18 May 2007
Survey says…!
I’ve updated my genealogy site. New version of PHP and new version of TNG. Looks pretty snazzy, even if it is just using one of the pre-made templates. The data is still from 2004, but the site is all new like.
I’ve updated my genealogy site. New version of PHP and new version of TNG. Looks pretty snazzy, even if it is just using one of the pre-made templates. The data is still from 2004, but the site is all new like.
My non-blogging site, rjmaguire.com, that mainly hosts my genealogy stuff, was hacked recently. The perp found an underground published security hole in the 3rd party genealogy software I use called TNG: The Next Generation. I found a message on their support forums that describes how to close the hole and now it has. I’ve also replaced the damaged file (as they at least were kind enough to only do a minimal amount of damage).
I don’t blame the author of the software or the PHP programming language. It was an easy mistake to make. I still intend on using the software (and upgrade to the newest version even). It was my own fault for not keeping a closer eye on the server logs and on the TNG mailing list to notice that this kind of thing was going on.
I haven’t actually been able to pinpoint the exact day or time when the hack occurred. The first attempts began in mid-March. I don’t think the hack actually occurred until just a few days ago, when I noticed the page on my site was posted in a Spanish-language forum as a badge of honour as it were. Thankfully, the kids trying this stuff out aren’t really that bright, as witnessed by a lot of failures to even copy and paste correctly.
One of them actually managed to copy a couple of executables that looked like IRC server software or something, but was undoubtedly stopped cold when it had no chance of running on my server’s architecture.
Your friendly neighbourhood admin is Bob Maguire. Feel free to contact me with questions or comments.
Valid XHTML | CSS | Powered by WordPress