pouët.net

Good Bye Nectarine

category: general [glöplog]
Well, it seems it is final: Nectarine is history.

Quote:
This morning a script kiddie hacked nectarine.
He did post a hint on the vulnerability in the oneliner before trashing everything.
The whole Database is deleted, backup too. The only one i have is from august.


The vulnerability was coming from multipage class i used.

My motivation is too low to fight against lamers again.

If you are a donor, maybe could you unsubscribe your paypal donation.

Sorry guys, but i don't have enough free time to restore everything and i don't have enough money to pay hosting alone.



Friendly

Yes aka Christophe


http://www.nectarine.fr/
added on the 2008-09-09 21:17:23 by Salinga Salinga
:(
added on the 2008-09-09 21:19:01 by micksam7 micksam7
Terrible news. I hope something can be done at least, like someone take the HD's and try and recover it if possible.
added on the 2008-09-09 21:23:26 by rc55 rc55
didn't nectarine get hacked like two weeks ago as well?
added on the 2008-09-09 21:23:50 by Gargaj Gargaj
when i read this on the nectarine "frontpage", it really mad me extremly sad. YOU DAMN WANKERS!!! SCRIPT KIDDIES!!! FOOLS! IDIOTS! WHY CAN'T YOU JUST LEAVE WEBSITES AS THEY ARE?!
sorry, but i'm extremely sad now. nectarine was always a great place to stay at and losing such a great community will definitely hurt the demoscene. a lot.
Gargaj: More like a month. But yes, this is extremely LAME.
What a sad news !!!
Maybe we can help Yes to reinstall his august backup ?
added on the 2008-09-09 21:27:04 by Nicky One Nicky One
The damn fucker posted comments via the oneliner this morning and deleted step by step the whole page.. i was online and talked to this shithead via oneliner..... didn´t know that it was possible to delete the actual backup too :(
added on the 2008-09-09 21:32:48 by Premium Premium
This attack did not only hurt Yes and his work but also a very vital community attached to this site. For years now many spent hours and hours having fun hearing music, sharing it and talking about the music of demoscene.

I consider this not only a attack on a website or Yes but an attack on demoscene itself.

I am really curious if it is possible to take legal actions against this individual - is the IP address logged?
added on the 2008-09-09 21:33:21 by Salinga Salinga
if i remember correctly nectarine is also the origin of brainstorm's comeback to the scene.. damn hackers! I hope nectarine will be back some day! any day!
added on the 2008-09-09 21:37:56 by magic magic
Well even if it is it's probabbly dynamic IP. Sad news indeed. :(
added on the 2008-09-09 21:38:08 by masterm masterm
:(
Ip adress...legal actions....

Im quite against hacking and taking stuff down etc.
But i wouldnt mind if the IP got logged that "somehow someone accidently let that scriptkiddy's stuff crash"....

Nectarine was such a nice place, i loved to listen to the music. Hear songs from good times, hear songs that where new to me even tough they where so old....

And the nice people there.

:(
Well, if the IP is not from an anonymizer, even if it's dynamic combined with the time of usage you can link it to the logged on user behind it. The provider should have the IP/time referenced to the customer using the IP -> customer has contract -> contract has postal address.
added on the 2008-09-09 21:41:57 by Salinga Salinga
I'm talking to Yes right now and he told me that he lost all php sources and only got the old mysql/mp3 backups. this is really SHIT! He also doesn't want to start it again... So I vote for this: We, as a team, re-create this bloody great website... together. I'm in. I want to ressurect nectarine.
WTF!? He had no local backup of the sources from Nectarine?
added on the 2008-09-09 21:45:06 by Salinga Salinga
Quote:
Well, if the IP is not from an anonymizer, even if it's dynamic combined with the time of usage you can link it to the logged on user behind it. The provider should have the IP/time referenced to the customer using the IP -> customer has contract -> contract has postal address.
*fingers crossed*
added on the 2008-09-09 21:46:01 by masterm masterm
Maybe trying to recover the actual HD isn't that bad idea after all.
added on the 2008-09-09 21:46:16 by Salinga Salinga
Quote:
WTF!? He had no local backup of the sources from Nectarine?

guess what, his backup hard disk died last week.
Sad news :( very sad news !!!
added on the 2008-09-09 21:48:49 by _wheely_ _wheely_
Maybe we can donate money so he can give the HD to a professional HD recovery firm?
added on the 2008-09-09 21:49:22 by Salinga Salinga
Saga Musix : Ok for me (as much as possible) !
added on the 2008-09-09 21:49:35 by Nicky One Nicky One
masterm: oh come on, if our "haxor" can "hack" nectarine and take care of deleting 1) the database 2) the logs and 3) the php instead of a simple /var/www deface, then he prolly had the sensibility to at least proxy his way through.

then again, the whole thing smells of WTF all the way - NOT backing up a website source? ever? i mean you keep developing the site, of course you make backups - it's just part of the cron routine with mysqldump.

something doesn't add up here.
added on the 2008-09-09 21:50:38 by Gargaj Gargaj
@gargaj: it seems the actual local backup HD died recently.
added on the 2008-09-09 21:51:38 by Salinga Salinga
Quote:

then again, the whole thing smells of WTF all the way - NOT backing up a website source? ever? i mean you keep developing the site, of course you make backups - it's just part of the cron routine with mysqldump.

i feel free to quote directly from MSN here:
Quote:
21:36 Yes^BRS: you want to know?
21:36 Yes^BRS: i was at paris today
21:37 Yes^BRS: and this morning before a meeting i told myself to launch a nectarine backup
21:37 Yes^BRS: but i said 'well, after the meeting'
21:37 Saga: damn :\
21:37 Yes^BRS: the lamerz deleted everything 15 mn later

login