Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,153,369 members, 7,819,327 topics. Date: Monday, 06 May 2024 at 02:26 PM

I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! - Nairaland / General - Nairaland

Nairaland Forum / Nairaland / General / I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! (5738 Views)

MD/CEO Of Trendy Beauty Outlet Was Attacked By "Evil Snake" (Picture) / Why Nairaland Was Shut Down / Nairaland Was Offline Friday, Saturday, Sunday. Now We're Back! (2) (3) (4)

(1) (2) (3) (Reply) (Go Down)

I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by makajie: 7:27pm On Jun 28, 2014
Im not here to drop conspiracy theories about why Nairaland was attacked. There are many possible reasons why this could've happened; competitors, internet terrorists asking for a ransom, aggrieved potential buyers, jobless / bored hackers, someone whose posts never made front page..... and the list goes on, but conspiracy theories just aint my thing. What i find interesting is HOW NAIRALAND WAS ATTACKED, as in, the technique the attackers might've used. About a week before Nairaland got attacked, i'd been seeing signs of an imminent attack; signs i've come to attribute to a botnet kind of attack over time. To break it down, it seems the attackers were actually using some of our laptops (and maybe phones) to launch rebounding (amplified) attack codes @ Nairaland (possibly XSS).
Some of you might ask why i didn't raise an alarm. Well, its simple, some dude raised an alarm about Nairaland containing some adware and another said his Nairaland account had been hijacked and noticed some strange stuff on his account. These people (from their choice of words) were laymen so it must've been easy to brush their observations aside. I believe the Nairaland Team had noted their observations anyway, so why cry "Fire" without being sure. Seun has sacrificed a lot to build this fortress (we should be proud of him) and i won't be the one to tarnish Nairaland's image.
I was interested in what these two fellows had reported (so unIT-like though) so i did a little investigation by creating a new Nairaland account then. I was able to register the email address but could not go past the part where you pick a username and password to finalize the registration process, i kept getting an error message which meant that some additional strings were being passed along with my username and password . I then turned to Hydra to tell me more about these strings. There were two possibilities; either a shell was resulting in a broken code or i was looking at some form of injection attack (must've been @ mapping stage from the looks of the code).
I believe that the core strategy of this attack is infected devices using Nairaland (although i can't prove it beyond reasonable doubt) and it might just be a few of them. I don't think the infection could've spread among devices (although I might be wrong for unprotected devices) because i involved Norton IS during the whole process and should've got an intrusion alert if there was an attempt.
I believe LindaIkeji's blog is one of the next set of targets (due to its huge traffic) and the attack is likely going to be a Remote File Inclusion attack via script embedded images AT THE COMMENTS SECTION. The attackers strike me as too smart to attempt a Bruteforce (that would be stupid) or server level attack (that would be them versus Google).
To cap this all up, i really wonder why some people just want to frustrate other people's successes. Maybe hacking makes them feel more powerful or something, i wouldn't know, but its just plain cowardly. I could understand hacking a company's website or government website just to drive home a point (still doesn't make it right) but haba, attacking places where people break away from the daily hassles of life? Who does that!!!

20 Likes

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Esesuper: 7:35pm On Jun 28, 2014
HHHhhhhmmmmmmm.......
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Nobody: 7:44pm On Jun 28, 2014
Still concealing facts?

Keep it up
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by ITbomb(m): 7:49pm On Jun 28, 2014
This is the most objective post I have seen since the beginning of the crisis.

I remember a user creating a thread on what he had observed and Seun ask him for screenshots, I'm not sure he provided it. About 4 more people complained about some unknown pop ups on that thread.

I'm sure the admin thought it was a code issue rather than a direct assault and didn't take precautions.

Linda is and would be more disastrous

3 Likes

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Randerl: 7:54pm On Jun 28, 2014
Anoda Story Pls.

1 Like

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Krak(m): 7:54pm On Jun 28, 2014
Hmmm...
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Nobody: 8:02pm On Jun 28, 2014
Interesting analysis

1 Like

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by FKO1(m): 8:20pm On Jun 28, 2014
STORY STORY ...SUPER STORY
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Nobody: 8:23pm On Jun 28, 2014
men and this is just wickedness...when I did all this trash when I was still learning... I think the hacker was using this forum for practice lol
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by jakiedudu(m): 8:36pm On Jun 28, 2014
As fars as am concern the supporters of APC are behind Nairaland Attack.

4 Likes

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Danhumprey: 8:38pm On Jun 28, 2014
Can someone explain what the OP said in layman's term,please? I'm lost at sea.embarassed

7 Likes

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Nobody: 8:44pm On Jun 28, 2014
Oga seun prolly boasted bout how secured his site is..he did that some years back and got hacked ...bumped upon d thread https://forum.intern0t.org/general-hacking-discussions/1296-nairaland-unhackable.html?_e_pi_=7%2CPAGE_ID10%2C2944814634


i don't know if am talking crap but am saying something

1 Like

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by mstik(f): 8:46pm On Jun 28, 2014
Op, I cannot claim to understand up to half of what you just said(ain't a computer guru) but I totally agree with you that these bad belle hackers are wicked enemies of progress

1 Like

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Nobody: 8:51pm On Jun 28, 2014
Well,I don't know what to say but I think I noticed this few days before it went off
I cudnt see pics clearly on NL.
I usually see some computer format words I don't understand.
I see people's names in twos AND most times not properly spelt.
Lynpetra usually is not properly spelt on my profile.
Nairaland words on FP are not properly spelt and whenever I tried opening a thread on FP,some computer results pops up.At first I thought it was just a virus on my phone,but I checked only to find out my phone is clear.

2 Likes

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by proudly233: 8:53pm On Jun 28, 2014
I can't seem to access nairaland with my normal IP address, I have to use a different IP address, anyone noticing this too? Something is definitely going on here.
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by lilmax(m): 9:14pm On Jun 28, 2014
Something is wrong i can feel it,if that means what i think it means we are in trouble Big trouble!

1 Like

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by mercato: 9:20pm On Jun 28, 2014
Leave OUR Nairaland alone
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by MabraO: 9:22pm On Jun 28, 2014
Jregz: Oga seun prolly boasted bout how secured his site is..he did that some years back and got hacked ...bumped upon d thread https://forum.intern0t.org/general-hacking-discussions/1296-nairaland-unhackable.html?_e_pi_=7%2CPAGE_ID10%2C2944814634


i don't know if am talking crap but am saying something


[color=#550000][/color]U really made sense
Think I need to learn from u

1 Like

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by encryptjay(m): 9:27pm On Jun 28, 2014
Jregz: Oga seun prolly boasted bout how secured his site is..he did that some years back and got hacked ...bumped upon d thread https://forum.intern0t.org/general-hacking-discussions/1296-nairaland-unhackable.html?_e_pi_=7%2CPAGE_ID10%2C2944814634


i don't know if am talking crap but am saying something
Your link is quite fascinating.
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by adexsimply(m): 9:37pm On Jun 28, 2014
I don't think Linda can be hacked since it's hosted under Google's ...or is it possible?
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Osyxcel(m): 9:46pm On Jun 28, 2014
ITbomb: This is the most objective post I have seen since the beginning of the crisis.

I remember a user creating a thread on what he had observed and Seun ask him for screenshots, I'm not sure he provided it. About 4 more people complained about some unknown pop ups on that thread.

I'm sure the admin thought it was a code issue rather than a direct assault and didn't take precautions.

Linda is and would be more disastrous

Yes, I was on that thread, I also complained of not being able to login from the FP (if I click d login link from d FP) as it takes me back from the login page to d FP back without logging me in.

The attack was a slow and gradual one.
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by experimentist: 9:53pm On Jun 28, 2014
makajie: Im not here to drop conspiracy theories about why Nairaland was attacked. There are many possible reasons why this could've happened; competitors, internet terrorists asking for a ransom, aggrieved potential buyers, jobless / bored hackers, someone whose posts never made front page..... and the list goes on, but conspiracy theories just aint my thing. What i find interesting is HOW NAIRALAND WAS ATTACKED, as in, the technique the attackers might've used. About a week before Nairaland got attacked, i'd been seeing signs of an imminent attack; signs i've come to attribute to a botnet kind of attack over time. To break it down, it seems the attackers were actually using some of our laptops (and maybe phones) to launch rebounding (amplified) attack codes @ Nairaland.
Some of you might ask why i didn't raise an alarm. Well, its simple, some dude raised an alarm about Nairaland containing some adware and another said his Nairaland account had been hijacked and noticed some strange stuff on his account. These people (from their choice of words) were laymen so it must've been easy to brush their observations aside. I believe the Nairaland Team had noted their observations anyway, so why cry "Fire" without being sure. Seun has sacrificed a lot to build this fortress (we should be proud of him) and i won't be the one to tarnish Nairaland's image.
I was interested in what these two fellows had reported (so unIT-like though) so i did a little investigation by creating a new Nairaland account then. I was able to register the email address but could not go past the part where you pick a username and password to finalize the registration process, i kept getting an error message which meant that some additional strings were being passed along with my username and password . I then turned to Hydra to tell me more about these strings. There were two possibilities; either a shell was resulting in a broken code or i was looking at some form of injection attack (must've been @ mapping stage from the looks of the code).
I believe that the core strategy of this attack is infected devices using Nairaland (although i can't prove it beyond reasonable doubt) and it might just be a few of them. I don't think the infection can spread among devices however because i involved Norton IS during the whole process and would've got an intrusion alert if there was an attempt.
I believe LindaIkeji's blog is one of the next set of targets (due to its huge traffic) and the attack is likely going to be a Remote File Inclusion attack via script embedded images. The attackers strike me as too smart to attempt a Bruteforce (that would be stupid) or server level attack (that would be them versus Google).
To cap this all up, i really wonder why some people just want to frustrate other people's successes. Maybe hacking makes them feel more powerful or something, i wouldn't know, but its just plain cowardly. I could understand hacking a company's website or government website just to drive home a point (still doesn't make it right) but haba, attacking places where people break away from the daily hassles of life? Who does that!!!
Too long! Explain in two sentence.
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by li2boy: 10:04pm On Jun 28, 2014
I think this OP is right tho, Linda just posted on her blog some minutes ago that she's having some issues. Mayb its signs she's under attack
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Nobody: 10:13pm On Jun 28, 2014
lmaoo.. @ DMF was outdated..

lindaikeji can be hacked, but i think a DOS or as the op said a remote file inclusion attack... but it can easily be rectified by linda, as google hosts it... that is if the hackers dont wipe every data from her logs if they gain access to her control panel before she tries to restore it... if i was linda now, i would contact google atm nd alert them of a soon to be attack, as the host i bliv google would constantly backup her logs, incase even if she finally gets attacked... lessons learnt from the nairaland attack, always have a constant backup, atleast 14 hours before the present time you are in..

11 Likes

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by goalburner(m): 10:26pm On Jun 28, 2014
Nairalanders pls wise up! Ogakpaktapakta and Justwise are the ones who hacked nairaland...... Na d truth be dat.

7 Likes

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by adexsimply(m): 10:29pm On Jun 28, 2014
Jregz: Oga seun prolly boasted bout how secured his site is..he did that some years back and got hacked ...bumped upon d thread https://forum.intern0t.org/general-hacking-discussions/1296-nairaland-unhackable.html?_e_pi_=7%2CPAGE_ID10%2C2944814634


i don't know if am talking crap but am saying something
thanks for this link..I learnt a couple of things
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Saeed348(m): 10:32pm On Jun 28, 2014
BREAKING NEWS:

Linda Thomas, the lady who
usually says "You have insufficient credit to make
this call" is dead...U can now make free calls....

3 Likes

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Lexusgs430: 10:37pm On Jun 28, 2014
What would surprise me is if, Seun and his team have no form of backup to replicate contents incase of an attack!!!!
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by just2endowed: 10:40pm On Jun 28, 2014
ITbomb: This is the most objective post I have seen since the beginning of the crisis.

I remember a user creating a thread on what he had observed and Seun ask him for screenshots, I'm not sure he provided it. About 4 more people complained about some unknown pop ups on that thread.

I'm sure the admin thought it was a code issue rather than a direct assault and didn't take precautions.

Linda is and would be more disastrous


I was the user that raise the topic one week ago before Nairaland was short down that it's under attack by adware and malware virus. Seun did respond and I was not surprised he short down the site temporarily. It was clear and I prove it to him. Am glad it's resolve but seun should try have the site secure and encourage users to have latest updated Antivirus and Anti-Malware installed.
Believe me, so many Nairalanders pc has been infected as it only affect pc not smart phone

2 Likes

Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by Djicemob: 11:03pm On Jun 28, 2014
This whole episode reminds me of Dan Brown's novel the "Digital fortress". I jus hope dat is not the case here.
Re: I Believe I Know How Nairaland Was Attacked...and How Lindaikeji's Blog Will Be! by sweetguy10(m): 11:12pm On Jun 28, 2014
These past days my AVG anti-virus has been detecting a Trojan horse Virus , when I checked the source file I Immediately know that it is a botnet attack . You all should change your email passwords and clean up your system . I'm telling you that thousands of systems are being compromised and remotely hacked due to this Nairaland attack .

(1) (2) (3) (Reply)

Baba Alanu / PHCN/NEPA Electricity Supply: Any Difference? / Lala247 Has Deactivated!

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 48
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.