As a few of you know, I (along with XGameMasterX and Syed75) have been working on a DSi formatted website, DSiRealms, for a while. Well, around 8 PM on March 5th, as I was editing the site, I was randomly logged out. After several log-in attempts by both I and the other original Administrators, we learned that our website had been stolen fromus, with a new email and password to the account. Whoever did so even went around various parts of the site and inputted their own info in place of my own. However, they did miss some, such as my Admin profile page (although, it's of little use).
Armed with this terrible news, I contacted the Administrators to report this, and am hoping for a reply soon.
Now, the reason I'm posting this blog is simple:
Do NOT go to DSiRealms, and more importantly, DON'T give this...thief ANY credit or compliments about the site. He is a liar and has no morals. I'm hoping that our host can right these wrongs quickly, as the other Admins and I have been working VERY hard on the site.
Now here's a lesson for budding web developers:
Be careful who you allow to know your CPanel login info.
Because we 3 Admins wanted to get the site out sooner, we decided to 'hire' a couple of new admins, thecreator123 and PHPMaker (their Socialite usernames).I know not if it was they who did this, but considering they did nothing on the site in their short tenure, and knew the account info, they're my prime suspects.
Hopefully the morning will bring good news, but I've no idea of whether or not our host will believe my tale. The more people that know about this, the better.
Oh and for a bit of proof, you can look into the 'Affiliate Websites' section in the BBs, and go to the DSiRealm topic to see that I'm telling the truth. Wish us luck.
No. There is no exploit.. And heres what happend.. Some idiot gave out the pass.
Or some admin was key logged(rare)..
But only one thing we can do..
GM can delete the domain cause it's co.cc
Which he did??
-_-" And after all that work....
It likely had essentially nothing to do with our security methods. Like it says in the blog, it was likely one of the Admins we added, as I doubt someone could guess it, and it's equally doubtful someone managed to exploit a system vulnerability of 000webhost.
Thank you so much for accepting this Jake! Normally, I would never ask someone to feature a blog of mine (I'd rather the blog earn that merit itself), but I really needed people to know, soas not to give this person free reign. Again, thank you.
(>^_^)>==[[::::::::::::::::::::>