOL so you deserve what you get

That made me chuckle. Yes, I'm truely a masochist of the internet world. Actually, since Sift was hacked, I started viewing the site in FF, cuz AOL kept freezing up and of course, the trojans sucked.

dag says...

Comment hidden because you are ignoring dag. (show it anyway)

As much as it's fun to blame the hax0rs, it's our server- we will do our best to make sure it doesn't happen again. The good news is that I think that the vast majority of our members are very cluey and would have patched, up to date systems. ;-)

prisonpanda says...

Jeez thats a nasty piece of work and the russian gangs are selling this thing at 900 quid a go? Dam thats not good for the future if thats a sign of things to come.

TBh i NEVER use IE infact i tell anyone i know not to use it. Im not sure how IE 7 is nowadays in comparison to Firefox is it still the same pile of crap it was before? Anyone got some info on how how both compare for security etc?

karaidl says...

When I read the review in PCWorld a while back it said that the security between the two was roughly even at the time. However, it also noted that FF made several updates in the time that IE was able to make just one, and expected it to do so in the future. Undoubtedly, if they ever were even, FF has surpassed IE again. (And AOL, as I've just recently had first hand knowledge on.)

Speaking of FF, anyone got any addon recommendations? I've been going through PCWorld's list of essential addons - find.pcworld.com/56100

swampgirl says...

I guess I'm only marginally geeky, silvercord.. I'm currently trying to figure out what I'm infected with I have mccafee and I've ran it, but I just tried the Panda scan mentioned above and it said I have something.
I use Firefox btw

Any suggestions? (help )

batmanuel says...

FF extensions I cannot live without:

Nuke Anything Enhanced - Allows removal of almost anything on a webpage, for example, nuking freaky avatars of man-titties.
https://addons.mozilla.org/en-US/firefox/addon/951

Flashblock - Blocks Flash so it won't get in your way, but if you want to see it, just click.
https://addons.mozilla.org/en-US/firefox/addon/433

Web dev - So many good tools that are not just for web development
https://addons.mozilla.org/en-US/firefox/addon/60

SessionSaver - Restores your browser session and more
https://addons.mozilla.org/en-US/firefox/addon/436

Plain text to link
https://addons.mozilla.org/en-US/firefox/addon/623

GreaseMonkey - customize any web page
https://addons.mozilla.org/en-US/firefox/addon/748

MediaPlayerConnectivity - launch embedded media in vlc, mplayer, winamp, etc.
https://addons.mozilla.org/en-US/firefox/addon/446

karaidl says...

Hmmmm... this is weird. My Google toolbar went away, and I can't seem to get it back. I've tried reinstalling it several times. It went away after I install the Netcraft anti-phishing extension, by recommendation of PCWorld.

[Edit] - Nevermind, I fixed it.

xxovercastxx says...

My own experiences with AVG were underwhelming. I also used Clam for a while, and though clamav/clamd works nicely on *nix, I found clamwin to be fairly lacking. I recommend Avast for free antivirus these days. Just make sure to change or disable the definition update sound, lest you be scared out of your chair on a daily basis.

Something else to keep in mind is that every Firefox addon is a potential attack vector. Limit yourself to the few you actually need. I use only Flashblock and SearchWords.

looris says...

[OT@Karaidl] a counter-suggestion: now, install and play with any addon you like. But remember that addons slow down A LOT the starting of FF, so if you don't want to wait ages to start it, you'll have to decide what to keep and what to disable.

J-Rova says...

The address I use for this site is relatively new; not many people have it because I can't stand spam, and so far so good...haven't gotten a single bit yet. However, I recently received one that was odd... the subject said something about receiving an application for employment or something like that, but there was no body text except for the confidentiality warning, which is usually attached after emails from employers, hospitals, etc. (after that, there was a similar one about the IRS, which I'd never seen before)... both seemed to be a signature on an email which otherwise contained no text. So I looked to see who it was from, and it was from "unknown@unknown.unknown" It's true I've been looking for a few jobs lately, but I don't recall applying at the CIA. So, A) it had me wondering if it was correlated to the security breach here, (ie intruders obtaining email addresses) and/or B) has anyone had a similar experience with gmail, especially with the triple-unknown "From" address?

Send this Article to a Friend



Separate multiple emails with a comma (,); limit 5 recipients






Your email has been sent successfully!

Manage this Video in Your Playlists

New Blog Posts from All Members