ringofbrodgar.com appears to have been hijacked

General discussion and socializing.

ringofbrodgar.com appears to have been hijacked

Postby IainBruce » Mon Feb 23, 2015 2:37 pm

Forgive me, I'm not terribly sure where to post this, but having spent some hours on ringofbrodgar.com (the wiki) while playing Haven and Hearth, my router logs indicated that for the entire time I was online, I was recieving multiple HTTP requests per second scanning every port of my router. My router only logged this because it considers it an attempted DDoS. Now I'm sure the creators of Haven and Hearth did not intend this, but it would appear that ringofbrodgar.com is being used to DDoS anyone who opens it. I felt it important to inform people of this and hopefully draw the attention of the owners of Haven & Hearth; It IS possible that it is simply a major bug in the page causing it to spam routers constantly, but I'm sure nobody wants a wiki that launches DoS attacks against you, whether erroneously or by a third-party hack.
IainBruce
 
Posts: 2
Joined: Sun Feb 22, 2015 7:13 pm

Re: ringofbrodgar.com appears to have been hijacked

Postby loftar » Mon Feb 23, 2015 4:14 pm

Just for the record, the Wiki is not run by us. However, I don't see it exhibiting the behavior you describe. Did you verify with your logs that the port scan did indeed originate from ringofbrodgar.com and wasn't just coincidental? It's the kind of thing that happens every now and then when you're on the Internet, after all; that it happened while you were browsing ringofbrodgar.com could very well have been a pure coincidence.

IainBruce wrote:I was recieving multiple HTTP requests per second scanning every port of my router.

I think you mean TCP requests.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: ringofbrodgar.com appears to have been hijacked

Postby IainBruce » Mon Feb 23, 2015 5:41 pm

They were made via HTTP, and yes, the router logs stated the source was ringofbrodgar.com. However with javascript disabled this oddly does not happen...
IainBruce
 
Posts: 2
Joined: Sun Feb 22, 2015 7:13 pm

Re: ringofbrodgar.com appears to have been hijacked

Postby borka » Mon Feb 23, 2015 7:21 pm

Nope
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: ringofbrodgar.com appears to have been hijacked

Postby mvgulik » Mon Feb 23, 2015 7:32 pm

I have a hard time taking this seriously. Not that I could do anything about it if there was a problem anyway, as I'm not a RoB wiki Bureaucrat/Owner.
I currently only see some nice story. But no real usable data in support of this story.
Ergo: ... Sitting back and waiting for things to really break, or blow over.
mvgulik
 
Posts: 3770
Joined: Fri May 21, 2010 2:29 am

Re: ringofbrodgar.com appears to have been hijacked

Postby Metruption » Mon Feb 23, 2015 9:03 pm

Just get out wireshark, click around the wiki for a few minutes and have a look at the packet capture
User avatar
Metruption
 
Posts: 358
Joined: Tue Jun 10, 2014 12:26 am

Re: ringofbrodgar.com appears to have been hijacked

Postby borka » Mon Feb 23, 2015 9:04 pm

Metruption wrote:Just get out wireshark, click around the wiki for a few minutes and have a look at the packet capture


And what did you find ?!? ;)
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: ringofbrodgar.com appears to have been hijacked

Postby loftar » Tue Feb 24, 2015 12:25 am

Metruption wrote:Just get out wireshark, click around the wiki for a few minutes and have a look at the packet capture

Ain't gonna do much good when there's a NAT router in between.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: ringofbrodgar.com appears to have been hijacked

Postby Metruption » Tue Feb 24, 2015 1:23 am

borka wrote:
Metruption wrote:Just get out wireshark, click around the wiki for a few minutes and have a look at the packet capture


And what did you find ?!? ;)

I found nothing because I haven't looked yet ^:)
User avatar
Metruption
 
Posts: 358
Joined: Tue Jun 10, 2014 12:26 am

Re: ringofbrodgar.com appears to have been hijacked

Postby loftar » Tue Feb 24, 2015 3:50 am

IainBruce wrote:They were made via HTTP

How would you even know the protocol if it doesn't get a chance to connect? :)
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Next

Return to The Inn of Brodgar

Who is online

Users browsing this forum: Claude [Bot], Semrush [Bot] and 2 guests