PDA

View Full Version : Diabuddies Crashes


BriOnH
10-03-2006, 10:12 AM
I found out why the site is crashing and will fix it this afternoon.

For those interested it's becuase people are trying to hack the diabuddies database. When they do this they take up all the available connections to it. They aren't even close to hacking it yet, at the rate they are attempting it would take over a year. Just know your info is secure and I will do everything I can to protect it.

Stuboy
10-03-2006, 10:18 AM
why would people want to hack the database!??? What people take pleasure or get off on reading people's results, seriously!!

BriOnH
10-03-2006, 10:26 AM
why would people want to hack the database!??? What people take pleasure or get off on reading people's results, seriously!!
I think someone just crawled open ports on the server and saw that there is a DB. They are trying random logins and passwords, I don't know how they would ever, ever crack a DB this way.

The site is up now and a resolution is being worked on and will be implemented today. Sorry for the inconvienence.

JediSkipdogg
10-03-2006, 12:26 PM
That sucks and I hope you can trace who is doing it. My chat program was hacked numerous times, and I could never figure out why. The chat was a communication method for players to find battles in a peer to peer game only. So crashing it really did nothing but hurt the game, which still stood strong.

BriOnH
10-03-2006, 01:00 PM
I diagnosed the problem wrong. Looking at the DataBase log files there are numerous attempts by users to hack it, but this is fairly normal, and people with weak secutiry measuers could be breached. I am confident no one needs to worry about a security breach at diabuddies.

What is really happening is I am leaving a connection to the DataBase open somewhere. Right now it allows a 100 simultanous users(Actually user processes, so theoritcally 400 users) to access the DB and will find where I am leaving a DB connection open in my Data Access tier tonight. Until then I have upped the pooled connections to a 1000 so a crash should not happen again.

JediSkipdogg
10-03-2006, 06:43 PM
Still getting crashes, got this one tonight Brian...

Server Error in '/' Application.
--------------------------------------------------------------------------------

Runtime Error
Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server machine.

Details: To enable the details of this specific error message to be viewable on remote machines, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application. This <customErrors> tag should then have its "mode" attribute set to "Off".


<!-- Web.Config Configuration File -->

<configuration>
<system.web>
<customErrors mode="Off"/>
</system.web>
</configuration>


Notes: The current error page you are seeing can be replaced by a custom error page by modifying the "defaultRedirect" attribute of the application's <customErrors> configuration tag to point to a custom error page URL.


<!-- Web.Config Configuration File -->

<configuration>
<system.web>
<customErrors mode="RemoteOnly" defaultRedirect="mycustompage.htm"/>
</system.web>
</configuration>

koblenz
10-03-2006, 09:35 PM
Must of been trying to hack the "Gipson"! :D

http://www.ozbricks.com/syme1984/hackers/hackers_graphics/home_page01.jpg

BriOnH
10-04-2006, 01:52 AM
Must of been trying to hack the "Gipson"! :D

http://www.ozbricks.com/syme1984/hackers/hackers_graphics/home_page01.jpg
can you believe that was angelina jolie? crazy.