Monday night I started seeing some replies in my Inbox from friends of mine, commenting on the message body. Apparently an email had gone from my address to a number of friends and some other people with whom I am loosely affiliated.
The message looked like this:
I kinda freaked! Either someone exploited an application I use that had my email address and the addresses of friends (such as Gmail or Squirrelmail) or something fishy had to be going on. Did I leave myself logged in somewhere?! SHIT!!
So I dug around on all my computers at home, and nothing looked suspicious. So when I got into work the next day it occured to me. MESSAGE BOARDS! I am the admin on 4 different boards (3 of which are mine). On the ones I own and operate my email address is listed in the database under the admin account.
I had recently upgraded one (00bliss.com) to vBulletin 3.x which had also included some fixes to major security flaws from the previous version of vBulletin, so I knew it couldn't be that one. However, I had forgotten to upgrade the forums @ bruteforceindustries.com on which I was also hosting the forums for DCDNB. That board was still running vBulletin 2.3.0. Oops!
So I checked the board at:
http://bruteforceindustries.com/forums
And sure as shit, it was hacked.
Turns out that all members of the forum received an email from 'jathan@breakbeat.org' (since I am the admin with user id of 1) entitled 'sexyswitchstance' (the latter part being my username) with the suspicious URL above in the message body.
By the looks of it (on the index page for the forums), it looks to have been done by an Arabic group or at least posers...
Additionally, the hacker(s) deleted all of the forums and all of the style settings for the forum as well as the primary administrator account, effectively taking the board out of commission until further notice.
I was curious what the text on the hacked index page said, and what the context of the pictures included on the page was. I asked around and it turned out that the father of one of my friend's spoke Arabic. He translated the text for me:
"There is no diety except Allah and Mohammed is His only prophet."
The text at the bottom says we were "chosen by Anahina" which is apparently an Arab religious group.
It seems we were "chosen" because we are American. But being that the site was running a vulnerable version of a widely-used application, it was only a matter of time before the board got exploited. Anahina just happened to get there first.
Here's some related links to the pics on the hacked site:
http://www.palestinefacts.org/pf_1991to_now_alaqsa_dura.php
http://www.eretzyisroel.org/~ginsburg/aldura/
http://www.theatlantic.com/doc/prem/200306/fallows
It's really sad... :(