PDA

View Full Version : [problem] How did they do it?


djheart
09-08-2009, 06:54 PM
Hello guys,
If this is the wrong forum please let me know.....


Am facing a strange thing, Some kids calling themselves "hackers" are messing up with my clients vbulletin forums.. I dont know how they change the index page of the forum with another page and they write bad words and their emails...ect

To return the forums back i usualy enter the "admincp" and all what i do is downloading the style xml file and then re upload it again.. Thats all! and everything return normal..

That kids is playing around and change the index again and again...

My question is: What can i do to stop these kids?
PS: all forums have the latest vbulletin version, and the server's Perl is switched off..


Please let me know what to do asap.. since am losing customers



Thanks in advance..
-Moe

HMBeaty
09-08-2009, 06:58 PM
Have a look here: https://vborg.vbsupport.ru/showthread.php?t=193930&highlight=email

And also change the passwords to everything if they keep getting back in and doing it again

djheart
09-08-2009, 07:00 PM
thanks alot

djheart
09-10-2009, 04:42 AM
Did everything you told me, The hack came again today...

kevcj
09-10-2009, 09:02 PM
Are you sure its the forums fault? Maybe its a hole in the server allowing them to upload files? Is the server and all of the server services up to date? Meaning, are all of the latest security patches installed on the server? Is apache up to date, is the ftp server up to date, is the database server up to date,,,,.

Have you asked the host to do a security audit? Have you changed the root password and the admin passwords? Do you have brute force protection installed?

If you do not have something to stop a brute force attack on the server level, they can throw tens of thousands of passwords at the server until the finally break the root password.

Is this a shared hosting plan, VPS or a dedicated server?

There are a lot of questions that need to be looked at outside of vbulletin.